Grit SMART
Grit SMART is cloud software for managing grit/salt bin networks. It maintains a single inventory of locations, condition and status, records inspections, refills and maintenance, and surfaces usage and movement patterns. Authorities can target interventions, reduce abortive visits, justify placement or removal decisions, and respond to enquiries during winter service.
Features
- Geospatial bin inventory with unique identifiers
- Condition grading and status flags per asset
- Inspection, refill and repair workflow recording
- Activity history timeline with audit trail
- Usage indicators highlighting under-used and over-used bins
- Movement tracking for relocated or missing bins
- Interference alerts for obstruction or tampering events
- Programme builder for targeted refill rounds
- Rationalisation tools for placement, relocation, removal decisions
- Exportable reports for governance, review and member responses
Benefits
- Cuts wasted journeys across dispersed estates and rural networks
- Speeds answering public queries with evidenced bin records
- Supports proportionate risk-based provision across priority communities
- Enables budget savings through network right-sizing decisions
- Strengthens assurance for winter arrangements and cost scrutiny
- Maintains continuity when roles change or knowledge leaves
- Highlights problem locations needing protection from repeated meddling
- Focuses crews on assets actually requiring attention
- Reduces complaints by clarifying availability, ownership and upkeep
- Builds confidence for managers during severe weather demand
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 7 1 7 4 6 4 3 2 7 0 7 8 0 9
Contact
KaarbonTech
Mark Entwistle
Telephone: 01202031333
Email: sales@kaarbontech.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
The system is delivered as a cloud-hosted SaaS service and requires an internet connection and a modern, standards-compliant web browser.
Planned maintenance is carried out periodically and, where service availability may be affected, users are notified in advance.
Configuration and integration with existing corporate systems (for example GIS or asset management systems) may be subject to technical feasibility and agreement at onboarding.
Support availability is provided in line with the agreed support package. - System requirements
-
- Modern Web Browser (Chrome, Edge, Firefox, or Safari)
- Stable Internet Connection
- JavaScript enabled in browser
- Secure HTTPS access permitted.
- User Account with Role-Based Permissions
- Screen resolution suitable for web-based applications.
- PDF viewer for reports and exports.
- CSV compatible spreadsheet software for data export.
- Optional API access for system integrations.
- Email access for notifications and support.
User support
- Email or online ticketing support
- Yes
- Support response times
- Monday to Friday 8am to 5pm - response within 60 minutes, out of hours SLA can be specified, further details on request
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Our support services are delivered by online ticket, email or telephone and are operational 0800 until 1700 UK time, Monday to Friday excluding bank and public holidays. We do provide a dedicated account manager for each customer but this is not specifically a technical or cloud support engineer.
We offer onsite support at the rate published on our pricelist. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
KaarbonTech onboarding is designed to ensure users can start using the service quickly and confidently, with support tailored to local authority needs.
At onboarding, KaarbonTech works with the buyer to configure the system to reflect local processes, asset standards and reporting requirements. This includes setup of asset structures, workflows, configurable inspection and collection questions, user roles and permissions.
Training is provided to support different user groups. On-site training is available for field-based users, focusing on practical use of the mobile interface, including viewing asset information, capturing inspections and observations, recording outcomes and submitting evidence. This helps ensure operatives are comfortable using the service in live operational environments.
Online training sessions are also provided for administrators and management users, covering system configuration, reporting, dashboards and day-to-day management tasks. Sessions can be delivered remotely and recorded where appropriate for later reference.
User documentation is provided to support onboarding and ongoing use, including written guidance and reference materials covering core functionality and common tasks. Ongoing support and advisory input is available following go-live to help users embed the service into business-as-usual operations. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of the contract, users can extract their data from the system using the standard data export functionality provided within the service. Data can be exported in commonly used, open formats suitable for reporting, audit and onward use. Exported data includes asset records, inspection and activity history, observations and associated metadata. Customers retain ownership of their data at all times. Where required, KaarbonTech can provide reasonable assistance to support data extraction and handover as part of the offboarding process, subject to agreement. Any additional support beyond standard export functionality can be agreed separately if needed.
- End-of-contract process
-
At the end of the contract, access to the system is managed in line with the agreed contract end date. Users are able to export their data using the standard export functionality provided within the service prior to service termination.
The contract price includes continued access to the service until the contract end date and the ability for users to extract their data using standard export tools. Data ownership remains with the customer at all times.
Following contract expiry, user access is removed and customer data is retained for a limited period in line with agreed retention policies, after which it is securely deleted.
Where buyers require additional offboarding support — for example, assisted data extraction, bespoke data formats, extended access periods, or support with transition to another system — this can be provided subject to agreement and may incur additional cost. Any such support would be agreed in advance at call-off or during offboarding. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation is provided in accessible digital formats designed to support a wide range of users. Documentation uses clear structure, headings and plain English, and is provided in common open formats that support zoom, reflow and screen-reading tools. Content is readable on desktop and mobile devices and avoids scanned or image-only documents. Where required, additional guidance can be provided through supported walkthroughs or verbal explanation. Formal certification against a specific accessibility standard has not been completed, but accessibility considerations are applied proportionately in line with government guidance on document formats and structure.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The system is accessed via a web-based interface that adapts to desktop, tablet and mobile devices. The mobile interface is optimised for field use, enabling operatives to view asset records, capture inspections, observations and outcomes, and record evidence while on site. Mobile use supports offline working, allowing data to be captured without network connectivity and synchronised when the connection is restored. The desktop interface is optimised for office-based activities such as data analysis, reporting, configuration and administrative tasks, including working with larger datasets, maps and dashboards. Some advanced configuration and reporting functions are therefore more practical on desktop devices.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- The system supports configuration to align with local authority processes and standards. Asset collection and inspection workflows include configurable questions, options and outcomes, which can be tailored by the buyer to reflect local practices, guidance and reporting requirements. Configuration is applied within the standard service and does not require bespoke software development. More complex configuration or integration requirements can be agreed at onboarding where required.
Scaling
- Independence of resources
- The system is delivered as a cloud-hosted, multi-tenant SaaS platform designed to scale with user demand. System resources are managed centrally and monitored to ensure consistent performance across customers. The platform uses capacity planning, performance monitoring and controlled deployment processes to prevent individual customer activity from adversely affecting others. Usage is isolated at the application and data level, with role-based access controls and logical separation of customer data. The service is designed to handle variable demand while maintaining availability and responsiveness for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The system provides service usage metrics to support operational oversight and reporting. Metrics include user activity levels, asset records created and updated, inspections and observations recorded, and completion of activities and workflows within the system. Usage metrics can be viewed through dashboards and standard reports, supporting monitoring of adoption, workload and performance over time. Data can also be exported for further analysis or audit purposes. Metrics are provided at an aggregate and user-level, subject to role-based access controls, to ensure appropriate visibility while maintaining data security.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Data can be exported from the operations section of the main menu or from many of the reporting screens within the system.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Geodatabase
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- KaarbonTech guarantees a minimum system availability of 99% within agreed service hours. Our SaaS platform is hosted on ISO 27001-certified AWS and Hetzner infrastructure, whose underlying cloud SLAs typically exceed 99.95% availability. High availability is supported through redundant infrastructure, live data replication, frequent off-site backups, and automated monitoring with rapid escalation. Detailed SLAs and any associated service credits for avoidable under-performance are defined in the contract-specific SLA and Terms & Conditions, aligned to the Authority’s requirements.
- Approach to resilience
- KaarbonTech’s cloud services are designed with resilience by default. This SaaS platform is hosted within secure, ISO 27001-certified cloud data centres, using tiered power, cooling and physical security controls. The production environment is operated across two independent data-centre locations, with live services supported by a geographically separate standby environment. Data is replicated between environments and backed up regularly, including off-site backups, to support service recovery. In the event of a data-centre incident, defined disaster-recovery procedures are in place to restore service using replicated data. Availability is further supported through continuous monitoring, automated alerting and established incident-management processes. More detailed infrastructure information can be provided to Authorities on request and, where appropriate, under NDA.
- Outage reporting
- Service outages are managed through established incident management procedures. Where a service disruption occurs, users are informed via direct communication, such as email notifications to nominated contacts, and through support channels where appropriate. Incidents are logged and tracked internally, with updates provided as needed until resolution. Post-incident information can be shared with customers on request, including details of the issue and corrective actions taken.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted to authorised staff only. Administrative access is granted on a role-based, least-privilege basis and limited to those who require it to perform their role. Access permissions are reviewed periodically and removed promptly when no longer required. Support requests are managed through controlled support channels, with identity verified before account-specific information is discussed. All administrative and support access is logged to support accountability and incident investigation.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- KaarbonTech follows a set of information security policies and operational processes designed to protect the confidentiality, integrity and availability of customer data. These include policies covering access control, data protection, incident management, vulnerability management, secure development and acceptable use. Responsibility for information security sits with senior management, with operational responsibility delegated to the technical leadership team. Security risks, incidents and material changes are escalated through defined internal reporting lines and reviewed as part of regular management oversight. Compliance with policies is supported through role-based access controls, technical controls within the platform, staff awareness of security responsibilities and the use of third-party cloud infrastructure with recognised security standards. Policies and processes are reviewed periodically and updated as the service evolves.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Configuration and change management follows defined internal processes to maintain service stability and security. Service components, including application code and configuration, are version controlled and tracked throughout their lifecycle. Proposed changes are documented and reviewed prior to deployment, with assessment of potential impacts on availability, data protection and security. Changes are tested before release and deployed using controlled processes to minimise risk. Security patches and updates are prioritised based on risk and applied in a timely manner, with monitoring and rollback procedures in place where required.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is handled through defined internal processes. Potential threats are assessed by monitoring the service architecture, reviewing changes, and evaluating their impact on confidentiality, integrity and availability. Vulnerabilities are prioritised based on risk and potential impact on the service and users. Security patches and updates are deployed in a timely manner, with higher-risk issues addressed as a priority. Information about potential threats is obtained from a combination of cloud hosting provider security advisories, software supplier notifications, industry best-practice guidance and internal testing, including periodic external security testing.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Protective monitoring is implemented through a combination of system monitoring, logging and alerting. Potential compromises are identified by monitoring service availability, access activity and system behaviour for unexpected or anomalous events. Alerts are reviewed by technical staff to assess severity and impact. Where a potential compromise is identified, defined incident management procedures are followed to contain the issue, investigate root cause and implement corrective actions. Incidents are prioritised based on risk, with higher-severity issues responded to promptly in line with established incident response processes.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Incident management follows defined internal processes to ensure consistent and timely handling of service issues. Pre-defined procedures are in place for common events such as service disruption, security incidents and access issues. Users can report incidents via the service support channels, including email or ticketing, which are monitored by the technical team. Incidents are logged, prioritised based on severity and investigated accordingly. Updates are provided to affected users as appropriate, and incident reports can be shared following resolution, outlining the issue, impact and corrective actions taken.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Approachable Certification Ltd
- ISO/IEC 27001 accreditation date
- Tuesday 12 November 2024
- What the ISO/IEC 27001 doesn’t cover
- Our ISO/IEC 27001 certification applies only to the scope defined in the certificate and Statement of Applicability. It does not extend to customer-owned devices, customer networks, or third-party systems not included within our ISMS scope. The certification does not cover end-user behaviour, customer configuration choices, or data entered or exported by users. Third-party services are covered only where they are explicitly included within the ISMS and managed through supplier assurance processes. ISO 27001 certifies the operation of an information security management system and does not represent a guarantee against all security incidents.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2f541c67-bf4f-4a59-8b8f-e806e182a50a
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-