Skip to main content

Help us improve the Digital Marketplace - send your feedback

BRIGHTLY SOFTWARE LIMITED

Confirm Enterprise Asset Management

Enterprise asset management software aligned to ISO 55001, enabling councils to manage assets, services and people across highways, street lighting, structures, drainage, green spaces, trees, waste, recycling and other public assets. A unified asset register supports risk-based inspections, work scheduling and end-to-end workflows, with dashboards, GIS and reporting.

Features

  • Flexible asset register capturing condition, financial, operational data across assets.
  • Smart IoT/connected assets for automated monitoring, Unadopted Roads Inspection
  • Condition surveys, safety inspections, RBIs, UKPMS, SCANNER, CVI, mobile GN22.
  • Supports highways, ILP lighting, DMRB structures, drainage, waste, parks, trees.
  • Citizen enquiries linking issues / faults, service requests against assets.
  • Configurable dashboards, KPIs, analytics, email reporting, aligned with reporting standards.
  • Integrations: GIS, finance, CRM, Contractors, IoT, mobile, NSG, LSG, What3Words.
  • Strategic lifecycle modelling, pavement management, UKRLG guidance and risk visualisation.
  • Works management, smart work scheduling, field-crew allocation, mobile working.
  • Street Manager integration supporting NRSWA, permits, noticing and compliance.

Benefits

  • Lifecycle Management: Costing and prioritisation for smarter, evidence-based decisions.
  • Risk-Based Optimisation: Improves service, asset effectiveness, and regulatory compliance.
  • Spatial Intelligence: ESRI, MapInfo, WMS, GIS integration for planning insights.
  • Citizen Engagement: Enables real-time reporting and interactive communication.
  • Operational Visibility: Complete activity history with real-time workflow optimisation.
  • Contractor Management: Streamlines coordination, prioritises work, improves delivery efficiency.
  • Sustainability: Assesses condition, whole-life costs, carbon impact for interventions.
  • Predictive Analytics: Prevent failures, reduce costs, plan proactive maintenance strategically.
  • Mobile Field Support: Online/offline Apple iOS and Android access.
  • Supports: pavement & footways, parks & grounds, bridges, gullies, arboriculture.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ams-uk-gcloud.si@siemens.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 8 0 1 0 3 5 1 2 0 5 3 3 3 8

Contact

BRIGHTLY SOFTWARE LIMITED Siemens Asset Management Software - UK Sales Team
Telephone: +44 (0) 808 167 4526
Email: ams-uk-gcloud.si@siemens.com

About your service

Service categories

Applications

Enterprise resource management

  • Asset life-cycle management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Planned maintenance activities are scheduled in advance, and any expected downtime is communicated to clients beforehand. These maintenance windows are carefully planned to minimize disruption.
System requirements
  • Suitable modern browser (Edge, Chrome, Firefox, Safari).
  • Mobile device (iOS, Android).

User support

Email or online ticketing support
Yes
Support response times
Brightly provides 24x7x365 technical support via telephone, email (support@brightlysoftware.com), and chat where available. Tier 1 support handles initial requests, resolving many issues through guidance on features, functionality, and known workarounds. More complex issues are escalated to Tier 2 support, and confirmed software defects are further escalated to Brightly’s technology teams for resolution. Severity 1 production issues should be reported by telephone. All production issues are logged in Brightly’s enterprise tracking system and managed according to defined severity, response, and resolution targets.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Brightly provides 24x7x365 technical support via telephone, email (support@brightlysoftware.com), and chat where available. Tier 1 support handles initial requests, resolving many issues through guidance on features, functionality, and known workarounds. More complex issues are escalated to Tier 2 support, and confirmed software defects are further escalated to Brightly’s technology teams for resolution. Severity 1 production issues should be reported by telephone. All production issues are logged in Brightly’s enterprise tracking system and managed according to defined severity, response, and resolution targets.
Each client is assigned an individual Account Manager and a Client Success Consultant to provide additional support during the term of the contract.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Our experienced and qualified Professional Services team have a diverse array of software, training, engineering and asset management backgrounds. We implement the vision and business outcomes of our clients, working collaboratively across all relevant teams, and provide a seamless experience for our clients whether they need one-off consultancy or a large-scale implementation.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
We will provide an export of the customers data. Document files, such as photographs, will also be exported. These will be made available to download.
End-of-contract process
We will provide an export of the customers data. Document files, such as photographs, will also be exported. These will be made available to download.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The ConfirmConnect mobile app is designed specifically for field-based users undertaking a range of on-site tasks, including asset surveys, condition inspections, customer enquiries, maintenance jobs and Street Works inspections. The app is designed to work without the requirement for an 'always on' connection. The app also uses the GPS capability of the mobile device to show the user's current location.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service user interface is a modern web client, accessible using a modern browser (Edge, Chrome, Firefox, Safari).
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Accessibility testing tools are used by our developers, testers and designers to ensure Confirm meets accessibility standards.
API
Yes
What users can and can't do using the API
Confirm provides a suite of fully documented API's. Establishing integrations with other corporate systems such as GIS, CRM, finance, contractor and IoT devices are typical uses of the API's.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service is highly configurable without requiring software development. For example, business process workflows, validation rules, lookups and map layers are all configurable.

Configuration of the service would be a client System Administrator role. Brightly provide user manuals, online knowledge articles and online training videos to support System Administrators. In addition, our Professional Services team can provide training and consultancy services.

Scaling

Independence of resources
Brightly ensures stable performance in Confirm by running it as a multi‑tenant, cloud‑hosted application designed to scale as demand increases. The multi‑tenant architecture prevents one tenant’s activity from affecting another’s performance. Automated scaling, monitoring, and operational safeguards help maintain responsiveness even during periods of high demand.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
AWS adhers to global security standards like ISO 27001, PCI DSS, and HIPAA. Encryption happens at multiple layers, from storage disks (NVMe uses XTS-AES-256 in hardware) to application-level data, ensuring compliance and broad protection.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Degaussing
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can use the reporting tools built-in to the user interface to export data from the system, on either ad hoc or scheduled basis. APIs are also available to access and export data from the system.
Data export formats
  • CSV
  • Other
Other data export formats
  • TXT
  • Map Layer - Mapinfo TAB
  • HTML
  • PDF
  • SQL
  • XML
  • Tab Delimited Text
  • JSON
  • Dbase3
Data import formats
  • CSV
  • Other
Other data import formats
  • XML
  • JSON
  • Tab Delimited Text

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
At least 99.00%.
Approach to resilience
Available on request.
Outage reporting
Brightly communicates outages via Pendo, email, and online via our Status Page.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access management processes are in place that meet the requirements of ISO27001.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Brightly follows a comprehensive Information Security Management System (ISMS) based on ISO/IEC 27001 and NIST 800-53 frameworks, reinforced by CE+ compliance. Our policies cover access control, data protection, incident response, and vendor risk management. Governance is led by the Chief Security Officer (CISO) and supported by the Security Incident Response Team (SIRT), which includes senior leadership from IT, Legal, and Client Services. We ensure adherence through documented standards, mandatory employee training, continuous monitoring via SIEM systems, and regular audits. Incident response processes mandate classification, containment, and client notification within 72 hours, with escalation to Siemens CERT when required. This structure guarantees accountability and consistent enforcement across all operations.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Brightly maintains a formal configuration and change management program aligned with industry best practices and CE+ requirements. Service components are tracked throughout their lifecycle using centralized asset inventories and Infrastructure-as-Code (IaC) methodologies for cloud environments. Changes to production systems follow a structured process governed by the Production Change Control Board (PCCB), which meets regularly to review, authorize, and document changes. Change requests undergo rigorous assessment for potential security impact, including testing and approval before deployment. Emergency changes are handled under strict incident response protocols. Release notes and client notifications ensure transparency, while automated monitoring and audit logs provide continuous oversight.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Brightly implements a structured vulnerability and patch management program following our defined policy. We conduct regular vulnerability scans across our infrastructure and applications to identify security weaknesses. Identified vulnerabilities are prioritized based on severity and remediated according to timelines established in our vulnerability management policy.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Brightly implements a Security Information and Event Management (SIEM) solution that aggregates and correlates log data from across our infrastructure to provide real-time threat detection and security monitoring. Our SIEM platform enables advanced security analytics, automated alerting for suspicious activities, and detailed forensic capabilities that support rapid incident investigation and response.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Brightly's incident reporting approach includes multiple reporting channels, clear guidelines for what constitutes an incident, defined escalation paths to the Security Incident Response Team, and documentation procedures to ensure security incidents are properly recorded, tracked, and addressed according to their severity and potential impact within our established security framework.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI Assurance UK Ltd
ISO/IEC 27001 accreditation date
Monday 4 December 2023
What the ISO/IEC 27001 doesn’t cover
The information security management system covers the creation, support, sales, and supply of Confirm software and associated services to local government, central government, and the commercial sector.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI Assurance UK Ltd
ISO 9001 accreditation date
Tuesday 18 June 2024
What the ISO 9001 doesn’t cover
The quality management system covers the creation, support, sales, and supply of Confirm software and associated services to local government, central government, and the commercial sector.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
72c00570-5a5b-4242-92fe-02a3b72282ff
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
7c8790dd-c3c6-409b-9be8-709ff89169ae
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ams-uk-gcloud.si@siemens.com. Tell them what format you need. It will help if you say what assistive technology you use.