Skip to main content

Help us improve the Digital Marketplace - send your feedback

PENTAGULL LTD

Fleet management

Fleet Management system is a cloud software service for managing every aspect of a fleet of vehicles, plant and associated assets. It has been designed uniquely for the needs of local authority transport managers and caters to the unique challenges faced by local authorities when managing an in-house fleet.

Features

  • Built-in asset register
  • Scheduled and reactive maintenance module
  • Defect management
  • Driver database
  • Accident and incident database
  • Comprehensive integration with third party systems
  • Complete managed service via the Cloud
  • Designed and developed with local government
  • Sustainable, flexible and future-proof.
  • Data management module for GDPR compliance

Benefits

  • Facilitates cost reductions
  • Streamlines processes
  • Secure data model
  • Facilitates consistency
  • Simple to change and maintain
  • Extremely flexible and sustainable
  • Powerful reporting tools
  • Enables mobile and agile working
  • Reduction in paperwork

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@pentagull.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 7 3 1 9 2 1 4 1 2 1 7 9 3 4

Contact

PENTAGULL LTD Stuart Gilbert
Telephone: 0845 680 7147
Email: sales@pentagull.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Other
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
Maintenance Windows:- Maintenance windows for regular maintenance and product updates are always scheduled outside normal working hours.

We aim to give at least 48 hours’ notice of any planned maintenance work that we intend to undertake.

Product Schedules:- Product roadmap and related information is available on request.
System requirements
  • Supported web-browsers
  • Working LAN, firewall and internet connectivity

User support

Email or online ticketing support
Yes
Support response times
Dedicated customer service number, manned from 9am to 5pm excluding English national holidays. All customers have access to our dedicated customer helpdesk via phone and on-line 24 -7.

• Priority A: System not usable or service down - 1 hour
• Priority B: Important production job or service will not run - 4 hours
• Priority C: Any other problem call - 1 day

By agreement for weekends and bank holidays.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Unlimited support is standard and included within the licence charge. All customers benefit from the same excellent level of support.
Target resolution times are set out below:

Priority A - Target resolution time of 4 hours.
Priority B - Target resolution time of 5 business days.
Priority C - Target resolution time of 10 business days.

Each customer will be provided with a dedicated Account Manager available between 9am and 5.00pm (Monday - Friday).
Support available to third parties
No

Onboarding and offboarding

Getting started
Pentagull's general onboarding plan consists of:

Preparation
• Identify stakeholders - determine who will use the service (e.g., administrators, employees, and IT support).
• Dedicated implementation team - establish a team to assist with any issues or questions during onboarding
• Draw up initial implementation timeline

Initial Setup/Configuration
• System installation and subsequent configuration - ensure the service is deployed correctly and then tailor the system to meet the organisation's specific needs working with the relevant stakeholders (e.g. - user roles, permissions, custom fields, corporate skin for online forms).
• User account creation - create accounts for all users, assign appropriate roles, and distribute login credentials if not using federated access

Online Training Sessions
• Kick-off meeting - introduce the system to all stakeholders that haven't been involved with the configuration
• Employees - basic training on how to use the system.
• Administrators - deeper training on system configuration, user management, reporting, and troubleshooting.

Feedback and Continuous Improvement
• Iterative improvements - continuously refine the system, training materials and support processes based on user feedback which is canvassed regularly.

Support Handover
• Set up relevant users to access support channels.
• Provide access to the support desk.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
The service has in-built functionality to extract information in various formats available to the users.
If the data is required in a different format or there is a bespoke requirement to the extraction of the data then this will need to be estimated and the work costed accordingly with prices based on our standard day rate defined in the pricing document.
End-of-contract process
• Pentagull will identify all the relevant stakeholders involved in the service and use this for the communication plan
• Pentagull will create a detailed-timeline with milestones for the exit plan
• Pentagull will collaborate with the service to define the relevant data format
• At the appropriate date specified in the detailed-timeline, the current data on the system will then be transferred via the appropriate secure mechanism (sFTP, file share, etc) in the format specified
• Assurances will need to be given by the authority that the data has been received and validated (correct data in the correct format)
• At the appropriate date specified in the detailed-timeline, user permissions will be revoked from the system
• At the appropriate date specified in the detailed-timeline, the data will be permanently deleted from the system
• The authority will then satisfy themselves that this has been completed with a temporary user on the system, on confirmation of this Pentagull will remove the temporary user
• Pentagull will then fully decommission the digital service, this ensures urls to the backoffice system and any online forms will no longer be accessible.
• Confirmation of this will be sent to the relevant stakeholders
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Web browser
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Use of accessibility tools such as JAWS have been tested for use with browser form UI. Labels and field content have been verified for speech output. We also utilise the WAVE suite of evaluation tools to ensure our content is accessible for people with disabilities.
API
No
Customisation available
Yes
Description of customisation
The ESB platform provides the functionality to perform in-depth customisation straight out of the box. You can rename and add new fields and sections to your processes with ease. PDF templates can be created and amended to be automatically produced by the system along with bespoke email notifications for your staff or customers.
Our in-built granular permission set allows for precise access changes to processes as staff and situations change without having to resort to contacting Pentagull thus ensuring you have control to deal with variations in the work.
More experienced users can go even further and amend the rules that govern the automation for your processes. This allows you to continually make changes in the workflow of your process ensuring it remains fit for purpose and effective all without incurring any additional costs. Features such as allocation of work to shared or individual workbaskets within the system can be configured by your own staff.
All this customisation is available with no coding knowledge required, the platform is designed to be used by anyone with basic computer literacy and a few days training.

Scaling

Independence of resources
A series of key performance metrics are constantly monitored, ranging from low level operating system counters to high level application layer metrics. This allows us to automatically respond to increases in demand by scaling up the resources allocated to the application before any impact is felt by end-users. By partnering with Amazon Web Services we are able to leverage the vast resources of their Elastic Compute Cloud
(EC2) to ensure that we can continually exceed our capacity requirements.

Analytics

Service usage metrics
Yes
Metrics types
As a web application our primary performance metric is the page response time. This is carefully monitored to ensure it stays within acceptable levels. In addition to the HTTP response metrics, a number of lower-level metrics are monitored to ensure the application stack remains healthy and responsive. These include CPU usage, memory usage and disk I/O metrics.
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
A wide variety of formats and platforms are supported for secure data export. Some will be chargeable over and above the standard formats listed below.
Data export formats
  • CSV
  • Other
Other data export formats
XLSX
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Service Availability - 99.9% up-time per month
Service Availability - 24 hours per day (all days)
Response time for accessing screens - within 3 seconds (99% of the time)
Response time for system searches - within 5 seconds (97% of the time)

If the uptime for the service drops below the relevant threshold (99.9% availability excluding permitted maintenance windows or Force Majeure event), a penalty will be applied in the form of service credits to the buyer.

The level of penalty will be calculated depending on the number of hours for which the service was unavailable, minus the downtime permitted by the SLA and will be capped at 50% of the SaaS charges for the month in which the threshold wasn’t met.
Approach to resilience
Our service is hosted on infrastructure provided by Amazon Web Services, who provide a monthly uptime percentage of 99.99%. To achieve maximum resiliency, we utilise all 3 AWS London data centres (known as Availability Zones) as either active or DR locations. This means that in the event of total data centre failure we are able to resume service using one or both of the alternate locations. Impacts to service delivery caused by more routine events such as server patching, server reboots and failure of individual components are mitigated through the use of load balancing and redundant storage. At the network level, AWS provides multiple carrier-independent feeds to each of its data centres.
Outage reporting
Customer's are contacted directly by a member of the company.
Email alerts can be setup upon request from Pentagull monitoring tools.
The email alerts service is hosted using infrastructure that is totally independent from that which is used to host the service, ensuring that even a catastrophic failure of AWS infrastructure does not affect our ability to communicate with our customers.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access is restricted to designated support staff at a level required for them to perform their role.
In terms of management interfaces there is an escalation process in place whereby senior staff can interface if required.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
As part of our ISO27001 certification, Pentagull applies its comprehensive ISMS (Information Security Management System) throughout the Company. The ISMS manager reports all incidents directly to the board of directors. All policies which form part of the ISO 27001 system are applied to staff as part of their induction to the Company and their yearly reviews. Any policy changed outside this time frame is applied when required.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Change control to our ESB platform’s core is managed through the practice of continuous integration (CI). Each build is tracked through formal version control process supported by a software version control system.
Each new release has formal unit, integration, security and regression testing and is released into our test environment before subsequently being deployed onto our customers live environments.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our vulnerability management process is based on industry standards combined with advice from our own hardware/software suppliers. We regularly review our infrastructure to ensure we identify and categorise components based on risk/impact.

Patching is automated where it’s practical to do so, outside of this there we have a robust patch management procedure including a named individual responsible for patch management. All patches are applied within 7 days of release.

In order to keep abreast of the latest infrastructure threats we obtain information from multiple sources - our own hardware, software and infrastructure suppliers, additionally from a number of industry outlets.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We employ proactive monitoring of various logs to detect unusual patterns of activity. This includes traffic and request patterns, authentication attempts and analysis of source IP addresses.

Our Incident Management System is used to manage and respond to any suspected compromise. This provides us with a structured way of handling potential security issues at each step of the investigation, and ensuring timely disclosure to our customers where appropriate. All suspected security incidents are investigated within 24 hours and co-ordinated by our Security Officer
Incident management type
Supplier-defined controls
Incident management approach
Customers are able to report incidents using our support portal, this is logged directly into our support desk system with automated RAG categorisation and escalation of priority items.

Workflow within this system is also capable of routing specific problems or customers to an individual or team.

The teams also have access to a knowledge based system that enables for rapid diagnosis of problems.

We proactively monitor incidents on a regular basis to highlight any mitigation that we can put in place to reduce the likelihood of re-occurrence.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
World Certification Services
ISO/IEC 27001 accreditation date
Thursday 15 December 2022
What the ISO/IEC 27001 doesn’t cover
Nothing - the scope of our ISO 27001 covers all activities undertaken by the company.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
World Certification Services
ISO 9001 accreditation date
Monday 21 November 2022
What the ISO 9001 doesn’t cover
Nothing - the scope of our ISO 9001 covers all activities undertaken by the company.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
4aa1ab2c-c6ea-4c7c-9465-57c30cce7e36
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Volunteering opportunities for staff
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@pentagull.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.