Probit Asset Investment Manager
Probit Asset Investment Manager is a cloud-hosted SaaS platform that helps asset-intensive organisations model and optimise capital and operational investments. It integrates risk, performance and cost data to support data-driven decisions, scenario analysis and long-term investment planning. Enabling transparent, defensible strategies that maximise asset value and align with organisational goals.
Features
- Asset-level investment modelling across large infrastructure portfolios
- Scenario analysis to compare funding, risk and performance trade-offs
- Optimisation engine to determine optimal investment portfolios under constraints
- Integrated risk, performance and cost-based decision frameworks
- Long-term and short-term capital programme generation
- Interactive dashboards and configurable reporting for stakeholders
- Scalable data processing supporting millions of individual assets
- Cloud-hosted SaaS with secure, browser-based remote access
- API and data integration with external asset and corporate systems
- Audit-ready outputs supporting regulatory and governance requirements
Benefits
- Make defensible investment decisions using transparent, optimisation-based evidence
- Optimise asset investment strategies across cost, risk and performance objectives
- Answer complex investment questions in minutes, not days or weeks
- Reduce inefficient spend caused by prioritisation and single-metric ranking
- Align investment plans with regulatory, service and stakeholder requirements
- Clearly understand trade-offs between risk reduction, cost and outcomes
- Adapt investment strategies quickly as data, constraints or objectives change
- Improve organisational confidence in long-term capital investment decisions
- Retain full in-house ownership of investment models and assumptions
- Enable collaborative investment planning across internal teams and partners
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 2 4 5 0 7 6 4 0 9 4 8 0 1 0
Contact
PROBIT LTD
Philip Jonkergouw
Telephone: 01606 610002
Email: hello@probit.io
About your service
- Service categories
-
Applications
Enterprise resource management
- Asset life-cycle management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service is subject to planned maintenance for software updates and upgrades, with advance notification provided. Emergency maintenance may also be undertaken where required to address security or service stability issues, managed to minimise disruption. The service is accessed via a modern web browser; due to its data-rich nature, larger displays (for example Full HD resolution or higher) are recommended for effective use.
- System requirements
-
- Modern standards-compliant web browser with JavaScript enabled.
- Stable internet connection suitable for cloud-based applications.
- HTTPS access permitted through organisational firewalls.
- Minimum 4 GB system memory available.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Email ticketing support is provided during UK Working Hours (09:00–17:00, Monday to Friday, excluding UK public holidays). Incidents are prioritised by severity.
Initial response targets are: Priority 1 (Critical) within 1 working hour; Priority 2 (High) within 4 working hours; Priority 3 (Medium) within 2 working days; Priority 4 (Low) within 5 working days. Requests logged outside Working Hours are typically actioned on the next Working Day unless otherwise agreed. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
The service is provided with standard support included as part of the SaaS subscription. Standard support is delivered via email during UK Working Hours (09:00–17:00, Monday to Friday, excluding UK public holidays).
Support requests are prioritised according to severity, with defined response targets for critical, high, medium and low priority incidents, as set out in the service SLA.
Support covers incident management, fault resolution, service availability issues, and general assistance with use of the platform. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
The supplier supports users in getting started through a combination of onboarding support, training and documentation. Online training sessions are provided to introduce users to the service, its core concepts and workflows. Onsite training can also be delivered where preferred, subject to agreement, to support hands-on learning and engagement with user teams.
The service includes contextual, in-application user guidance to support day-to-day use, helping users understand functionality and workflows at the point of use.
During onboarding, the supplier works with the buyer to configure the service to their requirements and ensure users are able to operate the platform effectively.
Where required, additional support services such as tailored training sessions, bespoke documentation or extended onboarding support can be provided by agreement. Any such additional services are scoped and priced separately as part of the relevant Call-Off Contract. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
At the end of the contract, users can extract their data directly from the service. Data can be exported through the user interface using configurable, user-defined reports, with outputs available in common formats such as Excel, CSV and plain text.
Where enabled, data can also be extracted programmatically via the web services API, allowing buyers to retrieve data for migration or archiving purposes.
Data extraction facilities are designed to provide flexibility, enabling buyers to select the scope and structure of the data required.
Where a buyer requires a specific or bespoke data extract that is not achievable through standard reporting or API access, Probit can provide a custom data extract by agreement. Any such bespoke extraction services are scoped and provided for a reasonable additional fee as part of the Call-Off Contract. - End-of-contract process
-
At the end of the contract, Probit supports an orderly service exit and data handover. Prior to contract termination, users are able to extract their data using standard reporting tools, export functionality and, where enabled, the web services API, in accordance with the service’s data extraction capabilities.
Once the contract has ended and any agreed data extraction period has completed, Probit securely and permanently sanitises and deletes the buyer’s data, in line with agreed data retention periods and Probit’s information security policies.
The contract price includes standard end-of-contract activities, including continued access to the service until contract expiry, standard data export facilities, and secure data sanitisation following termination.
Additional exit support, such as extended access periods, bespoke data extracts, assistance with migration to another system, or additional documentation, can be provided by agreement. Any such services are scoped and charged separately as part of the relevant Call-Off Contract. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, browser-based web interface. Users authenticate using individual accounts and interact with dashboards, visualisations and analytical views to configure models, explore data and review outputs. All core functionality available through the user interface is also accessible via web services, which may be enabled as an optional add-on to support system integration and automation. No local software installation or specialist client applications are required.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service has not been formally tested with users of assistive technology. The interface is designed with reference to WCAG 2.2 AA principles and is reviewed using a combination of automated accessibility testing tools and manual checks. Automated testing is used to assess factors such as colour contrast, text sizing and general accessibility issues, while manual testing is carried out to verify keyboard navigation and ensure core functionality is accessible without reliance on a mouse. Accessibility considerations are reviewed as part of ongoing interface design and improvement.
- API
- Yes
- What users can and can't do using the API
-
The service provides an optional web services API, enabled as an add-on, which exposes the same core functionality available through the user interface. Where enabled, the API allows users to integrate with external systems, automate data exchange, configure models, trigger analyses and optimisation runs, and retrieve results programmatically.
API access is enabled by the supplier as an optional service add-on and is secured using authenticated credentials and role-based permissions consistent with the user interface. Users can create, update and manage data and configurations within the scope of their assigned permissions.
Limitations include rate-limiting, permission controls, and the requirement that API access is explicitly enabled as part of the service subscription.
An API sandbox environment is also available as a separate service add-on. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The service is provided as a single, shared SaaS platform that can be customised through configuration rather than bespoke development. Buyers can customise data structures, asset models, assumptions, parameters, valuation frameworks, constraints and analytical scenarios to reflect their organisational requirements.
Customisation is performed through the browser-based user interface and, where enabled, via the optional web services API. Configuration changes can be applied without code changes or software deployment.
Customisation is carried out by authorised users within the buyer organisation, based on role-based access controls. Typically, system administrators and advanced users are able to configure models and parameters, while standard users interact with pre-configured views and workflows. Core platform functionality remains consistent across all users, ensuring a maintainable and scalable SaaS service.
Scaling
- Independence of resources
- The service is delivered on cloud infrastructure designed to scale to meet demand. Capacity is monitored and adjusted to ensure that user workloads are not adversely affected by other users of the service. Performance and availability are governed by the service SLA, which defines service levels and response targets. The platform supports deployment on shared infrastructure for multi-tenant use and, where required, on dedicated infrastructure for individual buyers, ensuring appropriate isolation and performance based on buyer needs.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data directly from the service using configurable, user-defined reports, with outputs available in common formats such as Excel, CSV and plain text. Where enabled, data can also be exported programmatically via the optional web services API to support integration, migration or archiving. Data export facilities allow users to control the scope and structure of exported data, ensuring flexibility while using open, non-proprietary formats.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Microsoft Excel
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Our public cloud provider utilises AES 128 or 256 encryption between our internal network components. We also make use of TLS 1.2 or above for some of our application interconnects.
Availability and resilience
- Guaranteed availability
-
The service is provided with a defined availability commitment set out in the service SLA. The supplier targets a minimum service availability of 99.5% per calendar month, excluding planned maintenance periods and circumstances beyond the supplier’s reasonable control, as defined in the SLA.
Where service availability falls below the agreed target in a given month, buyers may be eligible for service credits in accordance with the SLA. Service credits are calculated as a proportion of the monthly service charges and are applied as a credit against future invoices.
Service credits represent the buyer’s sole and exclusive remedy for failure to meet the availability commitment, as set out in the SLA. The SLA and availability commitments apply equally to services delivered on shared or dedicated infrastructure, where applicable. - Approach to resilience
- The service is designed for resilience using cloud-based infrastructure with redundancy, monitoring, and regular backup processes. Data is backed up in accordance with defined backup and restore policies, with recovery objectives appropriate to the service and buyer requirements. Disaster recovery and business continuity arrangements are in place and reviewed periodically. The underlying cloud platforms provide resilient datacentre environments with physical security, power redundancy, and network resilience. Further details of resilience, backup, and recovery arrangements are available on request.
- Outage reporting
- Service availability is monitored, and outages are reported directly to affected buyers via email notifications. Incidents are logged, managed and communicated in accordance with the Service Level Agreement. Service up-time and availability are reported to buyers on a regular basis, typically as part of monthly service reporting. A public status dashboard or outage reporting API is not currently provided.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted to authorised personnel only. Role-based access controls are used to ensure users and staff have access only to the functions required for their role.
Administrative access is limited to a small number of trained staff and is protected through strong authentication mechanisms. Access to support systems is similarly restricted, with permissions managed and reviewed periodically. All access is logged and monitored to support accountability and incident investigation. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is led by a named senior security lead with responsibility for the security of all services, operating with delegated authority from senior management. The organisation maintains documented security policies and procedures covering areas such as access control, secure development, incident management, vulnerability management and data protection. Security risks are identified, assessed and managed on an ongoing basis, and controls are reviewed periodically. The approach aligns with recognised good practice, including the Software Security Code of Practice, and is supported by regular monitoring, staff awareness and incident response processes.
- Information security policies and processes
-
The organisation operates a defined set of information security policies and processes covering areas including access control, data protection, secure development, incident management, vulnerability management, backup and recovery, and supplier security. These policies are approved and overseen by senior management and are applicable to all services and staff.
Information security governance is led by a named senior security lead with responsibility for security across all services, operating with delegated authority from senior management. This role is responsible for maintaining policies, assessing risk, overseeing incident response, and ensuring appropriate controls are implemented.
Policies are supported by operational procedures and technical controls, including role-based access controls, monitoring, logging, and regular review of security events. Compliance with policies is reinforced through staff onboarding, awareness activities and defined escalation processes. Security incidents are recorded, investigated and managed in line with documented procedures, with lessons learned used to inform continuous improvement. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Service components and configurations are managed using defined version control and deployment processes. Changes to the service, including configuration and software updates, are recorded and tracked through their lifecycle. Proposed changes are assessed for operational and security impact prior to implementation, with security considerations reviewed as part of the change process. Changes are tested before deployment and are implemented in a controlled manner. Security-related changes and incidents are escalated and managed in accordance with Probit’s security governance and incident management procedures.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Potential threats to the service are assessed through a combination of internal review, monitoring and supplier notifications. Vulnerability information is obtained from cloud service providers, software vendors, security advisories and trusted public sources. Probit maintains Cyber Essentials certification, which underpins baseline controls for patching, malware protection and secure configuration. Identified vulnerabilities are assessed for risk and impact, including potential security implications for the service. Security patches and mitigations are prioritised based on severity and are deployed in a timely manner using controlled change processes. Critical security patches are applied as soon as practicable.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The service is subject to ongoing protective monitoring to identify potential security incidents or compromises. Monitoring includes review of service logs, alerts and cloud platform monitoring outputs to detect unusual activity or potential threats. Identified events are assessed and, where a potential compromise is suspected, are escalated in accordance with the incident management process. Probit aims to respond to security incidents promptly, with initial investigation and containment actions initiated as soon as practicable, and critical incidents prioritised for immediate response. Incidents are managed and resolved in line with documented procedures and service commitments.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Probit operates defined incident management processes, including pre-defined procedures for common service and security events. Users can report incidents through the standard support channels, including email and the online ticketing system. Reported incidents are logged, prioritised and managed in accordance with the Service Level Agreement. Where appropriate, buyers are kept informed of incident progress through direct communication. Incident reports and post-incident summaries can be provided to buyers on request, including details of impact, resolution actions and any preventative measures identified.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8ed15615-22e4-4152-8e97-0d18660d6d16
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-