Skip to main content

Help us improve the Digital Marketplace - send your feedback

SOTERweb

SOTERweb

SOTERweb is a cloud based software platform that supports compliance, safety, and estates management for public sector organisations. It brings risk assessments, audits, fire safety, permits, and asset management etc.into one secure system, improving oversight, efficiency, and reporting for teams that manage facilities and statutory duties.

Features

  • Real time reporting with automated data refresh for accurate dashboards.
  • Remote access enabling users to work securely from any location.
  • Integrated Power BI connectors supporting advanced visual analytics and insights.
  • Customisable workflows matching organisational structures and approval processes.
  • Automated notifications alerting users to tasks, deadlines, and updates.
  • Mobile friendly interface allowing operatives to complete tasks onsite.
  • Centralised document storage ensuring controlled access to key information.
  • Role based permissions providing secure access for different user groups.
  • API integration enabling seamless connection with external systems and data.
  • Audit trails recording all activity to support compliance and governance.

Benefits

  • Helps teams track compliance tasks efficiently across organisations.
  • Generates clear reports supporting faster evidence based decisions.
  • Lets managers monitor contractor activity with strong oversight.
  • Streamlines permit workflows ensuring safer consistent working practices.
  • Simplifies data entry reducing errors and improving accuracy.
  • Sends timely notifications helping users respond to issues.
  • Maintains consistent records supporting full audit and compliance readiness.
  • Enables mobile access so operatives complete tasks onsite.
  • Improves collaboration by centralising documents and operational information.
  • Supports performance monitoring to identify trends and actions.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at admin@soterweb.org.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 7 8 1 4 7 5 1 8 6 7 8 5 1 8

Contact

SOTERweb Rik Hutchins
Telephone: 08451630134
Email: admin@soterweb.org.uk

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Healthcare
  • Education
  • Public Order and Safety
  • Police
  • Defence
  • Social Security Administration
  • Adult Social Care
  • Children's Social Care
  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No
System requirements
  • Modern browser
  • Internet Connection

User support

Email or online ticketing support
Yes
Support response times
Same day response, including weekends. All queries will be answered within a few hours of receipt.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide a single, comprehensive support level for all clients at no additional cost. This includes access to our email support service, our online ticketing portal, and remote assistance for system configuration, troubleshooting, and general queries. All support requests are triaged and prioritised to ensure timely responses, with urgent operational issues handled as a priority.

Our support covers assistance with system use, updates to configuration, guidance on new features, and investigation of any reported issues. All platform updates, security patches, and improvements are included within the standard licence fee and do not attract extra charges.

Clients do not need to purchase enhanced tiers, paid support packages, or bolt on services. Every organisation receives the same high quality support as part of their annual subscription.

Clients have direct access to our knowledgeable support team, who understand the system in depth and can assist with both technical and operational questions.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide a structured onboarding process to help users begin using SOTERweb quickly and confidently. Every organisation receives an initial remote onboarding session to introduce key features, system navigation, and configuration options. We also provide tailored online training for administrators covering module setup, workflow design, permissions, and data management. Additional remote training sessions can be arranged for wider user groups, such as Estates teams, compliance leads, and contractors.

Comprehensive user documentation is supplied, including module guides, quick start instructions, and process diagrams. These resources support independent learning and help organisations train new staff over time. We also assist with early configuration, such as uploading data, setting roles, and aligning modules with organisational requirements.

Ongoing support is available through email and the online ticketing portal, ensuring users can ask questions and receive guidance as they begin daily use of the system.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of a contract, users can extract all of their data directly from SOTERweb using the system’s built in export tools. Each module provides export functions that allow administrators to download records in common formats such as CSV or PDF, ensuring the organisation retains full access to all information it entered during the contract period. Users can perform these exports independently at any time before the contract end date.

If required, we can also provide a single consolidated export covering all modules the client has licensed. This is supplied in standard open formats to support easy migration to other systems.
End-of-contract process
At the end of the contract, the client is notified in advance of the renewal date and given the option to renew or allow the service to lapse. If the contract is not renewed, access to the system continues until the agreed contract end date. During this period, administrators can export all required data using the built in export tools. Data extraction is included within the standard contract price and does not incur additional charges.

Once the contract ends, user access is removed and the account is deactivated. Data is then retained securely for a defined period in line with our data retention policy.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
SOTERweb is designed to work on mobile devices. The core system is fully browser based, and key functions are accessible on mobile. In addition, operatives can use the Access IT tool, which provides a simplified mobile friendly interface for tasks such as signing onto permits, recording start and finish times, and completing basic actions. Desktop offers fuller administrative features and configuration tools, while mobile focuses on essential operational tasks.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
SOTERweb provides a clear web based service interface accessed through any modern browser. Users log in to view dashboards, manage records, complete workflows, and access modules such as Risk Assessment, Permit to Work, Fire Safety, Fleet, and Asset Management. The interface is intuitive, with role based views that show users only the functions relevant to their responsibilities. Administrative controls, configuration options, and reporting tools are available through the same interface, ensuring a consistent experience across all modules.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have carried out internal accessibility reviews and user based testing to confirm that key functions are usable with common assistive technologies. This includes testing navigation and operation using keyboard only controls, screen readers such as NVDA, and browser based accessibility tools. We have also reviewed colour contrast, focus order, form labels, and alternative text to support users with visual or cognitive impairments.

User feedback from clients with varying accessibility needs has been incorporated into interface improvements, particularly around navigation clarity, button sizing, and consistent use of headings. Testing is ongoing as new modules and features are released to ensure continued alignment with WCAG 2.2 AA principles.
API
Yes
What users can and can't do using the API
SOTERweb provides a secure REST API that allows clients to integrate selected system data with their own applications. Users can retrieve records such as assets, permits, risk assessments, users, and monitoring data, depending on the modules they licence. The API supports read operations for reporting, dashboarding, and synchronisation with external systems.

Users authenticate using secure API keys issued by the SOTERweb team. Once enabled, they can pull data into platforms such as Power BI or internal dashboards. The API does not allow users to configure the system, create modules, or make structural changes. Write access is limited to specific controlled functions to protect data integrity and ensure compliance.

All configuration, workflow design, and administrative setup must be performed through the main SOTERweb interface, not via the API.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Users can customise SOTERweb extensively to match their organisational structure and operational processes. Administrators can configure modules by adding their own datasets, workflows, approval routes, user roles, asset categories, permit types, and risk assessment templates. They can also customise terminology, notification settings, location structures, contractor requirements, and the specific information requested within each module. Many modules allow organisations to upload their own forms, documents, and guidance to ensure alignment with internal policies.

Customisation is completed through the system’s administrative interface using simple forms, menus, and configuration tools. No coding knowledge is required. Administrators can upload bulk data, set permission groups, adjust layouts, design workflow routes, and enable or disable features based on their needs. They can also create tailored reporting views and link the platform to external dashboards through the API or Power BI connector.

Only users with administrative permissions can undertake customisation. Standard users and contractors cannot customise the platform but can operate within the configured structure that the organisation has created.

Scaling

Independence of resources
We use a modern cloud architecture that allocates dedicated resources to each client environment. This ensures processing, storage, and performance are isolated, so activity from one organisation cannot impact another. Load balancing, autoscaling, and continuous performance monitoring maintain stable operation even during periods of high usage.

Analytics

Service usage metrics
Yes
Metrics types
We provide a range of service usage metrics, including login activity, number of records created across each module, permit volumes, asset updates, risk assessment activity, contractor usage, and Access IT interactions. Administrators can also view trends over time to monitor engagement and operational workload. These metrics support oversight, audit readiness, and performance management across the organisation.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users export their data directly through SOTERweb’s built in export tools. Each module includes options to download records in formats such as CSV or PDF. Administrators can run these exports at any time and as often as needed. No special setup or additional software is required.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We operate SOTERweb with a high level of availability and target uptime of over 99 percent. Since launch, we have not experienced any unplanned outages, and the service has remained consistently stable. The platform is hosted within resilient UK based infrastructure managed by our hosting partner, using redundancy, load balancing, and continuous monitoring to maintain performance.

We take availability extremely seriously. Any incident that might affect access would be investigated immediately, with priority support provided until full service is confirmed.

Planned maintenance is scheduled outside core working hours wherever possible, and advance notice is given. Our aim is to provide uninterrupted and dependable access throughout the contract term.
Approach to resilience
SOTERweb is designed with a resilient cloud architecture to ensure continuous availability and stable performance. The service is hosted in UK based datacentres managed by our infrastructure partner, which provide redundancy across power, networking, and hardware. Data is stored on replicated systems so that if a component fails, service continues without disruption. Load balancing and autoscaling technology help maintain consistent performance during periods of increased demand.
Regular monitoring is in place to detect issues early, and alerts allow our team to respond quickly. Backups are taken routinely and stored securely to support recovery in the event of a major incident. Datacentre resilience measures, detailed configuration, and underlying infrastructure controls are available on request for clients who require additional assurance.
Outage reporting
SOTERweb reports any service outages directly to clients through email alerts. If an issue arises that could affect performance or availability, we notify the designated administrators for each client organisation. These alerts outline the nature of the issue, the potential impact on the service, and the actions being taken to resolve it. Updates are provided as required until the issue is confirmed as fully resolved.

Although we do not use a public status dashboard or API based outage notifications, we prioritise direct communication to ensure clients receive accurate and prompt information. This approach allows us to tailor messages to each organisation’s setup and provide specific guidance if needed.

Given the high stability of the platform and the absence of unplanned outages to date, outage notifications are extremely rare. However, the process is fully established to ensure transparency and timely communication should an incident occur.

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
We restrict access to management interfaces through authenticated administrator accounts, role based permissions and logging. Only authorised staff can access system control panels, and all actions require secure login. Our hosting partner T3 restricts server level access to named engineers using controlled credentials. Support channels are limited to our official support inbox and ticketing process, and no changes are made without confirming the requester’s identity.
Access restriction testing frequency
At least once a year
Management access authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus.
We are also in the process of obtaining ISO 27001
Information security policies and processes
We follow a clear set of information security policies and processes aligned with Cyber Essentials Plus and recognised industry practice. These policies cover access control, authentication, data protection, incident management, secure development, vulnerability management, backups, and supplier oversight. Policies are reviewed annually or sooner if required due to regulatory or technical changes.

Security governance is managed directly by the owner of Montgomery and Coupers, who is responsible for maintaining compliance, overseeing policy adherence, and ensuring that security controls remain effective. All system changes follow a defined change management process that includes testing and validation before release. Access to systems is restricted using least privilege principles, and authentication requirements are enforced consistently.

Compliance is monitored through logging, routine internal checks, and external independent assessments.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We operate a documented configuration and change management process. All SOTERweb components are tracked through their lifecycle using version control, configuration records and managed hosting baselines maintained by T3 Network Solutions. Every change is logged, reviewed and assessed for security impact, including effects on access controls, data handling and system stability. Changes are tested in a non production environment, peer reviewed, approved and then deployed in a controlled manner. Post release checks confirm that updates operate correctly and securely.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate a structured vulnerability management process. Potential threats are assessed through regular security reviews, monitoring, and supplier alerts from T3 Network Solutions. We use reputable threat intelligence sources including vendor advisories, NCSC updates and industry feeds. Security patches for hosting and infrastructure are applied by T3 in line with agreed schedules, with critical patches applied promptly. Application vulnerabilities are reviewed, prioritised and fixed through our controlled development and release process.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use protective monitoring across our application and hosting environment. T3 Network Solutions provide real time monitoring, alerting and log analysis to identify unusual activity or potential compromise. Any alert is reviewed immediately and investigated to confirm whether further action is required. If a potential compromise is identified, we would isolate the affected component, apply fixes and validate containment. We aim to respond to critical alerts as soon as they are detected.
Incident management type
Supplier-defined controls
Incident management approach
We operate a documented incident management process covering security, service and availability events. Common scenarios have predefined steps for assessment, containment and escalation. Users can report incidents directly to our support inbox or through our ticketing process, which is monitored continuously during business hours. If an incident occurs, we would investigate, record findings and provide a clear written incident report to the client, including cause, actions taken and any follow up measures.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Our free trial gives temporary access to core SOTERweb modules for evaluation. It excludes integrations, data migration and bespoke development. Trials are time limited and provide a test environment only, not a live operational setup.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
7%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
12%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
18%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Ea5fb260-7fdc-4b17-abbc-00d1a3ec4870
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at admin@soterweb.org.uk. Tell them what format you need. It will help if you say what assistive technology you use.