Skip to main content

Help us improve the Digital Marketplace - send your feedback

PREOPTIMA LTD

Planning Application Carbon Evaluation and Reduction (PACER)

PACER is a web-based platform that supports local planning authorities in reviewing Whole Life Carbon Assessments (WLCAs) in planning applications. Applicants submit WLCA data through a structured workflow, while officers use automated checks, policy- and methodology-aligned validation, and clear dashboards to assess compliance, request clarifications, and make informed decisions.

Features

  • Web-based WLCA review platform for planning applications.
  • Structured applicant workflow for WLCA data, documents and evidence.
  • Automated validation/compliance checks against calculation methodology and local policy.
  • Results dashboards showing project- and jurisdiction-specific metrics.
  • Role-based access controls for planning users and applicants.
  • Streamlined officer-application communication through conversation threads.
  • Scenario comparison and reporting for retention schemes.
  • Exportable reports for committees, audit trails and statutory reporting.
  • Embedded guidance and knowledge resources on whole life carbon review.
  • Centralised database for project- and jurisdiction-level building and carbon data.

Benefits

  • Enable case officers to review WLCAs consistently, quickly and confidently.
  • Reduce manual checking effort and repetitive administrative review tasks.
  • Support evidence-based planning decisions aligned with climate commitments.
  • Upskill case officers through integrated guidance, feedback and real examples.
  • Improve communication with applicants using structured comments and responses.
  • Capture high-quality carbon/building data for benchmarking, policy and research.
  • Standardise WLCA submissions, improving fairness, transparency and consistency.
  • Provide clear audit trails supporting scrutiny and legal compliance.

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@preoptima.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 2 8 2 1 9 1 4 2 9 5 1 8 6 4

Contact

PREOPTIMA LTD Francesco Pomponi
Telephone: 07708378100
Email: info@preoptima.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
PACER is a browser-based SaaS application and requires a reliable internet connection and a modern web browser (e.g. current versions of Chrome, Edge, Safari or Firefox). Any planned maintenance is normally carried out outside of core UK business hours with advance notice where service disruption is expected.
System requirements
  • Modern web browser: latest Chrome, Edge, Firefox or Safari.
  • Reliable broadband internet connection for all users accessing PACER.
  • Ability to access HTTPS URLs through organisational firewalls and proxies.
  • User email accounts for notifications, password resets and support communications.
  • No additional software licences or local installations required for buyers.

User support

Email or online ticketing support
Yes
Support response times
Mon-Fri 8-18 response within 2hr
Weekend response within 24h
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
It is a HubSpot webchat component, as part of our CRM (Customer Relationship Management) system.
Onsite support
Yes, at extra cost
Support levels
Our support model for PACER is designed to be simple and inclusive. Every new customer goes through an onboarding period, which typically includes remote training sessions, configuration support and help integrating PACER into existing planning workflows. Where appropriate, elements of onboarding can be delivered on-site by agreement and may be subject to additional costs. Once live, customers can contact Preoptima via email during UK business hours (Monday to Friday, excluding public holidays) for incident reporting, questions and change requests. We aim to respond to all enquiries within 2 hours.

We provide ongoing product updates, release notes and access to online documentation and user guidance. We operate with a dedicated customer lead for commercial and relationship matters and a technical lead for product and implementation queries, ensuring continuity while still giving customers direct access to the right expertise.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We provide a structured onboarding process to help authorities start using PACER smoothly and confidently. Onboarding typically begins with a kick-off meeting to confirm objectives, users, and key planning workflows. We then configure the service for the customer, including user roles, local policy settings, and any agreed templates, benchmarks or reporting outputs.

Training is delivered primarily online through live remote sessions for administrators, planning officers and other users. These sessions cover core functionality, WLCA review workflows, and how PACER supports local policy implementation. We can also provide foundation training on WLC theory, including “train-the-trainer” sessions, so that authorities can cascade training internally. Where appropriate, and by agreement, elements of onboarding can be delivered onsite.

All customers receive access to user documentation, a comprehensive online Knowledge Hub, and other reference materials to support day-to-day use. We can create or adapt example cases for familiarisation and practice. Following go-live, our support team remains available for questions, minor configuration adjustments and refresher sessions as needed.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, customers can extract all PACER data relating to their planning applications and assessments. Throughout the contract, authorised users can export project-level information, results and reports using the standard export functions (for example, CSV/Excel-style tabular data and Word document reports).

On contract termination, we can provide a final bulk export on request within an agreed timeframe, typically delivered via a secure download link or other secure file transfer method. Data is provided in commonly used, non-proprietary formats to support reuse in other systems and avoid lock-in.

PACER data is hosted in the AWS UK Region and protected by daily encrypted backups retained for 30 days in a separate availability zone. Following confirmation that the customer has received their export, and after any agreed retention period has expired, we securely delete customer data from live systems and backups in line with our data protection policy and UK GDPR.
End-of-contract process
At the end of the contract, user access to PACER continues until the agreed contract end date, unless an extension or new contract is agreed. Before expiry, we will work with the customer to plan any required data export and transition activities. As standard, customers can use the in-service export functions at any time during the contract to download project information, results and reports. A reasonable final bulk export in commonly used formats (for example CSV/Excel-style data and PDF reports) is included in the contract price, as is standard support during the transition period.

After the contract end date and completion of any agreed export, user access to PACER is withdrawn and data is retained and deleted in line with our data protection and retention policies. Any additional services, such as extended access beyond the end date, bespoke data transformation, or extra training and consultancy, are chargeable.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
We design our onboarding and offboarding documentation to be clear and usable for as many users as possible, even though it has not been formally certified against a specific accessibility standard.

Documentation is provided in HTML (as an online Knowledge Hub) and PDF (as a robust User Guide document), with a consistent structure using headings, short paragraphs and bullet points to support easy scanning and screen-reader use. We avoid unnecessary jargon, use plain English wherever possible, and include annotated screenshots only where they genuinely aid understanding. Key actions are described in text, not just by reference to colours or icons.

PDFs are generated from source documents rather than scans, so text can be searched and selected. Users can zoom, print or save locally according to their needs. Where applicable, we add meaningful link text and captions for images.

On request, we can provide alternative formats (for example, editable versions for large-print adaptation). We also supplement written documentation with live online walk-throughs or recorded sessions to support different learning preferences.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Our solution is a web app implemented through a modern responsive user interface (UI) framework. The screen automatically resizes/adjusts, and the menu is rearranged based on the screen device size.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
PACER is a secure, browser-based Software as a Service (SaaS) platform accessed via HTTPS with role-based user access. It provides two portals: an LPA Portal for case officers to manage and review planning submissions and an Applicant Portal for applicants to complete submissions, respond to comments and resubmit. The interface uses a consistent layout with a project list, case overview (status, key details and version history), and left-hand navigation through workflow pages. Officers review dashboards and automated checks (pass/warning), add comments within the case record, and track responses accordingly. Reporting and exports are available via in-platform actions.
Accessibility standards
None or don’t know
Description of accessibility
PACER is a browser-based service designed to support accessible use across core workflows. Users can navigate key pages by keyboard, resize text/zoom without losing content, and use consistent headings, labels and page structure. Status and results are not conveyed by colour alone, and interactive controls are designed to expose accessible names/roles. We run automated accessibility checks (e.g. Lighthouse; the main checks review page scores 100) and supplement these with manual keyboard testing. Users can complete core tasks (view cases, review checks, add comments, respond and resubmit).
Accessibility testing
N/A
API
Yes
What users can and can't do using the API
PACER’s web application is powered by a RESTful JSON API (the same API the front-end uses). Where enabled for a buyer, the API can be used for integration and automation.

What users can do:
Set up: create and manage organisations/workspaces, projects/cases, users and roles (admin/reviewer/applicant), and (where configured) upload reference data/templates;
Make changes: full CRUD operations on core objects (cases, submissions, comments, status/stage, assignments), upload/download supporting documents, and trigger generation/retrieval of review outputs (checks, KPIs, reports/exports).

Limitations:
API access requires authenticated credentials and appropriate role permissions.

Some configuration changes (e.g. policy rules/benchmarks/tenant-level settings) may be restricted to admins or Preoptima support, depending on the deployment.

Input validation applies, and there may be file-size limits and rate limiting to protect service performance.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
PACER is a multi-tenant SaaS. Users can customise tenant-level settings, and Preoptima can deliver additional customisations where required.

What can be customised:
* Benchmarks/thresholds and KPI targets
* Which checks are enabled and when they apply (by project type/scheme/submission type)
* Messaging templates linked to checks and outcomes
* Report templates and dashboard views (fields shown, layout)

How users can customise:
Buyer administrators configure standard options in the admin interface. Where buyers require changes beyond standard configuration (for example, new check logic or additional data fields), Preoptima delivers these as scoped development work within the shared PACER codebase, controlled using tenant-specific configuration and/or feature flags (no separate codebase).

Who can customise:
Buyer administrators manage configuration; Preoptima implements code-level customisations.

Scaling

Independence of resources
We protect tenant performance in a multi-tenant environment through a combination of isolation, capacity management and control mechanisms:

Tenant-level authorisation and data isolation so users only access their own data and workloads.

Scalable infrastructure with monitoring and autoscaling to maintain headroom as demand varies.

Rate limiting and request throttling (especially on API and export-heavy operations) to prevent any single tenant or user from degrading service for others.

Queued/background processing for intensive jobs (e.g. report generation, large uploads) to smooth load and protect interactive performance.

Operational monitoring and alerting with defined incident response to restore service quickly if contention occurs.

Analytics

Service usage metrics
Yes
Metrics types
PACER provides service usage and operational metrics to tenant administrators (and, where required, to buyer contacts via reports). Typical metrics include active users, logins, cases created/received, review status counts, time-in-stage, comments and resubmissions, export/report generation activity, and audit events. Where configured, we can also provide basic platform health/availability metrics and API usage metrics.
Reporting types
  • API access
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
Never
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Other
Other data at rest protection approach
Data is encrypted at rest using AWS managed encryption for our storage services (e.g. database and object storage) with keys managed in AWS KMS and access controlled through least-privilege IAM. Backups and snapshots are encrypted. Tenant data is logically segregated at the application layer with role-based access controls. AWS provides physical security controls for the underlying data centres and publishes assurance reports via AWS Artifact.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Data Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export data from PACER through the web interface using case-level and programme-level export actions. Exports include downloadable reports (for example, PDF summaries) and tabular outputs (for example, CSV/XLSX) for offline review, audit records and internal reporting. Users can export individual case data (submissions, checks, comments and status history) and, where enabled, aggregated datasets across cases for benchmarking and monitoring. Exports are permission-controlled, so only authorised users can download data for their tenant. API-based export is also available for integration, where configured.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • Other
Other data import formats
JSON

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Internal service-to-service traffic is encrypted in transit (TLS 1.2+). Network access is restricted using private subnets/security groups/firewalls, and administrative access is limited and audited.

Availability and resilience

Guaranteed availability
PACER is provided as a multi-tenant SaaS with a monthly availability SLA of 99.0% for the production service.

Availability is measured over each calendar month as the percentage of minutes the PACER application/API is available at the service endpoint, excluding: (i) pre-notified planned maintenance, (ii) emergency maintenance, and (iii) events outside our reasonable control (e.g. internet-wide failures or upstream cloud outages).

We monitor the service and respond to incidents in line with our support process, prioritising restoration of service and timely buyer communications.

If monthly availability falls below 99.0%, the buyer is eligible for service credits applied against the next invoice (or issued as a credit note for annual prepay), typically on a sliding scale, for example:
98.0%–98.99%: 5% of the monthly fee
97.0%–97.99%: 10% of the monthly fee
<97.0%: 20% of the monthly fee

Service credits are the buyer’s remedy for SLA breaches, as set out in the contract.
Approach to resilience
PACER is designed for resilience through redundancy, fault isolation, and rapid recovery.

Architecture and hosting:
PACER is hosted on AWS and uses a multi-tier, horizontally scalable architecture. Critical components are deployed with redundancy and health checks so workloads can fail over automatically, and capacity can be increased to handle demand spikes.

Datacentre/availability zone resilience:
Production environments are deployed across multiple AWS Availability Zones within a region to reduce the impact of an AZ-level failure. Data services are configured for high availability (e.g. multi-AZ deployment where supported), and storage is replicated within the region.

Data protection and recovery:
We perform automated backups and retain snapshots in line with our retention policy. Recovery procedures are documented and periodically tested (restore testing) to verify that data can be recovered and services can be brought back online following an incident.

Operational resilience:
The service is monitored with alerting for availability, performance, and error conditions. We use controlled deployments and rollback procedures to reduce change risk, and we operate incident management processes for communication and restoration.
Outage reporting
PACER reports outages through direct buyer communications and service-status reporting.

Email alerts: We notify buyer contacts by email for confirmed incidents (service degradation or outage), including initial acknowledgement, expected impact, and progress updates until resolution. We also send advance notices for planned maintenance.

In-service notifications: Where appropriate, the application displays a banner/message to inform logged-in users of known incidents or maintenance.

Buyers can also report suspected incidents through the support channel. Post-incident, we provide a short incident summary and corrective actions on request.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted using role-based access control and least-privilege permissions. Only authorised tenant administrators can access admin features (user management, configuration and exports). Preoptima support access is limited to named staff accounts and granted only when required to deliver support. Support requests are handled through a ticketed process; configuration changes and data exports must be requested by verified buyer contacts. Privileged actions are logged for audit. Access to production systems is limited to a small set of authorised engineers using strong authentication, with monitoring and log review to detect unauthorised activity.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance for PACER is owned at the senior level, with day-to-day management led by engineering and operations. We maintain documented security policies (access control, data handling, incident management, change management and supplier management) and review them at least annually or after material change. Security risks are logged, prioritised and tracked to closure. We follow a secure SDLC with peer review, controlled deployments and vulnerability management. Access is least-privilege with role-based permissions and MFA where available. We monitor logs and performance, and maintain audit trails for administrative actions. Incidents follow a defined response and buyer communications process.
Information security policies and processes
We follow a documented set of information security policies and operational processes covering:

Governance & accountability: senior owner responsible for security across services, with engineering/operations leads responsible for implementation and day-to-day control.

Access control: least-privilege access, role-based permissions, MFA where available, joiner–mover–leaver process, periodic access reviews.

Data protection: data classification/handling rules, encryption in transit and at rest (AWS), secure backup/restore and retention, secure deletion/offboarding.

Secure delivery: secure SDLC (peer review, approvals, CI/CD controls), change and release management with rollback, environment separation.

Vulnerability management: dependency patching, security updates, routine scanning/testing where applicable, tracked remediation.

Monitoring & incident response: centralised logging/alerting, incident triage and escalation, buyer communications, post-incident reviews and corrective actions.

Supplier & device controls: supplier due diligence, remote/BYOD controls and acceptable use requirements.

Policies are embedded through onboarding, periodic refreshers, mandatory review/approval workflows, and tracked actions in our ticketing/change systems. Compliance is monitored via access audits, logs, and regular internal reviews reported to senior leadership.
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We manage configuration and change through a controlled release process. Service components (application, API, infrastructure and third-party dependencies) are version controlled and tracked from development to production. Changes follow a ticketed workflow linked to commits, peer review and release notes. Environments are separated (dev/test/staging/production) and deployments are automated with rollback procedures. We maintain an inventory of key systems and dependencies and track patches and end-of-life items for remediation. Security impact is assessed during change review (data handling, auth, permissions, logging and integrations). Higher-risk changes trigger additional testing before release, with post-deployment monitoring.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We manage vulnerabilities through ongoing risk assessment, monitoring and timely patching. Potential threats are assessed through design and change reviews, focusing on data exposure, authentication/authorisation, external dependencies and cloud configuration. We monitor for vulnerabilities in code and third-party libraries and prioritise remediation based on severity and exploitability. Security patches are deployed via our controlled release process: critical issues are triaged immediately and fixed as soon as practicable, with expedited deployment; high/medium issues are scheduled into regular maintenance releases. Threat intelligence sources include vendor advisories (AWS and key suppliers), CVE/NVD feeds, dependency alerts (e.g. GitHub Dependabot) and security mailing lists.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use centralised logging and alerting to detect suspicious activity and service issues. We monitor authentication events, privileged/admin actions, unusual access patterns, API error rates, and infrastructure/service health signals, and investigate alerts for indicators of compromise. When a potential compromise is identified, we follow an incident process: triage and validate, contain (e.g. revoke credentials, block access, isolate affected components), eradicate the cause, recover service, and preserve logs for analysis. We notify buyer contacts where their service may be impacted. Incidents are acknowledged and investigated as soon as detected, with expedited response for high-severity events and ongoing status updates until resolved.
Incident management type
Supplier-defined controls
Incident management approach
We operate a documented incident management process covering detection, triage, containment, recovery and post-incident review. We maintain pre-defined playbooks for common events (service outage/degradation, security incident, data access issue and failed deployment) with roles and escalation paths. Users report incidents via our support email/helpdesk (and, where agreed, by phone for urgent issues). We acknowledge incidents, provide regular status updates to buyer contacts, and record actions and timings. After resolution, we can provide an incident report on request, including impact, root cause, corrective actions and prevention measures, and any required notifications where buyer data or service delivery may have been affected.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Preoptima can provide test access to a non-production PACER environment for buyers to review functionality and workflows. Evaluation access is limited to dummy/sample data and does not include go-live, operational use, or processing of real application data. Functionality may be limited (for example, integrations or certain modules) during evaluation.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@preoptima.com. Tell them what format you need. It will help if you say what assistive technology you use.