Construction and Property Management Software
Zutec is a provider of cloud-based construction and property management software with over two decades experience in supporting contractors, housebuilders, developers, and asset owners manage building data. One platform provides solutions for document management, quality management, handover management and asset management, digitally connecting information across the building lifecycle.
Features
- Cloud-based remote access
- Single Sign On (SSO) & 2 Factor Authentication (2FA)
- Search Engine
- Folder Tree & Data Register
- Workflow & Forms
- Data Exports - PDF, XML, Excel
- Real-time Reporting, Dashbaords, Image Viewing and Mark Ups
- Mobile Field App with Offline Mode
- AI enabled chatbot to quickly find information
- View 3D Models Linked to Cloud Data
Benefits
- Digitise multiple processes across the building lifecycle
- Quickly manage information in the field or in the office
- Centralised compliance platform for the Building Safety Act
- Enables Part L Photographic Evidence Compliance
- Single Source of Truth for construction and building data
- Easily share documents with all stakeholders including assessors and regulators
- Golden Thread of Information for managing buildings
- Fill out inspections and forms from any device
- One audit trail of building information across life of asset
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 2 7 0 6 4 8 9 0 6 1 0 4 5
Contact
ZUTEC INC. (UK) LIMITED
Maria Hudson
Telephone: 07967813429
Email: maria.hudson@zutec.com
About your service
- Service categories
-
Application Development and Deployment
Data management
Data integration and intelligence
- Data Quality Software
- Master Data Intelligence Software
- Metadata Management Software
- Data Archiving and Information LifD-Cycle Management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- None
- System requirements
-
- Modern web browsers
- Mobile Phones with current supporting operating systems
- BIM requires 25G free disk space 8 GB of RAM.
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 24 hours Monday to Friday.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Zutec clients submit support tickets either via email (support@zutec.com) or via the support portal. Where clients use the portal they can track their tickets more easily.
Portal: Clients will have the ability to create either of the following
- Technical Support
- Request a New Feature
Email: When a client submits their request via email we have no ability to control the ticket.
Support is categorised into the following:
P1: Critical: Interruption making a critical functionality inaccessible or a complete network interruption causing a severe impact on the software platform’s availability. Highest priority request.
P2: Important: Critical functionality or network access interrupted, degraded or unusable, having a severe impact on the software platform’s availability. High Priority Request with strict deadline.
P3: Normal: Non-critical functionality is unusable or hard to use having an operational impact.
P4: Low: Application or procedure unusable, or information request with no urgency.
P5: Very Low: Application of procedure is unusable, where a workaround is available.
For those that purchase it, Technical Account Management (TAM) hours can be provided but this is costed on an account by account basis, based on which solutions purchased, at what level (project or enterprise) and hours required. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Zutec has an implementation and onboarding team, which provides online training and user documentation.
Super users are trained within each customer, who will then go on to train other users within the business. We find this works well at Zutec, as this allows there to be points of contacts within the customers, and means we can ensure training is focused on a few key users.
The training team provide a thorough training programme to get the right people up to speed and fully engaged in the solution to ensure ongoing user adoption. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Video
- Powerpoint
- In platform tutorials for some solutions
- End-of-contract data extraction
-
If and when a contract ends, users can extract their data through a snapshot export, excel file or XML export.
User simply click export and choose excel to extract data.
Users can also request a snapshot from the Zutec support team. - End-of-contract process
-
At th end of the contract, platform access is removed and a snapshot can be requested.
Data should be exported within contract timeline at no extra costs. - Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Designed for mobile and and desktop, the mobile version is suitable for recent iOS and Android devices, and can be used in the field or on site to complete forms, checklists, and inspections, as well as capture evidence of work done or building maintenance, such as photographic evidence, as an example.
The desktop version provides dashboards, which can be used for tracking project progress, managing subcontractors and suppliers, reporting and analytics, accessing an audit trail of building information or construction data, supporting decision-making, identifying gaps in data and understanding compliance. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- APIs can be enabled by our Implementation team. At a high level our APIs allow push and pull of data and files and are in JSON format.
- API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Customisation is handled by the Zutec implementation and product teams, and applies to forms, workflow, as well as a features and new capabilities hen requested.
Users can request platform customisations, which are reviewed, scoped and prioritised based on the customisation and requirements to deliver the customisation. Customisations will be priced based on customisation request and effort on the team.
The Zutec platform itself provides standard templates, howeverr it is also highly configurable, and when implementation is scoped, configuration can be discussed, reviewed and priced to ensure the best solution is delivered for each customer.
Scaling
- Independence of resources
-
We have a fair usage policy, found here: https://zutec.com/fair-use-policy
We also constantly monitor the service to ensure users are operating inside the remit of the fair usage policy. Any users that appear to be taking advantage of the system will be given a warning or service put on hold to ensure that all users are not impacted by the demand of other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Service metrics we provide are measures, but not limited to
- User logins
- Actions taken on platform
- Data uploaded and downloaded
- Users added to platfrom
- User feedback - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Within the platform, users can click Export and Choose Excel to extract data.
Under a standard license up to 500 MB of files can be downloaded per site per day, or up to 100 export files or API transactions per site per day.
Where there is a requirement to download more files, our account management team is able to help. - Data export formats
- Other
- Other data export formats
-
- XML
- Excel
- HTML
- Data import formats
- Other
- Other data import formats
-
- XML
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
An SLA is provided to enterprise customers, to support and sustain the Zutec Cloud Platform, and Field and BIM applications.
The goal of the SLA is to obtain mutual agreement for software service provision between the Zutec and the Customer to:
- Provide clear reference to service ownership, accountability, roles and/or
responsibilities.
- Present a clear, concise and measurable description of service provision to the
customer.
- Match perceptions of expected service provision with actual service support & delivery.
As an example, the software platform will be operational and available to users 24/7 with an uptime SLA of 99.9% in any given month, not including scheduled downtime for maintenance.Where required, customers will be notified in advance of any planned unavailability.
All Zutec servers are located at secure hosting facilities within the UK and
Ireland, unless another location has been requested in the contract. On-
premise installations are available if purchased and separate terms defined
for these in the specific contract.
A backup of the Customer’s information including data held in the database is taken daily. Backups are stored in a mirrored hosting environment to allow for quick recovery. - Approach to resilience
-
Our platform has dual, network, power redundancy.
All systems have redundant Disks with DR Servers running in standby mode
RTO: 6 Hours
RPO: 24 Hours - Outage reporting
- If there is an outage on the service we will report these via a public dashboard, and depending on the severity of the outage, we would also use email to communicate with customers.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Enterprise-leel single sign on.
- Access restrictions in management interfaces and support channels
-
At Zutec, we have a strict onboarding / off boarding process and we test our systems access controls every month.
Our solutions also allow customers to restrict access to users, depending on the user type. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Other
- Description of management access authentication
- Firewall restrictions blocked by location IP address.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Fully applied ISO27001 with all clauses in effect.
Policies are defined by Security Officer. Information security statement is signed by the CEO and enacted by the senior management team down to all reporting lines. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
When changes are identified, they are then qualified by type and size and impact. Minor changes with low risk are implemented. Major Changes are risk assessed in accordance with ISO27001 risk methodologies.
Changes are then approved and signed off and implemented. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
At Zutec we do regular vulnerability scans. If a vulnerability is detected, we have resolutions scoring:
- A priority 1 (P1) vulnerability = 24 Hour Resolution
- A priority 2 (P2) vulnerability = 1 Week Resolution
- A priority 3 (P3) vulnerability =3 Week Resolution
A priority 4 0r 5 (P3 or P 5) vulnerability = Within 1 Month
We receive vulnerability newsletters on the tech stack we use, these are reviewed daily. - Protective monitoring type
- Undisclosed
- Protective monitoring approach
-
We run Firewalls with IDS & IPS
We also have a Gartner endorsed monitoring system running across our entire network which monitors problems on our Cloud infrastructure.
We respond to incidents as immediately, and the prioritise them to ensure quick resolution. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We conform to ISO27001
The high level process at Zutec includes:
- Users report security issues to our support team
- They are escalated to Chief of Security
- Issue is classified and Investigated
- Issue is resolved.
- Users are kept in communication feedback with regular updates.
- Report is compiled and shared with customer. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA: https://www.nqa.com
- ISO/IEC 27001 accreditation date
- Tuesday 1 April 2025
- What the ISO/IEC 27001 doesn’t cover
- Zutec is fully covered
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 499ceb61-80ae-454d-986b-1a29997bced1
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- BSI BIM Kitemark
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-