Skip to main content

Help us improve the Digital Marketplace - send your feedback

CAUSEWAY TECHNOLOGIES LIMITED

Causeway AccsMap

Cloud-based collision analysis service providing validated, auditable STATS19and STATS21 insights. Enables spatial analysis, configurable reporting and DfT-compliant exports. Integrated dashboards, APIs and connectivity support evidence-led road safety, funding justification and cross-authority collaboration.

Features

  • Validated STATS19 collision data processing, CRASH, NICHE loading
  • Spatial collision analysis with configurable dashboards and mapping
  • DfT-compliant data exports and reporting
  • API based integration and file-based data exchange to streamline workflows
  • Facilitates collaboration across multiple stakeholders including authorities and police forces
  • Cross-authority comparative data analysis
  • Role-based access and audit controls
  • Manage statutory changes to STATS19, STATS20, STATS21 data structures
  • Scalable, fully managed SaaS platform

Benefits

  • Produce trusted evidence for funding and safety interventions
  • Defend decisions with auditable, validated collision data
  • Analyse vehicle collisions, trends and accident hot spots
  • Identify collision trends and high-risk locations faster
  • Meet statutory data processing and reporting obligations
  • Reduce manual reporting and data reconciliation effort
  • Support transparent public and stakeholder reporting
  • Adapt rapidly to regulatory or data structure changes

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at salesukgov@causeway.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 6 3 5 1 8 6 4 5 9 7 9 3 0 0

Contact

CAUSEWAY TECHNOLOGIES LIMITED Steve White
Telephone: 01628552000
Email: salesukgov@causeway.com

About your service

Service categories

Applications

Enterprise resource management

  • Project and portfolio management
  • Asset life-cycle management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Although the service is built to work primarily in a Microsoft Windows based environment, it can be accessed via other platforms, such as Mac OS. However, there may be individual applications licencing restraints.
System requirements
  • Citrix Work space App - latest recommended version installed
  • Internet browers - Microsoft Edge, Firefox, Safari, Chrome etc.

User support

Email or online ticketing support
Yes
Support response times
Within the teams standard support hours 07:30 - 17:30 Monday - Friday, in alignment to SLA.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
1st, 2nd and 3rd-line Support for all customers. Support charges are included within annual fees. We provide a dedicated Account Manager for certain customers, with access to the Account Management team for renewals for the remaining customers.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Onboarding support via professional services if requested.
How to guides
Online training videos
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
CHM
End-of-contract data extraction
At the end of the contract and including at anytime during the contract, designated users are able to export data in standard formats such as MapInfo Tab, MapInfo Midmif, ESRI Shp files. These exports can be saved to local networks or on specified FTP or SFTP sites. These exports can then be imported by other systems for use elsewhere.
End-of-contract process
One month prior to the end of the contract, users will be notified that the contract will be coming to an end. Designated users will be advised to carry out an export and copy all data that has been generated during the contract to local networks or FTP/SFTP site. At the end of the contract date, all user logins will be deactivated. Other associated data such as base-mapping and address gazetteers will be provided back to the client in the standard/native format. There are no additional costs for supplying the data to the client at the end of the contract into the above mentioned standard formats. Costs may apply if the client requires data to be provided in another format.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mobile service is for disseminating data, and as such is read-only, with very limited editing abilities.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
A modern web client without plugins or Citrix Workspace app.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Tests were carried using SortSite by PowerMapper and manual methods.
API
Yes
What users can and can't do using the API
We have an API that links into our collision database used by the AccsMap Dashboards and Download Centre. This database has GB coverage and is based on data supplied by the DfT on an annual basis and has data upto 2024. We can supply a link to this and API key that can be used to extract data for a specific LA or police area and also by date range. The data is returned in geoJSON format and contains most STATS19 attributes. The service is for viewing purposes only and no edits or updates can made.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Designated users, such as a supervisor or system administrator are able to customize the core element of the solution relating to collision analysis and make adaptations to meet the requirement of the clients. Areas that can be customized include, but are not limited to: • Flexible reporting, changing cluster locations • Export formats (e.g. exclusion of sensitive data) • Styles, size and colour based on different categories of accidents. E.g. by vehicle type or age of drivers, etc. • Print templates, adding corporate logo, scale bars, legend location and north arrow • Temporary Inclusion of other authority’s collision related data. From within AccsMap users can securely download any mainland authority’s collision data (with associated mapping). This will be used in conjunction with other open data sets based on SOA these include: population, deprivation, IMD index and traffic flow rates.

Scaling

Independence of resources
Usage and performance monitoring in parallel with onboarding management. All of our services are cloud based and are designed to scale with any increased service demands.

Analytics

Service usage metrics
Yes
Metrics types
Dashboards and reports are available within the service, accessible to users with relevant permissions. Additional metrics can be provided upon request.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Causeway protects data by using encryption for both data at rest and in transit. Data at rest is encrypted using industry-standard methods such as AES256, including backups. Data in transit is encrypted using HTTPS with TLS1.2 as a minimum standard, and secure protocols such as SFTP are also employed. Encryption is implemented across endpoints, servers, mobile devices, databases, backups, and removable media.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Via the service client.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • Shapefile SHP
  • Mapinto TAB
  • AutoCAD DXF
  • GeoJSON
Data import formats
  • CSV
  • Other
Other data import formats
  • Shapefile SHP
  • Mapinfo TAB
  • GeoJSON
  • CRASH XML

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Each product has a set of SLAs which can be provided on request but do not fall below 99.5%
Approach to resilience
Our products are designed with high availability and resilience as a core function. Dependent on the base infrastructure in use this could either be cloud based multi zone failover or highly resilient data centre replication.

Back up infrastructure methodology is platform dependent and consists of snap shots, bootable instance images, and back-ups at regular intervals.
Outage reporting
Systems fully monitored. Server and database issue/outage alerts and alarms. Monitoring systems vary depending on the native solutions to the cloud environments in use.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Our own managed Active Directory and Radius Service.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Cyber Essentials
ISO9001
ISO22301
ISO14001
ISO45001
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
The Asset Management policy requires assets to be recorded in the CMBD where assets are recorded and changes to those assets are managed through the Change Management Process. The process looks at the risk associated with those changes. These include, Security, Privacy, Legal and Operational.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our vulnerability management process is structured in four phases. The vulnerability management process phases are:
• Identifying Technical Vulnerabilities
• Evaluating Technical Vulnerabilities
• Address Technical Vulnerabilities
• Vulnerability Management Improvement"
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Our SoC consumes log data from a number of sources (Product, M365 and Infrastructure) to correlate and analyse activity that may relate to threat actor behaviour. These are triaged and managed in line with SOPs and where necessary incident response process are initiated to respond, contain and recover from any incident.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Customer incidents can be raised directly and these are handled by a customer facing incident management team. Customer are informed and updated in line with standard SLAs.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
7%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
LRQA
ISO/IEC 27001 accreditation date
Thursday 21 November 2024
What the ISO/IEC 27001 doesn’t cover
The whole business is in scope
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
LRQA
ISO 9001 accreditation date
Thursday 21 November 2024
What the ISO 9001 doesn’t cover
The whole business is in scope
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
5f69f5de-1a85-4a22-8d1f-d26642e411b2
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Plans for positive actions with community groups.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at salesukgov@causeway.com. Tell them what format you need. It will help if you say what assistive technology you use.