Skip to main content

Help us improve the Digital Marketplace - send your feedback

R2P UK SYSTEMS LIMITED

RTPI iConnex

iConnex is a comprehensive, secure, easy‑to‑use Real‑Time Information (RTI) System that helps councils and bus operators give passengers accurate, real‑time bus arrival information. It shows where buses are, when they will actually arrive, and helps keep services running smoothly.

Features

  • Map View and Dashboards
  • Reporting
  • Scrolling Messaging
  • Audio Announcements
  • Live and/or Scheduling detail
  • On vehicle passenger information
  • On-street passenger information
  • Timtetable, NaPTAN/location data import and management
  • Disruption Information
  • Content Management System

Benefits

  • Real Time tracking for urban buses
  • Publishing relliable information for passengers
  • Easily accessible journey information across various platforms
  • Allows passengers to make informed choices
  • Allows operators to control available data to passengers
  • Increases public transport opportunities for impared passengers
  • Integration of on-street, on-bus and digital information
  • Multiple platforms for passengers to access real time information
  • Live System View and status monitoring

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ukroad@r2p.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 7 0 0 3 4 8 7 0 1 1 2 9 9 4

Contact

R2P UK SYSTEMS LIMITED Steve Holloway
Telephone: 01293 665398
Email: ukroad@r2p.com

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Location and geospatial data management and analytics
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
No constraints
System requirements
Software licences

User support

Email or online ticketing support
Yes
Support response times
Hdepends on the fault category, minimum time is 8 h for the highset priority
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
Business hours support (Monday to Friday, 09:00–17:00 UK, excluding public holidays)

Access to the service desk via email and ticketing system

Incident logging, triage, and resolution for software and platform issues

Monitoring of core system availability

Access to documentation and standard release notes
Support available to third parties
No

Onboarding and offboarding

Getting started
We provide online training and user documentation to complement the training
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
All the information can be downloaded from the website before the contract ends
End-of-contract process
We proceed to decomission all the data incoming from third parties and to take off the site for the customer
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There are not many differences, it is the same desktop version which is mobile friendly
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure web-based service interface, providing role-based access to system configuration, operational dashboards, and reporting. The service also exposes documented APIs to support integration with third-party systems.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
User interfaces have been tested for accessibility in line with WCAG 2.1 AA. Testing includes keyboard-only navigation, screen reader compatibility (e.g. NVDA and VoiceOver), colour contrast, text scaling, and accessible form controls. Issues identified are logged and remediated, with re-testing performed after significant interface changes.
API
Yes
What users can and can't do using the API
Users can register on the webiste to use API for bus stop predictions, all the users must be approved by the Support Team
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
Capacity is planned and monitored so that increases in load trigger the allocation of additional resources rather than performance degradation for existing users. Independent firewalls on every server strictly control traffic flows between services and users, and all connections use TLS 1.2, aligning with NCSC cloud security principles to ensure that traffic from one tenant cannot interfere with others. Regular independent and internal vulnerability scanning, alongside pre‑go‑live testing for each new customer, validates that these controls remain effective as usage grows, maintaining consistent performance for all users.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Depending on the data, like reporting information that can be exported as a CSV format
Data export formats
CSV
Data import formats
  • CSV
  • Other
Other data import formats
XML

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
R2p offers support via our help desk with our standard operating hours being Monday–Friday, 8am-6pm.
Our Fault management system offers different levels of priority (P1 to P5) based on the nature of the fault; each fault categorisation has a different resolution time which need to be agreed with the specific customer.
Typically, we offer anything from a 4-hr response time to P1 calls through to a 14-day response time for P5 faults.
Our standard KPIs for all our solutions are as follows:
System Security – 100% (Per Month)
System Availability – 98% (Per Month)
SIRI Connectivity – 98% (Per Month)
API Connectivity – 98% (Per Month)
Display accuracy – 90% (Per Month)
These are our standard offerings, any additional SLAs or KPIs that are needed by specific customers would be subject to additional costs. Likewise any requirements for Low Performance Damages (LPDs) to be applicable to our systems will also be subject to increased costs.
In our experience, the best way to handle any LPDs that may be applicable to a system, would be to have them applied as service credits against monthly maintenance fees. All service credits would also be capped to an agreed level.
Approach to resilience
Available on request
Outage reporting
- Automatic Email Alerts, as well as email correspondence to customers
- A Service Monitoring Dashboard that is private to the customer

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
Include:

whether you have pre-defined processes for common events
how users report incidents
how you provide incident reports
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
CYBER ESSENTIALS PLUS
Information security policies and processes
CYBER ESSENTIALS PLUS
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
The Company recognises the importance of change management and the risks associated with ineffective change management. By implementing this policy we aim to mitigate risks such as:
• Information being corrupted and/or destroyed
• Systems performance being disrupted and/or degraded
• Productivity losses being incurred
• Exposure to reputational risk.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
All systems must permit central vulnerability scanning and periodic penetration testing. Internal and external vulnerability scans must be performed at least annually and after any significant network change.

A risk-based remediation plan will prioritise patching by asset criticality:

CVSS ≥ 8.9: remediate within 7 days

CVSS 7.0–8.9: remediate within 14 days

CVSS 4.0–6.9: remediate within 90 days

CVSS < 4.0: remediate within 180 days as part of normal maintenance

Remediation will be validated through rescanning.

Penetration testing of internal systems, external interfaces, and hosted applications will be conducted at least annually and after significant changes.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our ISP runs attack detection processes on their primary routers and firewalls.
We run log and firewall monitoring.
We run Heimdal security NextGen antivirus and anti-ransomware encyption solution.
Our security incident process covers all forms of security, not just IT.
It follows a five-step process:
• Prepare for handling incidents.
• Identify potential incidents through monitoring and reporting.
• Assess identified incidents for mitigation & onward alerting
• Responding and resolve
• Post-incident review
The system architecture provides for a high availability solution which is capable of supporting operations to meet the 1-hour RTO
Incident management type
Supplier-defined controls
Incident management approach
1. Detection: Staff and Vendors must monitor systems and alert the Delivery and Support Director within 1 hour of suspected incidents.
2. Reporting: Incidents are logged in the Incident Register with timestamp, source, and initial classification.
3. Containment: Vendors must isolate affected systems and prevent further spread.
4. Investigation: Root cause analysis and evidence collection led by the Vendor with Company oversight.
5. Communication: Stakeholders, customers, and regulators are notified when necessary.
6. Recovery: Systems restored as required following backup/restore or disaster recovery plans.
7. Closure: Incident formally closed with lessons learned and corrective actions.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
Yes
Connected networks
Other
Other public sector networks
BODS

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Time limited trial, using BODS data to demonstrate the capabilities of the iConnex System.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
7.5%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Nqa
ISO 9001 accreditation date
Friday 8 November 2024
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
6df0f212-3c93-4f20-880e-269d25828ceb
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
1b5e540e-78b2-4ee2-8776-2fba9c0ce13f
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Ensuring new workers are informed of their right to join a trade union
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ukroad@r2p.com. Tell them what format you need. It will help if you say what assistive technology you use.