SOTERweb
SOTERweb is a cloud based software platform that supports compliance, safety, and estates management for public sector organisations. It brings risk assessments, audits, fire safety, permits, and asset management etc.into one secure system, improving oversight, efficiency, and reporting for teams that manage facilities and statutory duties.
Features
- Real time reporting with automated data refresh for accurate dashboards.
- Remote access enabling users to work securely from any location.
- Integrated Power BI connectors supporting advanced visual analytics and insights.
- Customisable workflows matching organisational structures and approval processes.
- Automated notifications alerting users to tasks, deadlines, and updates.
- Mobile friendly interface allowing operatives to complete tasks onsite.
- Centralised document storage ensuring controlled access to key information.
- Role based permissions providing secure access for different user groups.
- API integration enabling seamless connection with external systems and data.
- Audit trails recording all activity to support compliance and governance.
Benefits
- Helps teams track compliance tasks efficiently across organisations.
- Generates clear reports supporting faster evidence based decisions.
- Lets managers monitor contractor activity with strong oversight.
- Streamlines permit workflows ensuring safer consistent working practices.
- Simplifies data entry reducing errors and improving accuracy.
- Sends timely notifications helping users respond to issues.
- Maintains consistent records supporting full audit and compliance readiness.
- Enables mobile access so operatives complete tasks onsite.
- Improves collaboration by centralising documents and operational information.
- Supports performance monitoring to identify trends and actions.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 7 8 1 4 7 5 1 8 6 7 8 5 1 8
Contact
SOTERweb
Rik Hutchins
Telephone: 08451630134
Email: admin@soterweb.org.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Police
- Defence
- Social Security Administration
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
-
- Modern browser
- Internet Connection
User support
- Email or online ticketing support
- Yes
- Support response times
- Same day response, including weekends. All queries will be answered within a few hours of receipt.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide a single, comprehensive support level for all clients at no additional cost. This includes access to our email support service, our online ticketing portal, and remote assistance for system configuration, troubleshooting, and general queries. All support requests are triaged and prioritised to ensure timely responses, with urgent operational issues handled as a priority.
Our support covers assistance with system use, updates to configuration, guidance on new features, and investigation of any reported issues. All platform updates, security patches, and improvements are included within the standard licence fee and do not attract extra charges.
Clients do not need to purchase enhanced tiers, paid support packages, or bolt on services. Every organisation receives the same high quality support as part of their annual subscription.
Clients have direct access to our knowledgeable support team, who understand the system in depth and can assist with both technical and operational questions. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide a structured onboarding process to help users begin using SOTERweb quickly and confidently. Every organisation receives an initial remote onboarding session to introduce key features, system navigation, and configuration options. We also provide tailored online training for administrators covering module setup, workflow design, permissions, and data management. Additional remote training sessions can be arranged for wider user groups, such as Estates teams, compliance leads, and contractors.
Comprehensive user documentation is supplied, including module guides, quick start instructions, and process diagrams. These resources support independent learning and help organisations train new staff over time. We also assist with early configuration, such as uploading data, setting roles, and aligning modules with organisational requirements.
Ongoing support is available through email and the online ticketing portal, ensuring users can ask questions and receive guidance as they begin daily use of the system. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At the end of a contract, users can extract all of their data directly from SOTERweb using the system’s built in export tools. Each module provides export functions that allow administrators to download records in common formats such as CSV or PDF, ensuring the organisation retains full access to all information it entered during the contract period. Users can perform these exports independently at any time before the contract end date.
If required, we can also provide a single consolidated export covering all modules the client has licensed. This is supplied in standard open formats to support easy migration to other systems. - End-of-contract process
-
At the end of the contract, the client is notified in advance of the renewal date and given the option to renew or allow the service to lapse. If the contract is not renewed, access to the system continues until the agreed contract end date. During this period, administrators can export all required data using the built in export tools. Data extraction is included within the standard contract price and does not incur additional charges.
Once the contract ends, user access is removed and the account is deactivated. Data is then retained securely for a defined period in line with our data retention policy. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- SOTERweb is designed to work on mobile devices. The core system is fully browser based, and key functions are accessible on mobile. In addition, operatives can use the Access IT tool, which provides a simplified mobile friendly interface for tasks such as signing onto permits, recording start and finish times, and completing basic actions. Desktop offers fuller administrative features and configuration tools, while mobile focuses on essential operational tasks.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- SOTERweb provides a clear web based service interface accessed through any modern browser. Users log in to view dashboards, manage records, complete workflows, and access modules such as Risk Assessment, Permit to Work, Fire Safety, Fleet, and Asset Management. The interface is intuitive, with role based views that show users only the functions relevant to their responsibilities. Administrative controls, configuration options, and reporting tools are available through the same interface, ensuring a consistent experience across all modules.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
We have carried out internal accessibility reviews and user based testing to confirm that key functions are usable with common assistive technologies. This includes testing navigation and operation using keyboard only controls, screen readers such as NVDA, and browser based accessibility tools. We have also reviewed colour contrast, focus order, form labels, and alternative text to support users with visual or cognitive impairments.
User feedback from clients with varying accessibility needs has been incorporated into interface improvements, particularly around navigation clarity, button sizing, and consistent use of headings. Testing is ongoing as new modules and features are released to ensure continued alignment with WCAG 2.2 AA principles. - API
- Yes
- What users can and can't do using the API
-
SOTERweb provides a secure REST API that allows clients to integrate selected system data with their own applications. Users can retrieve records such as assets, permits, risk assessments, users, and monitoring data, depending on the modules they licence. The API supports read operations for reporting, dashboarding, and synchronisation with external systems.
Users authenticate using secure API keys issued by the SOTERweb team. Once enabled, they can pull data into platforms such as Power BI or internal dashboards. The API does not allow users to configure the system, create modules, or make structural changes. Write access is limited to specific controlled functions to protect data integrity and ensure compliance.
All configuration, workflow design, and administrative setup must be performed through the main SOTERweb interface, not via the API. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise SOTERweb extensively to match their organisational structure and operational processes. Administrators can configure modules by adding their own datasets, workflows, approval routes, user roles, asset categories, permit types, and risk assessment templates. They can also customise terminology, notification settings, location structures, contractor requirements, and the specific information requested within each module. Many modules allow organisations to upload their own forms, documents, and guidance to ensure alignment with internal policies.
Customisation is completed through the system’s administrative interface using simple forms, menus, and configuration tools. No coding knowledge is required. Administrators can upload bulk data, set permission groups, adjust layouts, design workflow routes, and enable or disable features based on their needs. They can also create tailored reporting views and link the platform to external dashboards through the API or Power BI connector.
Only users with administrative permissions can undertake customisation. Standard users and contractors cannot customise the platform but can operate within the configured structure that the organisation has created.
Scaling
- Independence of resources
- We use a modern cloud architecture that allocates dedicated resources to each client environment. This ensures processing, storage, and performance are isolated, so activity from one organisation cannot impact another. Load balancing, autoscaling, and continuous performance monitoring maintain stable operation even during periods of high usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide a range of service usage metrics, including login activity, number of records created across each module, permit volumes, asset updates, risk assessment activity, contractor usage, and Access IT interactions. Administrators can also view trends over time to monitor engagement and operational workload. These metrics support oversight, audit readiness, and performance management across the organisation.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users export their data directly through SOTERweb’s built in export tools. Each module includes options to download records in formats such as CSV or PDF. Administrators can run these exports at any time and as often as needed. No special setup or additional software is required.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We operate SOTERweb with a high level of availability and target uptime of over 99 percent. Since launch, we have not experienced any unplanned outages, and the service has remained consistently stable. The platform is hosted within resilient UK based infrastructure managed by our hosting partner, using redundancy, load balancing, and continuous monitoring to maintain performance.
We take availability extremely seriously. Any incident that might affect access would be investigated immediately, with priority support provided until full service is confirmed.
Planned maintenance is scheduled outside core working hours wherever possible, and advance notice is given. Our aim is to provide uninterrupted and dependable access throughout the contract term. - Approach to resilience
-
SOTERweb is designed with a resilient cloud architecture to ensure continuous availability and stable performance. The service is hosted in UK based datacentres managed by our infrastructure partner, which provide redundancy across power, networking, and hardware. Data is stored on replicated systems so that if a component fails, service continues without disruption. Load balancing and autoscaling technology help maintain consistent performance during periods of increased demand.
Regular monitoring is in place to detect issues early, and alerts allow our team to respond quickly. Backups are taken routinely and stored securely to support recovery in the event of a major incident. Datacentre resilience measures, detailed configuration, and underlying infrastructure controls are available on request for clients who require additional assurance. - Outage reporting
-
SOTERweb reports any service outages directly to clients through email alerts. If an issue arises that could affect performance or availability, we notify the designated administrators for each client organisation. These alerts outline the nature of the issue, the potential impact on the service, and the actions being taken to resolve it. Updates are provided as required until the issue is confirmed as fully resolved.
Although we do not use a public status dashboard or API based outage notifications, we prioritise direct communication to ensure clients receive accurate and prompt information. This approach allows us to tailor messages to each organisation’s setup and provide specific guidance if needed.
Given the high stability of the platform and the absence of unplanned outages to date, outage notifications are extremely rare. However, the process is fully established to ensure transparency and timely communication should an incident occur.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- We restrict access to management interfaces through authenticated administrator accounts, role based permissions and logging. Only authorised staff can access system control panels, and all actions require secure login. Our hosting partner T3 restricts server level access to named engineers using controlled credentials. Support channels are limited to our official support inbox and ticketing process, and no changes are made without confirming the requester’s identity.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
Cyber Essentials Plus.
We are also in the process of obtaining ISO 27001 - Information security policies and processes
-
We follow a clear set of information security policies and processes aligned with Cyber Essentials Plus and recognised industry practice. These policies cover access control, authentication, data protection, incident management, secure development, vulnerability management, backups, and supplier oversight. Policies are reviewed annually or sooner if required due to regulatory or technical changes.
Security governance is managed directly by the owner of Montgomery and Coupers, who is responsible for maintaining compliance, overseeing policy adherence, and ensuring that security controls remain effective. All system changes follow a defined change management process that includes testing and validation before release. Access to systems is restricted using least privilege principles, and authentication requirements are enforced consistently.
Compliance is monitored through logging, routine internal checks, and external independent assessments. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We operate a documented configuration and change management process. All SOTERweb components are tracked through their lifecycle using version control, configuration records and managed hosting baselines maintained by T3 Network Solutions. Every change is logged, reviewed and assessed for security impact, including effects on access controls, data handling and system stability. Changes are tested in a non production environment, peer reviewed, approved and then deployed in a controlled manner. Post release checks confirm that updates operate correctly and securely.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We operate a structured vulnerability management process. Potential threats are assessed through regular security reviews, monitoring, and supplier alerts from T3 Network Solutions. We use reputable threat intelligence sources including vendor advisories, NCSC updates and industry feeds. Security patches for hosting and infrastructure are applied by T3 in line with agreed schedules, with critical patches applied promptly. Application vulnerabilities are reviewed, prioritised and fixed through our controlled development and release process.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use protective monitoring across our application and hosting environment. T3 Network Solutions provide real time monitoring, alerting and log analysis to identify unusual activity or potential compromise. Any alert is reviewed immediately and investigated to confirm whether further action is required. If a potential compromise is identified, we would isolate the affected component, apply fixes and validate containment. We aim to respond to critical alerts as soon as they are detected.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate a documented incident management process covering security, service and availability events. Common scenarios have predefined steps for assessment, containment and escalation. Users can report incidents directly to our support inbox or through our ticketing process, which is monitored continuously during business hours. If an incident occurs, we would investigate, record findings and provide a clear written incident report to the client, including cause, actions taken and any follow up measures.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Our free trial gives temporary access to core SOTERweb modules for evaluation. It excludes integrations, data migration and bespoke development. Trials are time limited and provide a test environment only, not a live operational setup.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 7%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 12%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 18%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Ea5fb260-7fdc-4b17-abbc-00d1a3ec4870
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-