Solar Wizard
Solar Wizard estimates rooftop solar potential for homes across England, Scotland and Wales. It provides fast, independent assessments of solar viability for individual or grouped buildings, allowing local authorities to assess solar potential across a whole area. Solar Wizard uses multiple datasets to calculate power generation, costs and potential savings.
Features
- Calculates building‑level rooftop solar potential across England, Scotland, Wales.
- Detailed rooftop suitability analysis including orientation, pitch and overshadowing
- Preloaded with accurate and independent building level data.
- Fully aligned with OS‑licensed datasets supplied through the PSGA
- Provides an interactive solar potential map for multiple buildings.
- Full financial analysis including cost benefit reports for multiple buildings.
- Unlimited data export for use in other software products.
- Service includes training for up to eight users.
- Monthly collaboration and roadmap steering group open to all users.
- Dedicated account manager delivering technical support and encouraging community engagement.
Benefits
- Supports evidence based decision making about rooftop solar potential
- Enables quick identification of buildings with rooftop solar potential.
- Reduces assessment time and improves accuracy
- Interactive multibuilding mapping saves time planning local solar initiatives.
- Cost-benefit modelling supports funding bids, investment cases and strategic planning.
- Immediate self‑service data access saves time and enables further analysis.
- Upfront training shortens onboarding and helps users realise benefits sooner.
- Dedicated account manager fosters partnership to increase solar uptake.
- Helps target viable solar upgrades to meet Warm Homes objectives.
- Trusted independent charity support maximises effective and meaningful community engagement.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 2 1 2 6 7 9 1 2 7 1 6 8 0 3
Contact
CENTRE FOR SUSTAINABLE ENERGY
<removed>
Telephone: <removed>
Email: csefunding@cse.org.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Location and geospatial data management and analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Some down time is required for scheduled maintenance and upgrades. These are carefully planned in advance and, whenever possible, carried out outside peak usage times to minimise disruption.
- System requirements
- Requires access to a web browser and an internet connection.
User support
- Email or online ticketing support
- Yes
- Support response times
- We aim to provide same‑day responses during standard office hours and working days wherever possible. For more complex enquiries requiring investigation, we issue regular progress updates in line with the severity and nature of the question.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- Every customer is assigned a dedicated technical account manager who serves as their primary point of contact for any technical support needs. In addition, we operate a team‑monitored support mailbox that is reviewed daily to ensure queries are picked up promptly and handled efficiently.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We help users start using the service through a structured onboarding process. As part of the service, we provide online training for up to eight users via Microsoft Teams, ensuring they understand how to use the system from day one. Users also receive our PDF user documentation by email, and additional guidance is available on the Solar Wizard website.
To support continued adoption, customers are invited to join our quarterly user group and can attend our monthly drop‑in sessions, where users share ideas and receive informal guidance. These ongoing activities help new and existing users build confidence and get the most value from the service. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Users have full access to extract their own financial modelling data from the service at any time during the contract. If preferred, we can provide a full data‑extraction service in a user‑defined format as part of off‑boarding; this is available on request for an additional charge.
All other datasets used by the service are licensed by the customer and remain fully under their control outside the system, including Ordnance Survey licensed data.
To comply with Ordnance Survey licensing requirements, we securely delete all customer‑provided datasets held within our environment. Deletion is completed within 30 days of contract termination, and written confirmation is available on request. - End-of-contract process
-
At the end of the contract, we work with the customer to ensure a smooth and secure off‑boarding process. We notify the customer of the upcoming contract end date and outline the steps involved. Customers are supported in exporting any final service outputs, usage reports, or configuration notes they wish to retain before termination.
Once this stage is complete, and to comply with Ordnance Survey licensing rules, we securely delete all copies of customer‑provided OS data that were ingested into the service. Deletion is carried out within 30 days of contract termination, and written confirmation can be provided on request.
We then issue a formal termination notice confirming the agreed switch‑off date for the service. At that point, all user accounts and access permissions are disabled, and the customer is notified once access has been fully withdrawn.
We also offer customers the opportunity to participate in an exit interview to capture their experience, reasons for leaving, and any feedback that may help inform future service improvements. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding and offboarding guidance is provided directly by our team and supplied to the customer via email. We guide the customer through each step of the process and deliver onboarding training for up to eight users.
All supporting user documentation is provided in accessible digital formats at the start of the contract and is also available online via the Solar Wizard website. The written content follows accessibility best practice and is presented in jargon‑free plain English. The documentation pack also includes a glossary of technical terms.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed through a standard browser‑based web interface designed with a clear layout, consistent navigation and standard HTML controls.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
Our service has been designed to be as accessible as practicable for a geospatial mapping service. The interface follows recognised accessibility good practice, including a clear visual hierarchy, consistent layouts, and keyboard navigation for core features. The service does not use flashing content, video, or time‑dependent interactions, and users can adjust their own browser settings to increase text size, contrast, or apply high‑contrast modes.
However, some map‑based interactions, are not fully accessible to users. These limitations are inherent in geospatial solutions. - Accessibility testing
- We have not conducted formal usability testing with assistive technology users. However, we follow general good‑practice web design principles to support clarity and ease of use. During routine development and QA, we focus on ensuring the interface behaves predictably and consistently for all users, with attention to straightforward navigation and clear layouts. We will respond positively to accessibility‑related feedback and would consider making reasonable adjustments where feasible.
- API
- No
- Customisation available
- Yes
- Description of customisation
- We provide standard branding configuration during onboarding, including uploading an organisation’s logo for display within the service interface. This is included as part of the onboarding process. Any subsequent branding changes are available as a chargeable service.
Scaling
- Independence of resources
- The service is designed so that typical user activity does not create excessive load on the underlying system. We monitor server performance and capacity regularly to ensure that the service continues to perform reliably for all users. Our development and database design follow good practice to minimise resource‑heavy operations, and we periodically review performance and make infrastructure or configuration improvements where needed. While we do not operate a multi‑tenant auto‑scaling architecture, we actively manage capacity and system health to minimise the risk that demand from one user affects the experience of others.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Users can export their own user‑generated data directly through the service interface, including financial modelling outputs. If a customer requires a single comprehensive extract of all data, we can provide this as an additional chargeable service.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
-
- The service does not support data import.
- All data used by the service is imported during onboarding.
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Administrative access to our servers is performed only via SSH, secured through strong authentication, hardened configurations, and tightly controlled network paths.
Availability and resilience
- Guaranteed availability
- We operate to a monthly uptime percentage of 99.5%. We don't have a set refund policy.
- Approach to resilience
- Our resilience approach focuses on maintaining a stable environment, keeping recoverable backups, and ensuring that we can restore or recreate the service in a timely manner if the need arises. We follow standard good‑practice measures to support stability and continuity. These include routine monitoring, applying security and system updates, and maintaining regular backups and snapshots.
- Outage reporting
- We notify customers of any service outage or significant disruption via email. If an issue is identified, we provide an initial notification with details of the impact and our current assessment, followed by updates as the issue progresses. A final communication is sent once the service is fully restored. For planned maintenance or expected downtime, we provide advance notice by email to all customer contacts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Access to the service is restricted to named user accounts created for each Local Authority tenant. Up to eight users are onboarded, each with individual credentials and access limited to their Local Authority area. Support staff cannot view or retrieve user passwords. Account transfers are managed by the supplier: the customer raises a request to deactivate an existing user, allowing a new user account to be created. Additional user accounts beyond the initial eight can be added at an extra charge.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We operate a risk‑based security governance model overseen by a named senior security owner. Our security policies are reviewed at least annually and updated as required. We enforce least‑privilege access, strong authentication for administrative roles, and peer‑reviewed, controlled change processes. All staff complete mandatory annual security awareness training covering phishing, data handling, incident reporting and acceptable use. Software engineers receive additional role‑specific guidance on secure coding and change control to ensure secure development practices are consistently followed.
- Information security policies and processes
-
We follow documented information security policies and processes that align with the UK Cyber Essentials scheme, which we are certified against. This includes controls for secure configuration, access management, malware protection, boundary firewalls, and the management of security updates.
System and software patches are applied in accordance with Cyber Essentials requirements, ensuring that supported versions are used and security updates are installed promptly as part of our regular maintenance process. Vulnerability checks are carried out during updates, and high‑risk issues are prioritised for rapid remediation.
Operational policies cover account management (joiners, movers, leavers), logging and monitoring, incident management, business continuity, supplier management, and data handling. Customer‑provided datasets are handled in accordance with contractual and licensing requirements, including secure deletion at contract end.
All policies and procedures are reviewed regularly and updated when risks, technology, or customer needs change. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We operate a documented configuration and change management process to ensure all updates are controlled and secure. All source code is managed in GitHub using branch protection, pull requests and mandatory peer review before changes are merged. Only authorised personnel can approve or deploy changes. Releases follow a defined release process that includes testing, review, and sign‑off before deployment to production. All changes are logged, version‑controlled, and traceable, with rollback procedures available if required. This approach ensures consistent, secure, and auditable change control across the service.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We follow supplier-defined vulnerability management controls aligned to Cyber Essentials requirements. We monitor vendor advisories and security updates for our operating systems, third-party services and software dependencies, prioritise remediation based on severity and exposure, and apply patches through our documented maintenance and release process. High-risk vulnerabilities are escalated and addressed as a priority, with changes tracked and deployed via controlled release procedures.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- System, application and access logs are collected and reviewed as part of normal operations, with alerts for error conditions or abnormal behaviour. Administrative access is logged and restricted to authorised personnel. Security‑related events identified through monitoring or reported by customers are triaged and responded to based on severity and potential impact. Critical issues are prioritised and can be acted on rapidly, with actions tracked through to full resolution.
- Incident management type
- Supplier-defined controls
- Incident management approach
- All incidents detected through monitoring, internal review or customer reports follow the same documented process. Users report incidents by emailing our support team, where they are logged and triaged by severity. High‑severity issues are prioritised and actioned rapidly. All actions are tracked through to closure, and full incident reports can be provided on request as PDF email attachments. Significant incidents undergo a post‑incident review to identify opportunities for service improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Users can generate the Solar PV potential for an individual household.
- Link to free trial
- https://solarwizard.org.uk/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Bf58754f-9688-4661-a10a-bfd241c49382
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-