Skip to main content

Help us improve the Digital Marketplace - send your feedback

Jewel B.V.

Jewel Winter Management

Ice and snow create risks for traffic and pedestrians and demand clear planning, reliable execution, and real-time oversight. Jewel’s smart software digitises winter service workflows from planning to execution, helping councils and contractors stay in control, coordinate teams efficiently, and respond quickly when conditions change.

Features

  • Recording, managing, controlling and archiving winter route data
  • Provides the base for a navigation tool
  • Calculation of capacity needed
  • Real-time Performance Monitoring and logging

Benefits

  • Real-time operational insight
  • More efficient use of staff and equipment
  • Safe route navigation
  • Stress-free planning
  • Continuous route optimisation
  • Faster response times
  • Easy to use digital workflows
  • Improved collaboration
  • Proof of completed work

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@jewelsoftware.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 8 6 2 9 9 4 2 1 6 9 0 0 4 8

Contact

Jewel B.V. Davinder Bhogal
Telephone: +31628408648
Email: sales@jewelsoftware.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
N/A, for more information contact Jewel Software
System requirements
  • Web browser (eg. Chrome, Firefox, Edge)
  • Mobile device (eg. tablet)

User support

Email or online ticketing support
Yes
Support response times
Critical issues: response within 1–4 hours.
High priority: 24–48 hours.
Routine requests: 3–5 business days
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
CSM available Monday-Friday 08:00-17:00 UK time
Support available Monday-Friday 07:30-17:00 UK time
Critical support out of office hours 24/7
Support available to third parties
No

Onboarding and offboarding

Getting started
Onboarding activities:
- Onsite or virtual Kick off meeting​
Discuss goals​
Work out work processes and its priority​
Planning for training (based per work process)​

- Training sessions​
Onsite or virtual raining per workprocess​
Evaluation ​

- Reviews​
Weekly touch base​
Monthly check on onboarding work process​
Quarterly review status of overall project
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
After the agreement expires our customers' data is available in the form of a csv file. If other formats are required this can be provided for an additional charge. After the contract ends the data will be saved for a maximum of one year. After that, the data will be deleted.
End-of-contract process
The license price is an all-inclusive price that includes access to the Jewel platform, upgrades, csm and support. At the end of the contract the customer will have no access to the platform and its services. The data can be provided to the customer in a CSV format. Other formats can be provided for additional costs.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our onboarding and offboarding is accessible through PDF documentation that is shared upon contract signing or end of contract period in case of offboarding requirements.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Desktop is web application Mobile is app installed
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Full service API, no limitations
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
- Role based permissions
- Data sources
- Language

Scaling

Independence of resources
We ensure that demand from one user does not adversely affect others through secure, scalable service design. - Services use logical tenant separation and access controls to prevent cross-customer resource impact. - Load balancing and traffic management distribute workloads evenly across system components. - Monitoring and alerting are used to track performance and resource usage in real time, enabling proactive capacity management. - Rate limiting and throttling controls prevent excessive usage by individual users from affecting overall service availability.

Analytics

Service usage metrics
Yes
Metrics types
Jewel Software ensures measurable value through key metrics as service usage, daily active users and engagement tracking via dashboards.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
The Jewel platform has an export function which gives customer the opportunity to receive get their data in CSV or SHP format.
Data export formats
  • CSV
  • Other
Other data export formats
SHP
Data import formats
  • CSV
  • Other
Other data import formats
SHP

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We offer 99.9% uptime during business hours 7:00 AM - 05:30 PM). The service is, of course, generally available 24 hours a day. We can (partially) disable the software for maintenance. Maintenance is generally carried out outside of office hours (7:00 AM - 05:30 PM). You will receive timely notification of the planned maintenance; we will send this message to the key user(s) of your organisation. We will only respond during office hours in the event of an emergency.
Approach to resilience
Available on request
Outage reporting
In the case of outages we notify our customers through email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
- SSO
- Role based Access Control
Access restrictions in management interfaces and support channels
Access to management interfaces is tightly restricted through Azure AD / Entra ID SSO, MFA, and role‑based access control (RBAC), ensuring only authorised personnel can access administrative functions. Support channels are also access‑controlled: periodic ISO‑27001 access‑rights checks ensure only designated staff retain permissions.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
- SSO
- Role Based Access Control

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Jewel’s Information Security and Privacy Policy defines how information and privacy are protected within the company, aligned with ISO27001, GDPR/AVG and contractual requirements. It applies to all employees, external hires and locations in scope of the ISMS. The Board owns and supports the ISMS and follows a Plan-Do-Check-Act cycle: identifying risks, implementing measures, auditing their effectiveness and improving them. Key principles are confidentiality, integrity and availability of information, supported by clear definitions, risk assessments, incident reporting, and employee awareness and responsibilities. Risks are assessed annually; medium and high risks lead to mitigating measures decided with management. Incidents and data breaches must be reported via the defined procedure and are escalated appropriately. Suppliers with access to Jewel’s IT or PII are contractually bound to security requirements and are assessed annually. For privacy, Jewel collects limited PII from employees for HR and payroll, processes it only for defined purposes, uses third-party systems under DPAs, and applies technical and organizational controls. Data subjects have rights of access, correction, deletion and objection. Continuous improvement is ensured through audits, checks, non-conformity handling and annual management review.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Jewel’s approved Change Procedure defines how changes are registered, classified, assessed, planned and executed. All changes are logged in the Change Register using the _Changes template. Changes arise from risks, incidents, or improvements and are first discussed and approved in Monthly/Quarterly management meetings. Changes are categorized as technical, personnel, organizational, physical, or supplier; non-technical changes follow this procedure. For each change, impact and risk (L/M/H) are identified. An execution plan is then created covering testing, emergency/rollback, process updates, and business continuity, and must be approved by management before the change is carried out.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Jewel operates a continuous vulnerability management process aligned with ISO 27001. We assess threats through automated scanning, secure‑by‑design reviews, penetration testing, and ongoing monitoring of our Azure-hosted environment. Critical vulnerabilities are patched within 24 hours, high‑severity issues within 72 hours, and others as part of scheduled maintenance. Threat intelligence is sourced from Microsoft Security Center, NCSC advisories, industry CERT feeds, OWASP updates, and Azure’s continuous security alerts. All findings are logged, assessed for impact, and remediated through our change‑management process to ensure service integrity and customer protection.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We continuously monitor our Azure‑hosted platform using automated log analysis, anomaly detection, audit logs, and Azure Security Center alerts. Potential compromises are identified through suspicious login patterns, integrity breaches, unusual system behaviour, or threat‑intelligence flags. When detected, incidents are triaged immediately, contained, investigated, and resolved following our ISO 27001 incident‑response procedures. Critical incidents receive an immediate response (typically within hours), with high‑severity issues addressed within one business day. Evidence collection, root‑cause analysis, and corrective actions follow established ISO 27001 controls to prevent recurrence.
Incident management type
Supplier-defined controls
Incident management approach
Jewel follows a formal ISO 27001‑aligned incident‑management procedure with predefined workflows for common security events. Users report incidents through the documented internal reporting route to management, where events are logged, classified, and escalated when required. Response steps—including containment, evidence preservation, analysis, and resolution—follow standardised processes ensuring fast and orderly handling. Incident reports are produced according to the same procedure, including assessment, outcome, and corrective actions, and shared with relevant stakeholders.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
- Limited access to the platform with predefined KPI's; TBD
- Limited period; TBD

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
DEKRA
ISO/IEC 27001 accreditation date
Wednesday 18 September 2019
What the ISO/IEC 27001 doesn’t cover
-
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@jewelsoftware.com. Tell them what format you need. It will help if you say what assistive technology you use.