Causeway AccsMap
Cloud-based collision analysis service providing validated, auditable STATS19and STATS21 insights. Enables spatial analysis, configurable reporting and DfT-compliant exports. Integrated dashboards, APIs and connectivity support evidence-led road safety, funding justification and cross-authority collaboration.
Features
- Validated STATS19 collision data processing, CRASH, NICHE loading
- Spatial collision analysis with configurable dashboards and mapping
- DfT-compliant data exports and reporting
- API based integration and file-based data exchange to streamline workflows
- Facilitates collaboration across multiple stakeholders including authorities and police forces
- Cross-authority comparative data analysis
- Role-based access and audit controls
- Manage statutory changes to STATS19, STATS20, STATS21 data structures
- Scalable, fully managed SaaS platform
Benefits
- Produce trusted evidence for funding and safety interventions
- Defend decisions with auditable, validated collision data
- Analyse vehicle collisions, trends and accident hot spots
- Identify collision trends and high-risk locations faster
- Meet statutory data processing and reporting obligations
- Reduce manual reporting and data reconciliation effort
- Support transparent public and stakeholder reporting
- Adapt rapidly to regulatory or data structure changes
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 3 5 1 8 6 4 5 9 7 9 3 0 0
Contact
CAUSEWAY TECHNOLOGIES LIMITED
Steve White
Telephone: 01628552000
Email: salesukgov@causeway.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Project and portfolio management
- Asset life-cycle management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Although the service is built to work primarily in a Microsoft Windows based environment, it can be accessed via other platforms, such as Mac OS. However, there may be individual applications licencing restraints.
- System requirements
-
- Citrix Work space App - latest recommended version installed
- Internet browers - Microsoft Edge, Firefox, Safari, Chrome etc.
User support
- Email or online ticketing support
- Yes
- Support response times
- Within the teams standard support hours 07:30 - 17:30 Monday - Friday, in alignment to SLA.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- 1st, 2nd and 3rd-line Support for all customers. Support charges are included within annual fees. We provide a dedicated Account Manager for certain customers, with access to the Account Management team for renewals for the remaining customers.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Onboarding support via professional services if requested.
How to guides
Online training videos - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- CHM
- End-of-contract data extraction
- At the end of the contract and including at anytime during the contract, designated users are able to export data in standard formats such as MapInfo Tab, MapInfo Midmif, ESRI Shp files. These exports can be saved to local networks or on specified FTP or SFTP sites. These exports can then be imported by other systems for use elsewhere.
- End-of-contract process
- One month prior to the end of the contract, users will be notified that the contract will be coming to an end. Designated users will be advised to carry out an export and copy all data that has been generated during the contract to local networks or FTP/SFTP site. At the end of the contract date, all user logins will be deactivated. Other associated data such as base-mapping and address gazetteers will be provided back to the client in the standard/native format. There are no additional costs for supplying the data to the client at the end of the contract into the above mentioned standard formats. Costs may apply if the client requires data to be provided in another format.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Mobile service is for disseminating data, and as such is read-only, with very limited editing abilities.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- A modern web client without plugins or Citrix Workspace app.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Tests were carried using SortSite by PowerMapper and manual methods.
- API
- Yes
- What users can and can't do using the API
- We have an API that links into our collision database used by the AccsMap Dashboards and Download Centre. This database has GB coverage and is based on data supplied by the DfT on an annual basis and has data upto 2024. We can supply a link to this and API key that can be used to extract data for a specific LA or police area and also by date range. The data is returned in geoJSON format and contains most STATS19 attributes. The service is for viewing purposes only and no edits or updates can made.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Designated users, such as a supervisor or system administrator are able to customize the core element of the solution relating to collision analysis and make adaptations to meet the requirement of the clients. Areas that can be customized include, but are not limited to: • Flexible reporting, changing cluster locations • Export formats (e.g. exclusion of sensitive data) • Styles, size and colour based on different categories of accidents. E.g. by vehicle type or age of drivers, etc. • Print templates, adding corporate logo, scale bars, legend location and north arrow • Temporary Inclusion of other authority’s collision related data. From within AccsMap users can securely download any mainland authority’s collision data (with associated mapping). This will be used in conjunction with other open data sets based on SOA these include: population, deprivation, IMD index and traffic flow rates.
Scaling
- Independence of resources
- Usage and performance monitoring in parallel with onboarding management. All of our services are cloud based and are designed to scale with any increased service demands.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Dashboards and reports are available within the service, accessible to users with relevant permissions. Additional metrics can be provided upon request.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Causeway protects data by using encryption for both data at rest and in transit. Data at rest is encrypted using industry-standard methods such as AES256, including backups. Data in transit is encrypted using HTTPS with TLS1.2 as a minimum standard, and secure protocols such as SFTP are also employed. Encryption is implemented across endpoints, servers, mobile devices, databases, backups, and removable media.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Via the service client.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- Shapefile SHP
- Mapinto TAB
- AutoCAD DXF
- GeoJSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Shapefile SHP
- Mapinfo TAB
- GeoJSON
- CRASH XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Each product has a set of SLAs which can be provided on request but do not fall below 99.5%
- Approach to resilience
-
Our products are designed with high availability and resilience as a core function. Dependent on the base infrastructure in use this could either be cloud based multi zone failover or highly resilient data centre replication.
Back up infrastructure methodology is platform dependent and consists of snap shots, bootable instance images, and back-ups at regular intervals. - Outage reporting
- Systems fully monitored. Server and database issue/outage alerts and alarms. Monitoring systems vary depending on the native solutions to the cloud environments in use.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Our own managed Active Directory and Radius Service.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Cyber Essentials
ISO9001
ISO22301
ISO14001
ISO45001 - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- The Asset Management policy requires assets to be recorded in the CMBD where assets are recorded and changes to those assets are managed through the Change Management Process. The process looks at the risk associated with those changes. These include, Security, Privacy, Legal and Operational.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Our vulnerability management process is structured in four phases. The vulnerability management process phases are:
• Identifying Technical Vulnerabilities
• Evaluating Technical Vulnerabilities
• Address Technical Vulnerabilities
• Vulnerability Management Improvement" - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our SoC consumes log data from a number of sources (Product, M365 and Infrastructure) to correlate and analyse activity that may relate to threat actor behaviour. These are triaged and managed in line with SOPs and where necessary incident response process are initiated to respond, contain and recover from any incident.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Customer incidents can be raised directly and these are handled by a customer facing incident management team. Customer are informed and updated in line with standard SLAs.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Thursday 21 November 2024
- What the ISO/IEC 27001 doesn’t cover
- The whole business is in scope
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Thursday 21 November 2024
- What the ISO 9001 doesn’t cover
- The whole business is in scope
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5f69f5de-1a85-4a22-8d1f-d26642e411b2
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for positive actions with community groups.
-