CausewayOne Digital Tools
A low-code digital platform connecting Causeway solutions, people and processes. Automate workflows, integrate systems, and create trusted data flows across projects and operations, improving efficiency, governance and delivery across the built environment.
Features
- Low-code workflow and automation builder
- API-led integration to internal and external systems
- Extensive third-party connector library to support OOB integrations
- Secure common data environment (CDE) to increase collaboration
- Comprehensive document and drawing management
- Configurable no-code mobile forms designer
- Field job and task management with online and offline capability
- Role-based approvals and governance to streamline processes
- In built file and BIM viewers
Benefits
- Reduce manual effort and rekeying to streamline activity
- Accelerate digital transformation initiatives, workflows and processes
- Improve governance, auditability and compliance, reducing project risks
- Enable faster system integration to drive value creation faster
- Improve collaboration across teams and projects for tighter project management
- Reduce errors and rework through controlled workflows
- Reduce time to complete site-based work with configurable forms
- Increase visibility of operational performance and site information
- Scale processes consistently across organisations
- Empower non-technical users
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 9 9 0 8 3 9 5 3 5 5 7 6 6 0
Contact
CAUSEWAY TECHNOLOGIES LIMITED
Steve White
Telephone: 01628552000
Email: salesukgov@causeway.com
About the service
- Service categories
-
Applications
Enterprise resource management
- Project and portfolio management
- Asset life-cycle management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Our services include planned maintenance which will be discussed during on-boarding.
- System requirements
-
- Modern web browser and/or mobile device.
- Valid email address.
User support
- Email or online ticketing support
- Yes
- Support response times
- Within the teams standard support hours 08:30 - 17:30 Monday - Friday, in alignment to SLA.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- 1st, 2nd and 3rd-line Support for all customers. Support charges are included within annual fees. We provide a dedicated Account Manager for certain customers, with access to the Account Management team for renewals for the remaining customers.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Onboarding support via professional services if requested.
How to guides
Online training videos - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Available on request from supplier in agreed format.
- End-of-contract process
- User access would be removed and an engagement to export any required data would be initiated. The customer data would then be deleted upon request.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Responsive design on mobile to optimise mobile device real estate.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- A modern web client which is accessible without the need for web browser plugins.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Causeway Technologies is committed to improving the accessibility of the CausewayOne platform and its related products. We aim to support a wide range of users by aligning our design, development, and testing practices with the Web Content Accessibility Guidelines (WCAG) 2.2, Level AA. Accessibility is considered throughout the product lifecycle, including user experience design, engineering, quality assurance, and ongoing improvement activities.
This accessibility statement applies to the CausewayOne web-based platform, including its core applications and user work flows.
Accessibility testing activities include a combination of automated and manual methods, informed by industry best practices and approaches similar to those used by the UK Government (https://www.gov.uk/guidance/accessibility-monitoring-how-wetest). These methods are used to identify accessibility barriers and prioritise improvements.
CausewayOne, as a software platform comprising several applications and functionalities, based on web technologies is partially compliant with the WCAG 2.2 AA Standard. - API
- No
- Customisation available
- Yes
- Description of customisation
- Product functionality can be configured in conjunction with system administrators. We work with customers to identify needs and provide product specific guidance to their requirements.
Scaling
- Independence of resources
- Usage and performance monitoring in parallel with onboarding management. All of our services are cloud based and are designed to scale with any increased service demands.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Dashboards and reports are available within the service, accessible to users with relevant permissions. Additional metrics can be provided upon request.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Causeway protects data by using encryption for both data at rest and in transit. Data at rest is encrypted using industry-standard methods such as AES256, including backups. Data in transit is encrypted using HTTPS with TLS1.2 as a minimum standard, and secure protocols such as SFTP are also employed. Encryption is implemented across endpoints, servers, mobile devices, databases, backups, and removable media.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Via the service client.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Each product has a set of SLAs which can be provided on request but do not fall below 99.5%
- Approach to resilience
-
Our products are designed with high availability and resilience as a core function. Dependent on the base infrastructure in use this could either be cloud based multi zone failover or highly resilient data centre replication.
Back up infrastructure methodology is platform dependent and consists of snap shots, bootable instance images, and back-ups at regular intervals. - Outage reporting
- Systems fully monitored. Server and database issue/outage alerts and alarms. Monitoring systems vary depending on the native solutions to the cloud environments in use.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- We use Azure AD B2C for authentication, in CausewayOne enabling access to available applications in accordance with the contract. During the requirements phase of any deployment these can be discussed in detail.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Cyber Essentials
ISO9001
ISO22301
ISO14001
ISO45001 - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- The Asset Management policy requires assets to be recorded in the CMBD where assets are recorded and changes to those assets are managed through the Change Management Process. The process looks at the risk associated with those changes. These include, Security, Privacy, Legal and Operational.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Our vulnerability management process is structured in four phases. The vulnerability management process phases are:
• Identifying Technical Vulnerabilities
• Evaluating Technical Vulnerabilities
• Address Technical Vulnerabilities
• Vulnerability Management Improvement" - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our SoC consumes log data from a number of sources (Product, M365 and Infrastructure) to correlate and analyse activity that may relate to threat actor behaviour. These are triaged and managed in line with SOPs and where necessary incident response process are initiated to respond, contain and recover from any incident.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Customer incidents can be raised directly and these are handled by a customer facing incident management team. Customer are informed and updated in line with standard SLAs.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- LRQA
- ISO/IEC 27001 accreditation date
- Thursday 21 November 2024
- What the ISO/IEC 27001 doesn’t cover
- The whole business is in scope
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- LRQA
- ISO 9001 accreditation date
- Thursday 21 November 2024
- What the ISO 9001 doesn’t cover
- The whole business is in scope
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 5f69f5de-1a85-4a22-8d1f-d26642e411b2
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for positive actions with community groups.