Confirm Enterprise Asset Management
Enterprise asset management software aligned to ISO 55001, enabling councils to manage assets, services and people across highways, street lighting, structures, drainage, green spaces, trees, waste, recycling and other public assets. A unified asset register supports risk-based inspections, work scheduling and end-to-end workflows, with dashboards, GIS and reporting.
Features
- Flexible asset register capturing condition, financial, operational data across assets.
- Smart IoT/connected assets for automated monitoring, Unadopted Roads Inspection
- Condition surveys, safety inspections, RBIs, UKPMS, SCANNER, CVI, mobile GN22.
- Supports highways, ILP lighting, DMRB structures, drainage, waste, parks, trees.
- Citizen enquiries linking issues / faults, service requests against assets.
- Configurable dashboards, KPIs, analytics, email reporting, aligned with reporting standards.
- Integrations: GIS, finance, CRM, Contractors, IoT, mobile, NSG, LSG, What3Words.
- Strategic lifecycle modelling, pavement management, UKRLG guidance and risk visualisation.
- Works management, smart work scheduling, field-crew allocation, mobile working.
- Street Manager integration supporting NRSWA, permits, noticing and compliance.
Benefits
- Lifecycle Management: Costing and prioritisation for smarter, evidence-based decisions.
- Risk-Based Optimisation: Improves service, asset effectiveness, and regulatory compliance.
- Spatial Intelligence: ESRI, MapInfo, WMS, GIS integration for planning insights.
- Citizen Engagement: Enables real-time reporting and interactive communication.
- Operational Visibility: Complete activity history with real-time workflow optimisation.
- Contractor Management: Streamlines coordination, prioritises work, improves delivery efficiency.
- Sustainability: Assesses condition, whole-life costs, carbon impact for interventions.
- Predictive Analytics: Prevent failures, reduce costs, plan proactive maintenance strategically.
- Mobile Field Support: Online/offline Apple iOS and Android access.
- Supports: pavement & footways, parks & grounds, bridges, gullies, arboriculture.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 8 0 1 0 3 5 1 2 0 5 3 3 3 8
Contact
BRIGHTLY SOFTWARE LIMITED
Siemens Asset Management Software - UK Sales Team
Telephone: +44 (0) 808 167 4526
Email: ams-uk-gcloud.si@siemens.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Asset life-cycle management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Planned maintenance activities are scheduled in advance, and any expected downtime is communicated to clients beforehand. These maintenance windows are carefully planned to minimize disruption.
- System requirements
-
- Suitable modern browser (Edge, Chrome, Firefox, Safari).
- Mobile device (iOS, Android).
User support
- Email or online ticketing support
- Yes
- Support response times
- Brightly provides 24x7x365 technical support via telephone, email (support@brightlysoftware.com), and chat where available. Tier 1 support handles initial requests, resolving many issues through guidance on features, functionality, and known workarounds. More complex issues are escalated to Tier 2 support, and confirmed software defects are further escalated to Brightly’s technology teams for resolution. Severity 1 production issues should be reported by telephone. All production issues are logged in Brightly’s enterprise tracking system and managed according to defined severity, response, and resolution targets.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Brightly provides 24x7x365 technical support via telephone, email (support@brightlysoftware.com), and chat where available. Tier 1 support handles initial requests, resolving many issues through guidance on features, functionality, and known workarounds. More complex issues are escalated to Tier 2 support, and confirmed software defects are further escalated to Brightly’s technology teams for resolution. Severity 1 production issues should be reported by telephone. All production issues are logged in Brightly’s enterprise tracking system and managed according to defined severity, response, and resolution targets.
Each client is assigned an individual Account Manager and a Client Success Consultant to provide additional support during the term of the contract. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Our experienced and qualified Professional Services team have a diverse array of software, training, engineering and asset management backgrounds. We implement the vision and business outcomes of our clients, working collaboratively across all relevant teams, and provide a seamless experience for our clients whether they need one-off consultancy or a large-scale implementation.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- We will provide an export of the customers data. Document files, such as photographs, will also be exported. These will be made available to download.
- End-of-contract process
- We will provide an export of the customers data. Document files, such as photographs, will also be exported. These will be made available to download.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The ConfirmConnect mobile app is designed specifically for field-based users undertaking a range of on-site tasks, including asset surveys, condition inspections, customer enquiries, maintenance jobs and Street Works inspections. The app is designed to work without the requirement for an 'always on' connection. The app also uses the GPS capability of the mobile device to show the user's current location.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service user interface is a modern web client, accessible using a modern browser (Edge, Chrome, Firefox, Safari).
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Accessibility testing tools are used by our developers, testers and designers to ensure Confirm meets accessibility standards.
- API
- Yes
- What users can and can't do using the API
- Confirm provides a suite of fully documented API's. Establishing integrations with other corporate systems such as GIS, CRM, finance, contractor and IoT devices are typical uses of the API's.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The service is highly configurable without requiring software development. For example, business process workflows, validation rules, lookups and map layers are all configurable.
Configuration of the service would be a client System Administrator role. Brightly provide user manuals, online knowledge articles and online training videos to support System Administrators. In addition, our Professional Services team can provide training and consultancy services.
Scaling
- Independence of resources
- Brightly ensures stable performance in Confirm by running it as a multi‑tenant, cloud‑hosted application designed to scale as demand increases. The multi‑tenant architecture prevents one tenant’s activity from affecting another’s performance. Automated scaling, monitoring, and operational safeguards help maintain responsiveness even during periods of high demand.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- AWS adhers to global security standards like ISO 27001, PCI DSS, and HIPAA. Encryption happens at multiple layers, from storage disks (NVMe uses XTS-AES-256 in hardware) to application-level data, ensuring compliance and broad protection.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can use the reporting tools built-in to the user interface to export data from the system, on either ad hoc or scheduled basis. APIs are also available to access and export data from the system.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- TXT
- Map Layer - Mapinfo TAB
- HTML
- SQL
- XML
- Tab Delimited Text
- JSON
- Dbase3
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML
- JSON
- Tab Delimited Text
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- At least 99.00%.
- Approach to resilience
- Available on request.
- Outage reporting
- Brightly communicates outages via Pendo, email, and online via our Status Page.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access management processes are in place that meet the requirements of ISO27001.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Brightly follows a comprehensive Information Security Management System (ISMS) based on ISO/IEC 27001 and NIST 800-53 frameworks, reinforced by CE+ compliance. Our policies cover access control, data protection, incident response, and vendor risk management. Governance is led by the Chief Security Officer (CISO) and supported by the Security Incident Response Team (SIRT), which includes senior leadership from IT, Legal, and Client Services. We ensure adherence through documented standards, mandatory employee training, continuous monitoring via SIEM systems, and regular audits. Incident response processes mandate classification, containment, and client notification within 72 hours, with escalation to Siemens CERT when required. This structure guarantees accountability and consistent enforcement across all operations.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Brightly maintains a formal configuration and change management program aligned with industry best practices and CE+ requirements. Service components are tracked throughout their lifecycle using centralized asset inventories and Infrastructure-as-Code (IaC) methodologies for cloud environments. Changes to production systems follow a structured process governed by the Production Change Control Board (PCCB), which meets regularly to review, authorize, and document changes. Change requests undergo rigorous assessment for potential security impact, including testing and approval before deployment. Emergency changes are handled under strict incident response protocols. Release notes and client notifications ensure transparency, while automated monitoring and audit logs provide continuous oversight.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Brightly implements a structured vulnerability and patch management program following our defined policy. We conduct regular vulnerability scans across our infrastructure and applications to identify security weaknesses. Identified vulnerabilities are prioritized based on severity and remediated according to timelines established in our vulnerability management policy.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Brightly implements a Security Information and Event Management (SIEM) solution that aggregates and correlates log data from across our infrastructure to provide real-time threat detection and security monitoring. Our SIEM platform enables advanced security analytics, automated alerting for suspicious activities, and detailed forensic capabilities that support rapid incident investigation and response.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Brightly's incident reporting approach includes multiple reporting channels, clear guidelines for what constitutes an incident, defined escalation paths to the Security Incident Response Team, and documentation procedures to ensure security incidents are properly recorded, tracked, and addressed according to their severity and potential impact within our established security framework.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI Assurance UK Ltd
- ISO/IEC 27001 accreditation date
- Monday 4 December 2023
- What the ISO/IEC 27001 doesn’t cover
- The information security management system covers the creation, support, sales, and supply of Confirm software and associated services to local government, central government, and the commercial sector.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI Assurance UK Ltd
- ISO 9001 accreditation date
- Tuesday 18 June 2024
- What the ISO 9001 doesn’t cover
- The quality management system covers the creation, support, sales, and supply of Confirm software and associated services to local government, central government, and the commercial sector.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 72c00570-5a5b-4242-92fe-02a3b72282ff
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 7c8790dd-c3c6-409b-9be8-709ff89169ae
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-