Mycelia
Mycelia is a software solution to help Local Planning Authorities (and similar organisations) drive better environmental outcomes in less time. It includes end-to-end support for Biodiversity Net Gain.
Features
- Tracks number and progress of BNG applications
- Drag-and-drop import of all Biodiversity Metric information
- Radically easier interfaces for interacting with the Metric
- Full and faithful recreation of the BNG algorithm
- Automatic checks & tools for Validation, Assessment and Monitoring
- AI verification of photographs
- Tracking of monitoring data, responsibilities, and deadlines for every case
- Ecological monitoring and Habitat Significance auto-advice
- Built from ground up to handle and display spatial data
- Ecology-driven risk-flagging and prioritisation
Benefits
- Complete BNG support: pre-app, validation, assessment, monitoring, and reporting
- Automatic validation and AI checks: Instantly detects errors and tampering
- Ecological risk identification: Beyond red-box errors, including habitat significance
- Statutory reporting automation: ~95% of Biodiversity Duty reporting managed automatically
- Advanced mapping: Integrated spatial data and aerial imagery, including historical
- Expert support: Access to Ecologists via BNG Clinics and resources
- Unlimited users: Collaborate easily with internal teams and external consultants
- True SaaS platform: no local installation required
- Funding: Costs usually covered through burdens funding or monitoring fees
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 5 1 1 4 9 7 8 9 4 1 1 4 1 9
Contact
Verna
Rafi Cohen
Telephone: 07817257041
Email: info@verna.earth
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
- GDS-supported browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Our target is to respond within four working hours, and in practice we are often faster than this. Our support hours are 9am-5pm Mondays to Fridays (excluding public holidays).
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Full support is included for all users at no additional cost. Users are able to contact support by email and through our support resources. Our support hours are 9am-5pm Mondays to Fridays excluding bank and public holidays.
Our targets are to acknowledge issues within 4 working hours and to fix serious problems (e.g. outages, material risks to security or privacy) within 24 hours; however these are minimum standards which in practice we outperform. All organisations using Mycelia have an account manager; there is no need for engineering support as no technical work is required by the customer – the service is delivered entirely through a web browser. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Mycelia is a modern, intuitive app accessed entirely through a web browser. When an organisation adopts Mycelia, to help get started we provide a live, online training session for any/all users at the organisation. This is supported by documentation, other resources (e.g. videos), regular “catch-up” live training sessions, special live training sessions when new functionality is rolled out, and ongoing email support.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- The Mycelia contract specifies that at end of contract the customer may request that all its data within the software be transferred to the customer in a useable format at no extra cost.
- End-of-contract process
- If a customer chooses to end the contract, its use of the software is discontinued from contract end. The customer has the option to request a transfer of all its data on the system (at no additional cost), after which the data is securely destroyed. Some standard contract provisions, such as confidentiality and data protection, continue after the contract ends.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Mycelia and our documentation is designed to be accessible to users and is compliant with WCAG 2.1 AA accessibility standards. The service is delivered as a web-based application, allowing access via standard modern web browsers without the need for specialist software. Accessibility considerations are incorporated into the design and operation of the system to support use by council staff with differing access needs. We are in the process of updating Mycelia and documentation to meet WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Mycelia is an HTML5 webapp, accessed through a web browser.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Mycelia is designed to be accessible to users and is compliant with WCAG 2.1 AA accessibility standards. The service is delivered as a web-based application, allowing access via standard modern web browsers without the need for specialist software. Accessibility considerations are incorporated into the design and operation of the system to support use by council staff with differing access needs. We are in the process of updating Mycelia to meet WCAG 2.2 AA.
- Accessibility testing
- N/A
- API
- No
- Customisation available
- Yes
- Description of customisation
- Each authority using Mycelia is set up as a separate organisation, with its own configuration. A variety of aspects can be customised to the organisation, including, for example, mapping data and workflow options. Customisation options will grow further over time as the software continues to develop.
Scaling
- Independence of resources
- Mycelia is a scalable multi-tenant solution, hosted in datacentres managed by industry-leading providers. The resources allocated within these datacentres are dynamically controlled by software configuration, so can be rapidly scaled in response to user demand.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- All files uploaded to Mycelia can be exported in their original form. In addition, Mycelia is designed to provide custom data reporting and exporting functionality tailored to the needs of ecology and Biodiversity Net Gain. This area of functionality is continuously being developed, in line with customers’ evolving needs.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLSX
- Defra Reporting Template
- Data import formats
- Other
- Other data import formats
-
- Statutory Biodiversity Metric
- Image files
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We aim for 100% uptime. Our uptime in 2025 was 99.963%. Our contractual standards for serious problems such as outages are notification within 4 hours and fix within 24 hours; these are minimum standards which in practice we outperform.
- Approach to resilience
-
All Mycelia data is stored and processed in UK datacentres which are ISO27001 certified, with industry-standard business continuity and disaster recovery measures including UPS and backup generators.
To ensure business continuity and disaster recovery, Mycelia uses a scalable cluster of three or more identical instances operating simultaneously in three different data centers in the UK. Mycelia uses a database with an additional read only replica in a different data center which will automatically take over if the primary node fails. Our database is backed up with per second point-in-time restoration as well as daily snapshots.
The Verna team manages the Mycelia service so as to continuously improve it without disrupting user experience. Updates are released as necessary and can be on a frequent basis (e.g. weekly) as maintenance and improvements are rolled out. In the vast majority of cases, updates are released with no impact on availability. Where downtime is required, we give customers a minimum of 48 hours’ notice and typically carry out this work outside of usual working hours. - Outage reporting
- All users are notified of any outages by email.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- At present, management interfaces are available only to the Verna team (restricted by various access controls including multi-factor authentication), with user management requests actioned via support channels. Management interfaces for users will be rolled out in the future, protected by (at least) multi-factor authentication or Single Sign On authentication. Support requests are only accepted from confirmed users.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Verna follows all relevant industry standards and guidance, including from the ICO and the NCSC. Verna’s Chief Technology Officer is responsible for the security of the service, and one of Verna’s Co-CEOs is responsible for the organisation’s data protection policy and measures. Security measures, procedures, and risks are reported on regularly at board level.
- Information security policies and processes
- Our policies and processes are based on best practice guidance from the Information Commissioner’s Office and the National Cyber Security Centre, including the NCSC Cloud Security Principles. Our Chief Technology Officer is responsible for the security of the Mycelia service, accountable at board level to one of our Co-Chief Executives. Adherence to security policies is a mandatory requirement of our contracts with workers, reinforced by training and management oversight.
- Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All of our application configuration, including hardware and software deployment descriptors, and container setup is managed as software and maintained under source code control. It is subject to the same code review processes as all of our application development, and access to deployment branches is protected and restricted to key staff. Secrets are deployed via a cryptographically secure store managed by our cloud provider. As part of the product management process, all potential changes are assessed against a range of key impact criteria including security impact. Changes are not accepted onto the roadmap without passing this process.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We use a range of measures including scanning using automated tools, manual tests, checks of our supply chain, and encouraging security notifications. Our CI/CD configuration includes an automated step to check for package dependencies that have been withdrawn, or are subject to a CVE disclosure. Team members also monitor a range of security and threat assessment sources, including LWN and cvedetails.com, as well as groups dedicated to the technologies Mycelia relies on. Our targets are to acknowledge issues within 4 working hours and fix serious problems within 24 hours; these are minimum standards which in practice we outperform.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We continuously and routinely monitor the service for any indications of potential malicious activity. This is supported by Open Telemetry, via Honeycomb.io, and error detection, via Sentry.io, to monitor for unusual conditions or error states, with automated alerts to the product team to enable swift action to be taken. All access and use of the service is fully logged. Our targets are to acknowledge issues within 4 working hours and fix serious problems within 24 hours; these are minimum standards which in practice we outperform.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We encourage security notifications from anyone via security@verna.earth. Our users can also report security issues via email to our support channels. All problems with the service are reported (and updated on) to users. We have robust systems to ensure security incidents are acted upon. We are an agile, tight-knit team and our incident management approach is based on rapid communication and rigorous project management (based on DSDM Agile). We keep users informed at every stage of the incident, by email, and (if necessary) phone cascade.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 20%
- Between £500,001 and £1,000,000
- 60%
- Between £1,000,001 and £2,500,000
- 60%
- Between £2,500,001 and £5,000,000
- 60%
- Over £5,000,001
- 60%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B6261bf3-b5aa-48ae-b40e-3c667efff75f
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-