Zatenviro
Zatenviro by Unity5 revolutionises environmental enforcement for customers, reducing operational costs and enhancing efficiency. With complete control over the enforcement lifecycle, seamless integration, and real-time monitoring, Zatenviro simplifies environmental management with automated processes and tailored solutions, freeing up resources to focus on improving customer service.
Features
- Advanced Self-Service Configurability: Simplify, automate and adapt business processes.
- Tailored Reporting and Dashboards: Quick customisable and exportable data.
- AI Technology: Including, integrated appeals chatbot, and response module.
- Future-Ready: Innovation delivered throughout the contract as a standard.
- Easy Integration: Real-time API integration with third-party systems
- System Availability: Cloud-hosted system with in-built redundancy.
- Scalability: Solutions that can be tailored for any size operation.
- Real-Time Data Sync: Enables immediate action against cases.
- Compliance and Accreditations including ISO27001, Cyber Essentials Plus, PCI/DSS Level1
- Enforcement Ticket Lifecycle: Issuance, appeals, payments, legal, and debt resolution.
Benefits
- Cost Reduction: Improved efficiency lowers operational costs.
- Flexibility of System Configuration: Ensures compliance with relevant legislation.
- Collection Rates: Improved through ticket accuracy and better workflow.
- End-to-end Service: Through automations and integrations.
- Service Focused: User-friendly and dedicated support.
- Cloud-Based: Ensures resilience, ease of delivery and change management.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 5 6 1 2 0 9 4 2 1 3 8 5 2 9
Contact
UNITY FIVE LIMITED
Sales
Telephone: 0333 344 0834
Email: tenders@zatpark.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
- Modern Web Browser
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our support team have four levels of severity with specific SLAs to be met. Service credits are available for underperformance.
P1 - Critical Incidents - Response 1 hour, resolution 6 hours.
P2 - Major Incidents - Response 2 working hours, resolution 2 working days.
P3 - Moderate Incidents - Response, 10 working hours, resolution 15 working days.
P4 - Minor Incidents - Response 16 working hours, resolution 2 months.
Out of hours support is provided for P1 - P2 cases, with the online portal monitored between 8 a.m. to 10 p.m. 7 days a week. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Our support offering is fully inclusive as part of our service.
We provide a robust escalation process and communicate updates at regular intervals to our customers. A point person is designated on our side as the point of contact for the customer. In most cases, this will be the Technical Account Manager, with access to a cloud support engineer. This escalation process operates within our core working hours, however, should an incident escalation process be activated outside of core hours, we have on-call staff at different levels of escalation who will manage this process. This is part of our business continuity plan.
In case resolution is delayed or the severity increases, incidents will be escalated to the Team Leader for expedited attention.
Initial point of escalation: Customer Support Manager
Secondary point of escalation: Director of Implementation
Tertiary point of escalation: Chief Commercial Officer
Where applicable, escalations are made to the Heads of Department for resolution, for example, should there be a need to escalate a technical issue, this would be raised to the Director of Engineering. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Unity5 provides a fully supported implementation service, following our DRIVE methodology:
Define: In this introduction phase, the scope of the project is fully confirmed and a project plan created with the target dates for the project.
Refine: This stage Includes all workshops to agree the configuration of the system and any integration requirements for build. A specification document is created and signed off to continue to the next stage.
Implement: Unity5 configures the system according to the specification and provides project team training, enabling customers to become experts in the system. Unity5 fully tests set-up before releasing it to the customer for review.
Verify: Unity5 supports the customer testing process to sign off on configuration and help make any changes to fit any final processes.
Execute: After sign-off for launch, Unity5 delivers end-user training to all system users. Training can be onsite, remote, or a combination of both depending on customer needs, and we have a knowledge base of content for all users to access for reference.
Our experienced implementation team ensures customers are fully supported and self-sufficient before transferring them to the support team post-go live - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Firstly, we require the new provider to provide a Google account, leveraging Google Cloud Storage (GCS) for secure and high-performing data transfer. This ensures seamless migration while upholding data integrity and confidentiality.
We will then provide a complete database backup and start a periodic synchronisation of “flat files” to a shared GCS bucket. These flat files, include crucial data, such as images, documents, and video.
On the agreed last date of system use, we finalise the off-boarding process. We deliver the final database backup, ensuring no loss of critical information. Additionally, we perform the last synchronisation of flat files to guarantee that all essential data is seamlessly transferred to the new provider. - End-of-contract process
-
The Unity5 off-boarding process prioritises security, efficiency, and transparency. Firstly, we require the new provider to provide a Google account, leveraging Google Cloud Storage (GCS) for secure and high-performing data transfer. This ensures seamless migration while upholding data integrity and confidentiality.
We will then provide a complete database backup and start a periodic synchronisation of “flat files” to a shared GCS bucket. These flat files, include crucial data, such as images, documents, and video.
On the agreed last date of system use, we finalise the off-boarding process. We deliver the final database backup, ensuring no loss of critical information. Additionally, we perform the last synchronisation of flat files to guarantee that all essential data is seamlessly transferred to the new provider.
Moreover, we maintain accessibility to data for a grace period of 30 days post-transition. This allows ample time for any unforeseen circumstances or data retrieval needs. Our commitment extends beyond the transition phase, ensuring our customers’ peace of mind and continuity of operations. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The motorist portal is device agnostic and mobile responsive. No difference in functionality.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Provision of our SaaS solution is accessed via a sophisticated best practice guided user interface. This interface facilitates the actions required for their parking management operation including oversight of the automatic case progression, responding to customer queries or appeals, and generating or accessing reports.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- UX / UI design is incorporated into all new development planning and testing. Design planning includes accessibility assessments for assistive technologies.
- API
- Yes
- What users can and can't do using the API
-
- Users generate a key within the system and integrate our API specification.
- Users can make a subset of actions through the API, representing the set of common functionality across frequently used business objects, including tickets and sessions.
- There are limitations on how users can set up or make changes through the API, controlled by a sophisticated, customisable permission model. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
All Zatpark platforms including parking management system and permits are fully configurable giving users the flexibility to make customised changes themselves. Although, our support team are also available to enable changes to be made to the system to meet your requirements.
The system will be configured to your needs during the implementation set up stages of the contract. All application portals can be branded and delivered in line with the customers corporate style guidelines, reflecting the customers branding.
Scaling
- Independence of resources
- We leverage cloud based managed services where possible for all operations in order to assure scalability, resilience, redundancy and security. This ensures that we are able to scale with user demand and growth over time.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We log and audit the state of all data moving through the system and use this as these metrics as a basis for business intelligence and financial reconciliation
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export data by system provided .CSV or PDF exports, and via available API.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Word
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- API (XML JSON)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% is our standard offering for availability, and we negotiate any refunds for users if we do not meet these guaranteed levels on a case-by-case basis.
- Approach to resilience
-
- No single point of failure
- All services are fully redundant, with at least two instances of each database on separate servers and/or zones.
-Use of managed services where possible, e.g. cloud storage
Full information available on request. - Outage reporting
- A public dashboard and email alerts are provided, and we also have a service availability status page which provides updates on service availability. A comprehensive process is in place for informing customers of any outages, interruptions or service degradations.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Users can shutdown support access to their account. By default all accounts are restricted. There are user permission levels which dictate whether management interfaces are visible to users.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We use industry standard policies and procedures.
- Information security policies and processes
-
We have a set of policies, including:
- GDPR Data Security Breach Policy
- GDPR Data Retention Policy
- GDPR Data Protection Policy
Our Compliance Officer is responsible for the implementation and monitoring of all Unity5 policies and data security practices and maintains a detailed reporting structure. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
- Requirements gathering
- Product approval estimation and entry to the product backlog
- Prioritisation and detailed design
- Entry to the agile software development lifecycle (SDLC) with special attention given to security and treatment of PII
- QA process and deployment
- Business release - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Unity5 maintains a proactive security posture for Zatpermit by conducting daily automated scans of all cloud infrastructure to identify emerging vulnerabilities. Our patch management strategy ensures that all production resources are updated via a "rolling" deployment model, requiring no system downtime for routine maintenance.
In the event of a zero-day threat, we act immediately by deploying emergency patches or mitigations ahead of the standard schedule. To ensure continuous oversight, the system triggers instant email alerts to our technical teams if any potential threat or update failure is detected, maintaining 24/7 system integrity. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We maintain a robust protective monitoring approach ensuring 24/7 system integrity and accountability:
Multi-Layered Server Monitoring: We utilise native Google Cloud Platform monitoring alongside independent external services to track infrastructure health, performance, and reliability from multiple perspectives.
Behavioural Intelligence: Standard provider metrics are complemented by our own Business Intelligence and data analytics. This allows us to monitor the system’s internal logic, identifying unusual patterns or unauthorised behaviours that standard alerts might miss.
Incident Response: Issues are prioritised by severity. Critical threats trigger immediate action in alignment with our BCDR protocols, ensuring rapid remediation and minimal service impact. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow a structured incident management process, ensuring operational continuity through clearly defined protocols and a high-touch support model:
Pre-defined Responses: We use established workflows for common events, allowing our team to respond with speed and consistency to known technical or operational scenarios.
Centralised Reporting: Users report incidents directly via the Helpdesk Support Line or the online portal.
Ongoing Transparency: Account Managers and the support team provide regular, comprehensive reports to customers. These include detailed incident logs and performance summaries to ensure long-term visibility and service improvement. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 16%
- Between £2,500,001 and £5,000,000
- 17%
- Over £5,000,001
- 18%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Standards Institution
- ISO/IEC 27001 accreditation date
- Sunday 3 November 2024
- What the ISO/IEC 27001 doesn’t cover
-
The ISMS applies to the Unity Five premises. This includes our internal IT infrastructure, including implemented open source software and internally developed tools or software relating to internal non-product infrastructure and the operational support for the delivery of technology solutions for business and industry. This also includes the physical environment and people supporting these business functions.
The scope covers Unity Five offices as well as internal cloud based servers. It also applies to any remote working location where employees can access business data and assets. This does not cover the suite of products. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Friday 24 June 2022
- What the ISO 9001 doesn’t cover
-
Our ISO 9001 certification covers: The provision of SaaS and cloud-based software solutions globally, Software development lifecycle (SDLC), Customer support, incident management, and continual improvement, Risk management, corrective actions, and customer feedback processes
This certification applies to how we design, deliver, and support our services, not to physical manufacturing (which we do not do) as such physical manufacturing is our of scope. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Securious Limited
- PCI DSS accreditation date
- Friday 24 January 2025
- What the PCI DSS doesn’t cover
-
Our PCI DSS covers PCI DSS covers:
Secure handling of payment card data,
Technical and organisational security controls,
Ongoing monitoring, testing, and risk management, Anything outside of this scope is not covered. - Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 260e34ff-b24b-4d4b-a67b-96426519dd1f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- E896d620-e9ce-4804-8b83-0381689f288a
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-