Atlas
Atlas is a complete digital planning system. It features a revolutionary planning register improving transparency and engagement. Atlas also includes an optional back office module based on the Government open source Back Office Planning System (BOPS), adapted and fully supported by Tytl and integrated seamlessly with the register.
Features
- Applications Module
- Registration & Validation to Appeal Stages
- Consultation Functions
- Document Management System
- Interactive Map
- Advanced Search
- Advanced Filters
- Contextual Map Layers
- Highly Responsive Page Loading
- Whitelabelled Branding
Benefits
- Enhanced Planning Transparency
- Improved Digitial Citizen Engagement
- Reduced Planning Support Enquiries
- Operational Efficiency Gains
- Dramatically Improved User Experience
- Reduce Context Switching
- Remove 3rd Party App Requirements
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 2 6 2 0 7 2 2 5 8 2 3 4 1 0
Contact
Tytl
Thomas McAlpine
Telephone: 07725686868
Email: thomas@tytl.com
About your service
- Service categories
-
Applications
Content workflow and management
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No constraints. Atlas is a complete digital planning system that can operate as a front end register integrated with any existing back office solution or as a full stack platform with its own back office module based on a proven Government open source system. Atlas integrates with Planning Portal when required and can also receive and validate applications directly. Each authority runs in its own secure AWS environment with full support provided by Tytl. We can deploy Atlas in any configuration needed, with no technical or contractual constraints.
- System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 24 hours (including weekends)
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide access to telephone support between 9am and 6pm, weekdays.
For emails, we will respond within 24 hours (including weekends).
For technical fixes, these will be within 24 hours for Severe issues, 48 hours for Moderate issues and within a week for Minor issues.
For in-person support for issues not caused by us, travel costs and an hourly rate of £100.00 will apply. Issues caused by us will be free of charge.
All customers will have a dedicated account manager. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- We work hand in hand with customers during an integration phase. In this period we ensure our platform is fully integrated with the customer's systems. We then thoroughly test with the customer in a safe non-public environment to comfirm all data is being passed normally. Prior and following launch we provide support as detailed in our support services.
- Service documentation
- No
- End-of-contract data extraction
- Data is constantly being exchanged in both directions. So the customer will already have all of their data. However, if for whatever reason they do not, we can make their data available to them in any format they choose.
- End-of-contract process
- If a customer chooses to end a contract, we will handover all data and remove our data intregrations. We will provide support to ensure continuity for the customer. There would only be extra charges if we were asked to help setup a new supplier.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Full functionality across mobile and desktop
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
All branding can be customised including logo and colour scheme.
Customers can also request for custom map layers to be added.
Scaling
- Independence of resources
- Each customer has their own environment in our cloud hosting architecture. Meaning they have their own dedicated servers to deliver their particular solution.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We measure unique visitors, cases viewed, comments received and documents viewed.
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- This is done automatically via automated data pipelines using an SFTP server.
- Data export formats
-
- CSV
- Other
- Other data export formats
- All normal formats
- Data import formats
-
- CSV
- Other
- Other data import formats
- All normal formats
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee that our service will have uptime of 99.99%, although we aim for 100% availability. Any scheduled downtime for maintenance will be given notice in advance and take place outside normal working hours.
If the service is not available for more than the above stated SLA , then we will offer pro-rated refunds. - Approach to resilience
- This is available upon request
- Outage reporting
- We have email alerts that will notify relevant users of an outage. We can then deploy further onsite notifications if required.
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- Our service is available to the Public. Any communication channels are secured by cloud service providers.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Other
- Description of management access authentication
- The service is available to the Public.
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We use industry best practices both in our development and delivery of our service. This includes the continuous data security practices that we utilise to monitor our services on an ongoing basis.
- Information security policies and processes
-
We have a document available to buyers:
Addland Limited Data Protection, Cybersecurity and Business Continuity Policy - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- The Atlas service is specifically secured within our organisation to only those directly involved in the ongoing development and delivery of the products. All aspects of delivery and changes are managed directly by a Board level team member.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We run a continuous vulnerability management process across all environments. We assess potential threats through automated scanning, manual review and regular security assessments. Threat intelligence is taken from trusted sources including NCSC advisories, vendor bulletins and industry security feeds. Once a vulnerability is identified we triage by severity and apply patches as quickly as possible, with critical issues patched within twenty four hours in most cases. All updates are deployed through controlled release pipelines with full logging and verification. We review our process regularly to ensure it meets current security standards.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We operate continuous protective monitoring across our platform. We use automated alerting, log analysis and anomaly detection to identify potential compromises, including unusual access patterns, failed authentication attempts and unexpected system behaviour.
When a potential compromise is detected, our support and engineering teams are alerted immediately. We triage the event, contain any affected systems, and conduct rapid root cause analysis. If needed, we escalate to our senior security leads.
We aim to respond to all incidents within minutes. Urgent or high risk events are acted on immediately, with follow up investigation and remediation completed as quickly as possible. - Incident management type
- Supplier-defined controls
- Incident management approach
- We maintain pre defined processes for common events including service outages, security alerts and data access issues. Users can report incidents through our support portal or by email, which raises a ticket with our team. After an incident is resolved we provide a clear written report detailing the cause, impact and actions taken.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5bbead2f-4213-4bf6-a33e-8dff4516d870
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-