Jewel Winter Management
Ice and snow create risks for traffic and pedestrians and demand clear planning, reliable execution, and real-time oversight. Jewel’s smart software digitises winter service workflows from planning to execution, helping councils and contractors stay in control, coordinate teams efficiently, and respond quickly when conditions change.
Features
- Recording, managing, controlling and archiving winter route data
- Provides the base for a navigation tool
- Calculation of capacity needed
- Real-time Performance Monitoring and logging
Benefits
- Real-time operational insight
- More efficient use of staff and equipment
- Safe route navigation
- Stress-free planning
- Continuous route optimisation
- Faster response times
- Easy to use digital workflows
- Improved collaboration
- Proof of completed work
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 8 6 2 9 9 4 2 1 6 9 0 0 4 8
Contact
Jewel B.V.
Davinder Bhogal
Telephone: +31628408648
Email: sales@jewelsoftware.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/A, for more information contact Jewel Software
- System requirements
-
- Web browser (eg. Chrome, Firefox, Edge)
- Mobile device (eg. tablet)
User support
- Email or online ticketing support
- Yes
- Support response times
-
Critical issues: response within 1–4 hours.
High priority: 24–48 hours.
Routine requests: 3–5 business days - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
CSM available Monday-Friday 08:00-17:00 UK time
Support available Monday-Friday 07:30-17:00 UK time
Critical support out of office hours 24/7 - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Onboarding activities:
- Onsite or virtual Kick off meeting
Discuss goals
Work out work processes and its priority
Planning for training (based per work process)
- Training sessions
Onsite or virtual raining per workprocess
Evaluation
- Reviews
Weekly touch base
Monthly check on onboarding work process
Quarterly review status of overall project - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- After the agreement expires our customers' data is available in the form of a csv file. If other formats are required this can be provided for an additional charge. After the contract ends the data will be saved for a maximum of one year. After that, the data will be deleted.
- End-of-contract process
- The license price is an all-inclusive price that includes access to the Jewel platform, upgrades, csm and support. At the end of the contract the customer will have no access to the platform and its services. The data can be provided to the customer in a CSV format. Other formats can be provided for additional costs.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our onboarding and offboarding is accessible through PDF documentation that is shared upon contract signing or end of contract period in case of offboarding requirements.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Desktop is web application Mobile is app installed
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- Full service API, no limitations
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
- Role based permissions
- Data sources
- Language
Scaling
- Independence of resources
- We ensure that demand from one user does not adversely affect others through secure, scalable service design. - Services use logical tenant separation and access controls to prevent cross-customer resource impact. - Load balancing and traffic management distribute workloads evenly across system components. - Monitoring and alerting are used to track performance and resource usage in real time, enabling proactive capacity management. - Rate limiting and throttling controls prevent excessive usage by individual users from affecting overall service availability.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Jewel Software ensures measurable value through key metrics as service usage, daily active users and engagement tracking via dashboards.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- The Jewel platform has an export function which gives customer the opportunity to receive get their data in CSV or SHP format.
- Data export formats
-
- CSV
- Other
- Other data export formats
- SHP
- Data import formats
-
- CSV
- Other
- Other data import formats
- SHP
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We offer 99.9% uptime during business hours 7:00 AM - 05:30 PM). The service is, of course, generally available 24 hours a day. We can (partially) disable the software for maintenance. Maintenance is generally carried out outside of office hours (7:00 AM - 05:30 PM). You will receive timely notification of the planned maintenance; we will send this message to the key user(s) of your organisation. We will only respond during office hours in the event of an emergency.
- Approach to resilience
- Available on request
- Outage reporting
- In the case of outages we notify our customers through email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
-
- SSO
- Role based Access Control - Access restrictions in management interfaces and support channels
- Access to management interfaces is tightly restricted through Azure AD / Entra ID SSO, MFA, and role‑based access control (RBAC), ensuring only authorised personnel can access administrative functions. Support channels are also access‑controlled: periodic ISO‑27001 access‑rights checks ensure only designated staff retain permissions.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
-
- SSO
- Role Based Access Control
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Jewel’s Information Security and Privacy Policy defines how information and privacy are protected within the company, aligned with ISO27001, GDPR/AVG and contractual requirements. It applies to all employees, external hires and locations in scope of the ISMS. The Board owns and supports the ISMS and follows a Plan-Do-Check-Act cycle: identifying risks, implementing measures, auditing their effectiveness and improving them. Key principles are confidentiality, integrity and availability of information, supported by clear definitions, risk assessments, incident reporting, and employee awareness and responsibilities. Risks are assessed annually; medium and high risks lead to mitigating measures decided with management. Incidents and data breaches must be reported via the defined procedure and are escalated appropriately. Suppliers with access to Jewel’s IT or PII are contractually bound to security requirements and are assessed annually. For privacy, Jewel collects limited PII from employees for HR and payroll, processes it only for defined purposes, uses third-party systems under DPAs, and applies technical and organizational controls. Data subjects have rights of access, correction, deletion and objection. Continuous improvement is ensured through audits, checks, non-conformity handling and annual management review.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Jewel’s approved Change Procedure defines how changes are registered, classified, assessed, planned and executed. All changes are logged in the Change Register using the _Changes template. Changes arise from risks, incidents, or improvements and are first discussed and approved in Monthly/Quarterly management meetings. Changes are categorized as technical, personnel, organizational, physical, or supplier; non-technical changes follow this procedure. For each change, impact and risk (L/M/H) are identified. An execution plan is then created covering testing, emergency/rollback, process updates, and business continuity, and must be approved by management before the change is carried out.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Jewel operates a continuous vulnerability management process aligned with ISO 27001. We assess threats through automated scanning, secure‑by‑design reviews, penetration testing, and ongoing monitoring of our Azure-hosted environment. Critical vulnerabilities are patched within 24 hours, high‑severity issues within 72 hours, and others as part of scheduled maintenance. Threat intelligence is sourced from Microsoft Security Center, NCSC advisories, industry CERT feeds, OWASP updates, and Azure’s continuous security alerts. All findings are logged, assessed for impact, and remediated through our change‑management process to ensure service integrity and customer protection.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We continuously monitor our Azure‑hosted platform using automated log analysis, anomaly detection, audit logs, and Azure Security Center alerts. Potential compromises are identified through suspicious login patterns, integrity breaches, unusual system behaviour, or threat‑intelligence flags. When detected, incidents are triaged immediately, contained, investigated, and resolved following our ISO 27001 incident‑response procedures. Critical incidents receive an immediate response (typically within hours), with high‑severity issues addressed within one business day. Evidence collection, root‑cause analysis, and corrective actions follow established ISO 27001 controls to prevent recurrence.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Jewel follows a formal ISO 27001‑aligned incident‑management procedure with predefined workflows for common security events. Users report incidents through the documented internal reporting route to management, where events are logged, classified, and escalated when required. Response steps—including containment, evidence preservation, analysis, and resolution—follow standardised processes ensuring fast and orderly handling. Incident reports are produced according to the same procedure, including assessment, outcome, and corrective actions, and shared with relevant stakeholders.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
- Limited access to the platform with predefined KPI's; TBD
- Limited period; TBD
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- DEKRA
- ISO/IEC 27001 accreditation date
- Wednesday 18 September 2019
- What the ISO/IEC 27001 doesn’t cover
- -
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-