AppThing - IoT Made Easy
AppThing makes IoT easy to implement and brings your data together and makes it actionable.
AppThing is a device-agnostic IoT platform that connects to any sensor, device, or data source, including LoRaWAN. Get up and running in minutes with real-time dashboards, custom reports, and smart alerts, all without complex setup.
Features
- Empowering Your IoT ecosystem with Powerful, Scalable Tools
- Custom AI Models for Meaningful Data Insights
- Customisable Dashboards and Widgets
- Real-Time Monitoring & Alerts with Scheduled Reporting
- Hierarchical, Role-Based Access
- Customisable Branding Experience
- APIs and Webhooks
- Plug and Play Integration
- Connect via via LoRaWAN, MQTT, or HTTP(s)
- Pay-as-you-go Subscription Model
Benefits
- Uncover trends and patterns to make data-driven decisions faster.
- Safeguard data by granting permissions based on roles and responsibilities
- Automate routine updates to keep informed around the clock
- Build tailored views and generate insightful reports
- Customize the platform with logo and colours for brand consistency
- Easily integrate with third-party apps for a seamless, connected ecosystem
- Seamlessly onboard LoRaWAN, MQTT, and HTTP(s) devices with zero hassle
- Track device performance live and get instant notifications
- Turning raw data into actionable insights
- Integrates with your existing systems
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 8 2 8 1 1 6 7 6 9 7 6 1 2 7
Contact
ILLUMINET SOLUTIONS LIMITED
Stephen Farmer
Telephone: 01202 770162
Email: enquiries@illuminetsolutions.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
- Search and knowledge discovery
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- No
- System requirements
-
- Public Cloud SaaS has no system requirements
- AWS Public Cloud & Virtual Private Cloud
User support
- Email or online ticketing support
- Yes
- Support response times
- To be completed
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- To be completed if applicable
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- By setting up their instance and creating the device types on AppThing. Every device type has a data model that needs to be mapped in AppThing. This allows for automatic mapping when the communication is done via MQTT. If the communication is via LoRaWAN or cloud-encoding is needed, AppThing can develop or integrate an existing decoder.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- They request a data extraction from AppThing and it can be shared in CSV files. Otherwise, they can download it themselves from the Device History report.
- End-of-contract process
- The instance is terminated, rendering all user accounts inactive, and the data is destroyed.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding documentation is provided as soon as the license is signed. Clients receive an offboarding package when they terminate the license.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The mobile application provides real-time access to alerts and overall status of your location.
The web application is a full-scale platform with users and permissions, dashboards, reports, analytics, hierarchy and application-level configurations. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- The API is both REST and Webhook. The REST application has endpoints for device status, aggregated metrics and historical data. The Webhook provides real-time integration regarding device data and alerts.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The solution can be branded with the customer logo and corporate colors. The admin role is capable of changing these settings.
Scaling
- Independence of resources
- Each appthing instance has a separate database schema and segmented cloud services. The scale of a customer does not affect other customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
System availability (by service component)
User sessions
Messages in, out
Knowledge queries
LLM interactions
Native natural language model interactions
Customer defined conversation measurements & journeys - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- From the Web interface.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
For the SaaS version of the service (hosted on vendor AWS tenant) 99.5%.
For dedicated - Approach to resilience
- The service runs on the AWS cloud platform (PaaS) and has high levels of resiliency.
- Outage reporting
-
For the SaaS instances the vendor gets notified on outages and has access to a dashboard.
For customer deployed instances (to customers AWS tenant), the customer gets notified and has access to a dashboard.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
All users are assigned roles which dictate authorized use of the management areas.
Only designated users have access to management and support pages. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Information Security Management System contains all policies & procedures to meet ISO27001.
CTO - Info security sponsor
> IT Director - Security Officer
> Internal Auditor - audits ISO27001 processes every 12 months
> External Auditor - ISO27001 surveillance audits every 12 months - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Changes are deployed monthly following software version development and testing. Testing incorporates automated unit tests, vulnerability/PEN tests, automated UI regression tests, and manual testing of new features.
Changes are firstly deployed to a UAT staging area and then to customer instances.
All changes are version controlled and system upgrades are fully audited. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We use third-party tools that monitor vulnerabilities in the libraries and frameworks utilized. When a vulnerability is discovered, it is patched within 2 weeks (1 sprint)
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Potential compromises can be detected during a monthly vulnerability scan and PEN test. These are assessed and dealt with immediately or in a future version depending on risk profile.
The support desk service manages incidents, classifying them based on severity & urgency. Engineering resource can be assigned quickly to troubleshoot. - Incident management type
- Supplier-defined controls
- Incident management approach
-
A Service Desk application is used for all incident management.
Incidents can be reported via phone, email, or web form.
Automated rule ensure rapid routing to the most appropriate service desk operative.
A customer support process is communicated to all customers and includes SLA's and reporting details. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Available depending on circumstances of request.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 7%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5ff7b083-d235-45ed-abb5-4d6b9c70aa82
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-