Skip to main content

Help us improve the Digital Marketplace - send your feedback

CAUSEWAY TECHNOLOGIES LIMITED

CausewayOne Digital Tools

A low-code digital platform connecting Causeway solutions, people and processes. Automate workflows, integrate systems, and create trusted data flows across projects and operations, improving efficiency, governance and delivery across the built environment.

Features

  • Low-code workflow and automation builder
  • API-led integration to internal and external systems
  • Extensive third-party connector library to support OOB integrations
  • Secure common data environment (CDE) to increase collaboration
  • Comprehensive document and drawing management
  • Configurable no-code mobile forms designer
  • Field job and task management with online and offline capability
  • Role-based approvals and governance to streamline processes
  • In built file and BIM viewers

Benefits

  • Reduce manual effort and rekeying to streamline activity
  • Accelerate digital transformation initiatives, workflows and processes
  • Improve governance, auditability and compliance, reducing project risks
  • Enable faster system integration to drive value creation faster
  • Improve collaboration across teams and projects for tighter project management
  • Reduce errors and rework through controlled workflows
  • Reduce time to complete site-based work with configurable forms
  • Increase visibility of operational performance and site information
  • Scale processes consistently across organisations
  • Empower non-technical users

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at salesukgov@causeway.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 9 9 0 8 3 9 5 3 5 5 7 6 6 0

Contact

CAUSEWAY TECHNOLOGIES LIMITED Steve White
Telephone: 01628552000
Email: salesukgov@causeway.com

About the service

Service categories

Applications

Enterprise resource management

  • Project and portfolio management
  • Asset life-cycle management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Our services include planned maintenance which will be discussed during on-boarding.
System requirements
  • Modern web browser and/or mobile device.
  • Valid email address.

User support

Email or online ticketing support
Yes
Support response times
Within the teams standard support hours 08:30 - 17:30 Monday - Friday, in alignment to SLA.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
1st, 2nd and 3rd-line Support for all customers. Support charges are included within annual fees. We provide a dedicated Account Manager for certain customers, with access to the Account Management team for renewals for the remaining customers.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Onboarding support via professional services if requested.
How to guides
Online training videos
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Available on request from supplier in agreed format.
End-of-contract process
User access would be removed and an engagement to export any required data would be initiated. The customer data would then be deleted upon request.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Responsive design on mobile to optimise mobile device real estate.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
A modern web client which is accessible without the need for web browser plugins.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Causeway Technologies is committed to improving the accessibility of the CausewayOne platform and its related products. We aim to support a wide range of users by aligning our design, development, and testing practices with the Web Content Accessibility Guidelines (WCAG) 2.2, Level AA. Accessibility is considered throughout the product lifecycle, including user experience design, engineering, quality assurance, and ongoing improvement activities.

This accessibility statement applies to the CausewayOne web-based platform, including its core applications and user work flows.

Accessibility testing activities include a combination of automated and manual methods, informed by industry best practices and approaches similar to those used by the UK Government (https://www.gov.uk/guidance/accessibility-monitoring-how-wetest). These methods are used to identify accessibility barriers and prioritise improvements.

CausewayOne, as a software platform comprising several applications and functionalities, based on web technologies is partially compliant with the WCAG 2.2 AA Standard.
API
No
Customisation available
Yes
Description of customisation
Product functionality can be configured in conjunction with system administrators. We work with customers to identify needs and provide product specific guidance to their requirements.

Scaling

Independence of resources
Usage and performance monitoring in parallel with onboarding management. All of our services are cloud based and are designed to scale with any increased service demands.

Analytics

Service usage metrics
Yes
Metrics types
Dashboards and reports are available within the service, accessible to users with relevant permissions. Additional metrics can be provided upon request.
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Causeway protects data by using encryption for both data at rest and in transit. Data at rest is encrypted using industry-standard methods such as AES256, including backups. Data in transit is encrypted using HTTPS with TLS1.2 as a minimum standard, and secure protocols such as SFTP are also employed. Encryption is implemented across endpoints, servers, mobile devices, databases, backups, and removable media.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Via the service client.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Each product has a set of SLAs which can be provided on request but do not fall below 99.5%
Approach to resilience
Our products are designed with high availability and resilience as a core function. Dependent on the base infrastructure in use this could either be cloud based multi zone failover or highly resilient data centre replication.

Back up infrastructure methodology is platform dependent and consists of snap shots, bootable instance images, and back-ups at regular intervals.
Outage reporting
Systems fully monitored. Server and database issue/outage alerts and alarms. Monitoring systems vary depending on the native solutions to the cloud environments in use.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
We use Azure AD B2C for authentication, in CausewayOne enabling access to available applications in accordance with the contract. During the requirements phase of any deployment these can be discussed in detail.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Cyber Essentials
ISO9001
ISO22301
ISO14001
ISO45001
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
The Asset Management policy requires assets to be recorded in the CMBD where assets are recorded and changes to those assets are managed through the Change Management Process. The process looks at the risk associated with those changes. These include, Security, Privacy, Legal and Operational.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our vulnerability management process is structured in four phases. The vulnerability management process phases are:
• Identifying Technical Vulnerabilities
• Evaluating Technical Vulnerabilities
• Address Technical Vulnerabilities
• Vulnerability Management Improvement"
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Our SoC consumes log data from a number of sources (Product, M365 and Infrastructure) to correlate and analyse activity that may relate to threat actor behaviour. These are triaged and managed in line with SOPs and where necessary incident response process are initiated to respond, contain and recover from any incident.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Customer incidents can be raised directly and these are handled by a customer facing incident management team. Customer are informed and updated in line with standard SLAs.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
7%
Over £5,000,001
10%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
LRQA
ISO/IEC 27001 accreditation date
Thursday 21 November 2024
What the ISO/IEC 27001 doesn’t cover
The whole business is in scope
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
ISO 9001 certification accredited by
LRQA
ISO 9001 accreditation date
Thursday 21 November 2024
What the ISO 9001 doesn’t cover
The whole business is in scope
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
5f69f5de-1a85-4a22-8d1f-d26642e411b2
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

  • Plans for positive actions with community groups.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at salesukgov@causeway.com. Tell them what format you need. It will help if you say what assistive technology you use.