SafeZone
CriticalArc, a global tech innovator, designs and delivers a distributed command and control solution, SafeZone™, which is revolutionising the way organisations manage day-to-day safety and security operations. SafeZone provides response teams with complete operational awareness, to enhance the protection of dispersed people, facilities, and assets, while delivering efficiency savings
Features
- Unified Safety, Security, Wellbeing and Emergency Management System
- High Risk and Lone Worker Management
- Real time team co-ordination and Emergency Response
- Mentalhealth and Wellbeing
- Active Threat Management
- Indoor Positioning
- Mass and Targetting communications
- Tip Reporting
- Audible alerting
Benefits
- Unified Solution reducing cost and silo'd systems
- Reduces costs & increases efficiency
- Eliminate capital costs
- Enhances Security & Business Continuity
- Improves Incident Response
- Optimises Resources & Assets
- Increases Staff and Student Safety
- Enables Collaboration
- Ultra-Fast, Reliable and Highly-secure
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 2 4 6 5 6 0 5 0 0 4 9 2 6 8
Contact
CRITICALARC LTD
Iain Pennell
Telephone: +44 7841 833398
Email: iain@criticalarc.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Per service agreement
- System requirements
- Web Browser Interface
User support
- Email or online ticketing support
- Yes
- Support response times
-
SLA's are listed within the SafeZone Security Software Agreement with two support offerings: Standard - Monday to Friday 9am-6pm Premium - 24/7 (20% additional cost on the support / maintenance costs)
Both options include remote and onsite services at no additional cost aligned to our SLA and KPI's. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
Two support offerings: Standard - Monday to Friday 9am-6pm, Premium - 24/7 (20% additional cost on the support / maintenance costs)
Both options include remote and onsite services at no additional cost aligned to our SLA and KPI's. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Onsite consultation, configuration, training and ongoing support. Full marketing campaign/templates provided to customers at no additional cost Ongoing product training, knowledge transfer from other users and an annual conference bringing together all customers for best use case sharing of ideas and vision for the platform
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Interfaces are available via the administration web pages to export data. In addition, full database exports are available via support requests.
- End-of-contract process
- At contract end, CriticalArc will either return or securely delete client data, based on the client’s written instruction, with processes validated by audits and aligned to GDPR and other privacy laws.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Fully mobile optimised. Omniguard, SafeZone and SafeTrans apps are all smartphone applications, and the SafeZone web service is also designed to work on mobile
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Users with appropriate permissions have access to the admin interface. General configuration of the software, service and admin can be conducted through this interface.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Annual CriticalArc Conformance Report completed based on VPAT 2.0
- API
- Yes
- What users can and can't do using the API
- The SafeZone API provides a robust way to integrate SafeZone’s user management, group handling, and alerting with external systems. It enables automation of administrative tasks, synchronization of user directories, and incident reporting into or out of SafeZone.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Features, functions, and workflows are customizable by specific users with appropriate permissions/training.
Scaling
- Independence of resources
- Via automated tools using our Microsoft Azure infrastructure allowing for scaling to meet demand and load balancing to ensure continuity of service.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Real time server stats and history Alert, users and performance real time and historical
Reporting types
• Through an API
• Real-time dashboards
• Regular reports
• Reports on request - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Interfaces are available via the administration web pages to export data. In addition, full database exports are available via support requests
- Data export formats
-
- CSV
- Other
- Other data export formats
- API
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- REST
- API
- XLS
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We offer a 99.9% up time aligned to Microsoft Azure's up time SLA. We have a structured support and maintenance agreement which provides SLA and KPI's to include penalties for non performance.
- Approach to resilience
- SafeZone utilizes the Microsoft Azure cloud platform for its Command, Web, Messaging and Database components as well as data backups. Each geographical region has a primary datacentre where data is processed, stored and served for the region, as well as a secondary datacentre where backups are persisted. Architecture within the primary datacentre is redundant, with any hardware failure having no impact on uptime. The secondary datacentre can be promoted to primary during a disaster recovery scenario. Customers are assigned to a region based on both their regulatory data protection requirements and geography. All sensitive and personally identifiable information is kept within region except in cases where expressed permission is given by the customer to allow data to be transferred out of region
- Outage reporting
- Email alerts and a public dashboard shows real time and historical service status: http://status.criticalarc.com/ API available also
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
-
2-factor authentication
Public key authentication (including by TLS client certificate)
Username or password - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Other
- Description of management access authentication
- Numerous tools, at a basic level user name and passwords, in addition two factor authentication and single sign on (we have standardised on SAML 2.0), this is flexible and can support other types of identity management systems.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- CriticalArc maintains a suite of Information Security Policies governing all aspects of company operations (currently 23 in total). These are designed to comply with ISO 27001 and 27002 and audited externally as such
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All development is managed and controlled using software development tools to include JIRA our cloud based solution. All software releases are released through a thorough release process which includes testing of back end and user GUI elements. Once completed, we typically issue a beta version to a customer who is in the beta program and then made available to all customers
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Continuous threat assessments Patches can be deployed same day once discovered Customers, security partners and own working knowledge (keeping up to date with local, national and international threats)
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Continuous assessments Patches can be deployed same day once discovered Customers, security partners and own working knowledge (keeping up to date with local, national and international incidents)
- Incident management type
- Supplier-defined controls
- Incident management approach
- Continuous assessments Patches can be deployed same day once discovered Customers, security partners and own working knowledge (keeping up to date with local, national and international incidents)
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Joint Academic Network (JANET)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation Certification
- ISO/IEC 27001 accreditation date
- Tuesday 19 September 2023
- What the ISO/IEC 27001 doesn’t cover
-
Our ISO/IEC 27001 certification covers the Information Security Management System (ISMS) supporting the delivery of our services. The exact scope is defined in the ISO 27001 Statement of Applicability (SoA) and certification documentation. It does not cover:
• Non-information-security quality processes (e.g. general business or operational quality management)
• Customer-owned environments, systems, or data outside CriticalArc’s control
• Third-party services not included in the defined ISMS scope
• Physical assets or locations not listed within the certification scope - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Cd5af55a-98e2-4006-bccd-fca585484b78
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- TX-Ramp
- SOC-2
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-