Planning Application Carbon Evaluation and Reduction (PACER)
PACER is a web-based platform that supports local planning authorities in reviewing Whole Life Carbon Assessments (WLCAs) in planning applications. Applicants submit WLCA data through a structured workflow, while officers use automated checks, policy- and methodology-aligned validation, and clear dashboards to assess compliance, request clarifications, and make informed decisions.
Features
- Web-based WLCA review platform for planning applications.
- Structured applicant workflow for WLCA data, documents and evidence.
- Automated validation/compliance checks against calculation methodology and local policy.
- Results dashboards showing project- and jurisdiction-specific metrics.
- Role-based access controls for planning users and applicants.
- Streamlined officer-application communication through conversation threads.
- Scenario comparison and reporting for retention schemes.
- Exportable reports for committees, audit trails and statutory reporting.
- Embedded guidance and knowledge resources on whole life carbon review.
- Centralised database for project- and jurisdiction-level building and carbon data.
Benefits
- Enable case officers to review WLCAs consistently, quickly and confidently.
- Reduce manual checking effort and repetitive administrative review tasks.
- Support evidence-based planning decisions aligned with climate commitments.
- Upskill case officers through integrated guidance, feedback and real examples.
- Improve communication with applicants using structured comments and responses.
- Capture high-quality carbon/building data for benchmarking, policy and research.
- Standardise WLCA submissions, improving fairness, transparency and consistency.
- Provide clear audit trails supporting scrutiny and legal compliance.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 2 8 2 1 9 1 4 2 9 5 1 8 6 4
Contact
PREOPTIMA LTD
Francesco Pomponi
Telephone: 07708378100
Email: info@preoptima.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- PACER is a browser-based SaaS application and requires a reliable internet connection and a modern web browser (e.g. current versions of Chrome, Edge, Safari or Firefox). Any planned maintenance is normally carried out outside of core UK business hours with advance notice where service disruption is expected.
- System requirements
-
- Modern web browser: latest Chrome, Edge, Firefox or Safari.
- Reliable broadband internet connection for all users accessing PACER.
- Ability to access HTTPS URLs through organisational firewalls and proxies.
- User email accounts for notifications, password resets and support communications.
- No additional software licences or local installations required for buyers.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Mon-Fri 8-18 response within 2hr
Weekend response within 24h - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- It is a HubSpot webchat component, as part of our CRM (Customer Relationship Management) system.
- Onsite support
- Yes, at extra cost
- Support levels
-
Our support model for PACER is designed to be simple and inclusive. Every new customer goes through an onboarding period, which typically includes remote training sessions, configuration support and help integrating PACER into existing planning workflows. Where appropriate, elements of onboarding can be delivered on-site by agreement and may be subject to additional costs. Once live, customers can contact Preoptima via email during UK business hours (Monday to Friday, excluding public holidays) for incident reporting, questions and change requests. We aim to respond to all enquiries within 2 hours.
We provide ongoing product updates, release notes and access to online documentation and user guidance. We operate with a dedicated customer lead for commercial and relationship matters and a technical lead for product and implementation queries, ensuring continuity while still giving customers direct access to the right expertise. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
We provide a structured onboarding process to help authorities start using PACER smoothly and confidently. Onboarding typically begins with a kick-off meeting to confirm objectives, users, and key planning workflows. We then configure the service for the customer, including user roles, local policy settings, and any agreed templates, benchmarks or reporting outputs.
Training is delivered primarily online through live remote sessions for administrators, planning officers and other users. These sessions cover core functionality, WLCA review workflows, and how PACER supports local policy implementation. We can also provide foundation training on WLC theory, including “train-the-trainer” sessions, so that authorities can cascade training internally. Where appropriate, and by agreement, elements of onboarding can be delivered onsite.
All customers receive access to user documentation, a comprehensive online Knowledge Hub, and other reference materials to support day-to-day use. We can create or adapt example cases for familiarisation and practice. Following go-live, our support team remains available for questions, minor configuration adjustments and refresher sessions as needed. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, customers can extract all PACER data relating to their planning applications and assessments. Throughout the contract, authorised users can export project-level information, results and reports using the standard export functions (for example, CSV/Excel-style tabular data and Word document reports).
On contract termination, we can provide a final bulk export on request within an agreed timeframe, typically delivered via a secure download link or other secure file transfer method. Data is provided in commonly used, non-proprietary formats to support reuse in other systems and avoid lock-in.
PACER data is hosted in the AWS UK Region and protected by daily encrypted backups retained for 30 days in a separate availability zone. Following confirmation that the customer has received their export, and after any agreed retention period has expired, we securely delete customer data from live systems and backups in line with our data protection policy and UK GDPR. - End-of-contract process
-
At the end of the contract, user access to PACER continues until the agreed contract end date, unless an extension or new contract is agreed. Before expiry, we will work with the customer to plan any required data export and transition activities. As standard, customers can use the in-service export functions at any time during the contract to download project information, results and reports. A reasonable final bulk export in commonly used formats (for example CSV/Excel-style data and PDF reports) is included in the contract price, as is standard support during the transition period.
After the contract end date and completion of any agreed export, user access to PACER is withdrawn and data is retained and deleted in line with our data protection and retention policies. Any additional services, such as extended access beyond the end date, bespoke data transformation, or extra training and consultancy, are chargeable. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
We design our onboarding and offboarding documentation to be clear and usable for as many users as possible, even though it has not been formally certified against a specific accessibility standard.
Documentation is provided in HTML (as an online Knowledge Hub) and PDF (as a robust User Guide document), with a consistent structure using headings, short paragraphs and bullet points to support easy scanning and screen-reader use. We avoid unnecessary jargon, use plain English wherever possible, and include annotated screenshots only where they genuinely aid understanding. Key actions are described in text, not just by reference to colours or icons.
PDFs are generated from source documents rather than scans, so text can be searched and selected. Users can zoom, print or save locally according to their needs. Where applicable, we add meaningful link text and captions for images.
On request, we can provide alternative formats (for example, editable versions for large-print adaptation). We also supplement written documentation with live online walk-throughs or recorded sessions to support different learning preferences.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our solution is a web app implemented through a modern responsive user interface (UI) framework. The screen automatically resizes/adjusts, and the menu is rearranged based on the screen device size.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- PACER is a secure, browser-based Software as a Service (SaaS) platform accessed via HTTPS with role-based user access. It provides two portals: an LPA Portal for case officers to manage and review planning submissions and an Applicant Portal for applicants to complete submissions, respond to comments and resubmit. The interface uses a consistent layout with a project list, case overview (status, key details and version history), and left-hand navigation through workflow pages. Officers review dashboards and automated checks (pass/warning), add comments within the case record, and track responses accordingly. Reporting and exports are available via in-platform actions.
- Accessibility standards
- None or don’t know
- Description of accessibility
- PACER is a browser-based service designed to support accessible use across core workflows. Users can navigate key pages by keyboard, resize text/zoom without losing content, and use consistent headings, labels and page structure. Status and results are not conveyed by colour alone, and interactive controls are designed to expose accessible names/roles. We run automated accessibility checks (e.g. Lighthouse; the main checks review page scores 100) and supplement these with manual keyboard testing. Users can complete core tasks (view cases, review checks, add comments, respond and resubmit).
- Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
-
PACER’s web application is powered by a RESTful JSON API (the same API the front-end uses). Where enabled for a buyer, the API can be used for integration and automation.
What users can do:
Set up: create and manage organisations/workspaces, projects/cases, users and roles (admin/reviewer/applicant), and (where configured) upload reference data/templates;
Make changes: full CRUD operations on core objects (cases, submissions, comments, status/stage, assignments), upload/download supporting documents, and trigger generation/retrieval of review outputs (checks, KPIs, reports/exports).
Limitations:
API access requires authenticated credentials and appropriate role permissions.
Some configuration changes (e.g. policy rules/benchmarks/tenant-level settings) may be restricted to admins or Preoptima support, depending on the deployment.
Input validation applies, and there may be file-size limits and rate limiting to protect service performance. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
PACER is a multi-tenant SaaS. Users can customise tenant-level settings, and Preoptima can deliver additional customisations where required.
What can be customised:
* Benchmarks/thresholds and KPI targets
* Which checks are enabled and when they apply (by project type/scheme/submission type)
* Messaging templates linked to checks and outcomes
* Report templates and dashboard views (fields shown, layout)
How users can customise:
Buyer administrators configure standard options in the admin interface. Where buyers require changes beyond standard configuration (for example, new check logic or additional data fields), Preoptima delivers these as scoped development work within the shared PACER codebase, controlled using tenant-specific configuration and/or feature flags (no separate codebase).
Who can customise:
Buyer administrators manage configuration; Preoptima implements code-level customisations.
Scaling
- Independence of resources
-
We protect tenant performance in a multi-tenant environment through a combination of isolation, capacity management and control mechanisms:
Tenant-level authorisation and data isolation so users only access their own data and workloads.
Scalable infrastructure with monitoring and autoscaling to maintain headroom as demand varies.
Rate limiting and request throttling (especially on API and export-heavy operations) to prevent any single tenant or user from degrading service for others.
Queued/background processing for intensive jobs (e.g. report generation, large uploads) to smooth load and protect interactive performance.
Operational monitoring and alerting with defined incident response to restore service quickly if contention occurs.
Analytics
- Service usage metrics
- Yes
- Metrics types
- PACER provides service usage and operational metrics to tenant administrators (and, where required, to buyer contacts via reports). Typical metrics include active users, logins, cases created/received, review status counts, time-in-stage, comments and resubmissions, export/report generation activity, and audit events. Where configured, we can also provide basic platform health/availability metrics and API usage metrics.
- Reporting types
-
- API access
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- Never
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Other
- Other data at rest protection approach
- Data is encrypted at rest using AWS managed encryption for our storage services (e.g. database and object storage) with keys managed in AWS KMS and access controlled through least-privilege IAM. Backups and snapshots are encrypted. Tenant data is logically segregated at the application layer with role-based access controls. AWS provides physical security controls for the underlying data centres and publishes assurance reports via AWS Artifact.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export data from PACER through the web interface using case-level and programme-level export actions. Exports include downloadable reports (for example, PDF summaries) and tabular outputs (for example, CSV/XLSX) for offline review, audit records and internal reporting. Users can export individual case data (submissions, checks, comments and status history) and, where enabled, aggregated datasets across cases for benchmarking and monitoring. Exports are permission-controlled, so only authorised users can download data for their tenant. API-based export is also available for integration, where configured.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Internal service-to-service traffic is encrypted in transit (TLS 1.2+). Network access is restricted using private subnets/security groups/firewalls, and administrative access is limited and audited.
Availability and resilience
- Guaranteed availability
-
PACER is provided as a multi-tenant SaaS with a monthly availability SLA of 99.0% for the production service.
Availability is measured over each calendar month as the percentage of minutes the PACER application/API is available at the service endpoint, excluding: (i) pre-notified planned maintenance, (ii) emergency maintenance, and (iii) events outside our reasonable control (e.g. internet-wide failures or upstream cloud outages).
We monitor the service and respond to incidents in line with our support process, prioritising restoration of service and timely buyer communications.
If monthly availability falls below 99.0%, the buyer is eligible for service credits applied against the next invoice (or issued as a credit note for annual prepay), typically on a sliding scale, for example:
98.0%–98.99%: 5% of the monthly fee
97.0%–97.99%: 10% of the monthly fee
<97.0%: 20% of the monthly fee
Service credits are the buyer’s remedy for SLA breaches, as set out in the contract. - Approach to resilience
-
PACER is designed for resilience through redundancy, fault isolation, and rapid recovery.
Architecture and hosting:
PACER is hosted on AWS and uses a multi-tier, horizontally scalable architecture. Critical components are deployed with redundancy and health checks so workloads can fail over automatically, and capacity can be increased to handle demand spikes.
Datacentre/availability zone resilience:
Production environments are deployed across multiple AWS Availability Zones within a region to reduce the impact of an AZ-level failure. Data services are configured for high availability (e.g. multi-AZ deployment where supported), and storage is replicated within the region.
Data protection and recovery:
We perform automated backups and retain snapshots in line with our retention policy. Recovery procedures are documented and periodically tested (restore testing) to verify that data can be recovered and services can be brought back online following an incident.
Operational resilience:
The service is monitored with alerting for availability, performance, and error conditions. We use controlled deployments and rollback procedures to reduce change risk, and we operate incident management processes for communication and restoration. - Outage reporting
-
PACER reports outages through direct buyer communications and service-status reporting.
Email alerts: We notify buyer contacts by email for confirmed incidents (service degradation or outage), including initial acknowledgement, expected impact, and progress updates until resolution. We also send advance notices for planned maintenance.
In-service notifications: Where appropriate, the application displays a banner/message to inform logged-in users of known incidents or maintenance.
Buyers can also report suspected incidents through the support channel. Post-incident, we provide a short incident summary and corrective actions on request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted using role-based access control and least-privilege permissions. Only authorised tenant administrators can access admin features (user management, configuration and exports). Preoptima support access is limited to named staff accounts and granted only when required to deliver support. Support requests are handled through a ticketed process; configuration changes and data exports must be requested by verified buyer contacts. Privileged actions are logged for audit. Access to production systems is limited to a small set of authorised engineers using strong authentication, with monitoring and log review to detect unauthorised activity.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance for PACER is owned at the senior level, with day-to-day management led by engineering and operations. We maintain documented security policies (access control, data handling, incident management, change management and supplier management) and review them at least annually or after material change. Security risks are logged, prioritised and tracked to closure. We follow a secure SDLC with peer review, controlled deployments and vulnerability management. Access is least-privilege with role-based permissions and MFA where available. We monitor logs and performance, and maintain audit trails for administrative actions. Incidents follow a defined response and buyer communications process.
- Information security policies and processes
-
We follow a documented set of information security policies and operational processes covering:
Governance & accountability: senior owner responsible for security across services, with engineering/operations leads responsible for implementation and day-to-day control.
Access control: least-privilege access, role-based permissions, MFA where available, joiner–mover–leaver process, periodic access reviews.
Data protection: data classification/handling rules, encryption in transit and at rest (AWS), secure backup/restore and retention, secure deletion/offboarding.
Secure delivery: secure SDLC (peer review, approvals, CI/CD controls), change and release management with rollback, environment separation.
Vulnerability management: dependency patching, security updates, routine scanning/testing where applicable, tracked remediation.
Monitoring & incident response: centralised logging/alerting, incident triage and escalation, buyer communications, post-incident reviews and corrective actions.
Supplier & device controls: supplier due diligence, remote/BYOD controls and acceptable use requirements.
Policies are embedded through onboarding, periodic refreshers, mandatory review/approval workflows, and tracked actions in our ticketing/change systems. Compliance is monitored via access audits, logs, and regular internal reviews reported to senior leadership. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We manage configuration and change through a controlled release process. Service components (application, API, infrastructure and third-party dependencies) are version controlled and tracked from development to production. Changes follow a ticketed workflow linked to commits, peer review and release notes. Environments are separated (dev/test/staging/production) and deployments are automated with rollback procedures. We maintain an inventory of key systems and dependencies and track patches and end-of-life items for remediation. Security impact is assessed during change review (data handling, auth, permissions, logging and integrations). Higher-risk changes trigger additional testing before release, with post-deployment monitoring.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We manage vulnerabilities through ongoing risk assessment, monitoring and timely patching. Potential threats are assessed through design and change reviews, focusing on data exposure, authentication/authorisation, external dependencies and cloud configuration. We monitor for vulnerabilities in code and third-party libraries and prioritise remediation based on severity and exploitability. Security patches are deployed via our controlled release process: critical issues are triaged immediately and fixed as soon as practicable, with expedited deployment; high/medium issues are scheduled into regular maintenance releases. Threat intelligence sources include vendor advisories (AWS and key suppliers), CVE/NVD feeds, dependency alerts (e.g. GitHub Dependabot) and security mailing lists.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use centralised logging and alerting to detect suspicious activity and service issues. We monitor authentication events, privileged/admin actions, unusual access patterns, API error rates, and infrastructure/service health signals, and investigate alerts for indicators of compromise. When a potential compromise is identified, we follow an incident process: triage and validate, contain (e.g. revoke credentials, block access, isolate affected components), eradicate the cause, recover service, and preserve logs for analysis. We notify buyer contacts where their service may be impacted. Incidents are acknowledged and investigated as soon as detected, with expedited response for high-severity events and ongoing status updates until resolved.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate a documented incident management process covering detection, triage, containment, recovery and post-incident review. We maintain pre-defined playbooks for common events (service outage/degradation, security incident, data access issue and failed deployment) with roles and escalation paths. Users report incidents via our support email/helpdesk (and, where agreed, by phone for urgent issues). We acknowledge incidents, provide regular status updates to buyer contacts, and record actions and timings. After resolution, we can provide an incident report on request, including impact, root cause, corrective actions and prevention measures, and any required notifications where buyer data or service delivery may have been affected.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Preoptima can provide test access to a non-production PACER environment for buyers to review functionality and workflows. Evaluation access is limited to dummy/sample data and does not include go-live, operational use, or processing of real application data. Functionality may be limited (for example, integrations or certain modules) during evaluation.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-