Thermal Energy Resource Modelling and Optimisation System
THERMOS enables local authorities to plan district heating networks with trusted results. Using advanced algorithms, it identifies optimal heat network solutions at building level within minutes, supporting pre-feasibility studies helping urban areas reach net zero. The tool produces comparable, scalable scenarios to prioritise investment.
Features
- Identifies optimal heat‑network solutions within minutes using advanced algorithms.
- Consider energy output and costs over time with varying tariffs.
- OpenStreetMap for quick and easy map creation and analysis.
- Automatically estimates heat demand for every building.
- Generates optimised network scenarios that identifies priority opportunities.
- Standardised datasets, enabling replicable and comparable results.
- Interoperable GIS formats for results and heat map export.
- Network supply model that simulates detailed heat supply for planning.
- Uses National Zoning Model zone outputs.
- Comprehensive documentation of data requirements and model operation
Benefits
- Makes heat‑network planning faster, more transparent and more cost‑effective.
- Automation replaces manual modelling, significantly reducing staff time.
- Streamlines early‑stage assessments saving money.
- Detailed supply modelling reduces risk of incorrectly sized energy infrastructure.
- Quickly visualise high‑value zones and communicate insights clearly.
- Empowers heat network zoning authorities to make data‑driven decisions.
- Consistent outputs suitable for a zonal market prospectus documentation
- Strengthens contract award decisions through independent assessment of estimates.
- Helps deliver heat network objectives within the Warm Homes Plan.
- Trusted independent charity with, proven expertise in heat network research.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 7 4 0 5 9 3 7 4 7 0 1 8 3 7
Contact
CENTRE FOR SUSTAINABLE ENERGY
<removed>
Telephone: <removed>
Email: csefunding@cse.org.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Location and geospatial data management and analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Some down time is required for scheduled maintenance and upgrades. These are carefully planned in advance and, whenever possible, carried out outside peak usage times to minimise disruption.
- System requirements
- Requires access to a web browser and an internet connection
User support
- Email or online ticketing support
- Yes
- Support response times
- We aim to provide same‑day responses during standard office hours and working days wherever possible. For more complex enquiries requiring investigation, we issue regular progress updates in line with the severity and nature of the issue.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- Every customer is assigned a dedicated technical account manager who serves as their primary point of contact for any technical support needs. In addition, we operate a team‑monitored support mailbox that is reviewed daily to ensure queries are picked up promptly and handled efficiently.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We support users in getting started through a structured onboarding process designed to ensure a smooth introduction to the service. Users have access to comprehensive online resources, including documentation, user guides, and video‑based training materials, all available at any time via the THERMOS website so they can learn at their own pace. In addition the service is highly intuitive, minimising the need for extensive formal training.
Bespoke individual training can also be provided at an additional cost. This training is delivered online via Microsoft Teams and can accommodate up to six attendees. It is task‑oriented and tailored to the user’s own data, incorporating realistic, real‑world modelling scenarios to maximise relevance and effectiveness. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Users have full access to extract heat-network diagrams and maps directly from the user interface at any time during the contract. If preferred, we can provide a full data‑extraction service in a user‑defined format as part of off‑boarding; this is available on request for an additional charge.
- End-of-contract process
-
At the end of the contract, we work closely with the customer to ensure a smooth and secure off‑boarding process. We notify the customer in advance of the contract end date and clearly outline the steps involved.
Customers are supported in exporting any final heat‑network diagrams or maps they wish to retain prior to service termination.
We then issue a formal termination notice confirming the agreed service switch‑off date. At this stage, the customer may choose either to have their account and access permissions downgraded to the free‑to‑use version of the service or to have their account permanently deleted. Once the chosen action has been completed, we notify the customer to confirm that their request has been fulfilled.
We also offer the customer the option to take part in an exit interview to capture their experience, understand their reasons for leaving, and gather feedback to inform future service improvements. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding guidance is provided directly by our team and supplied to the customer via email. We guide the customer through each step of the process. All supporting user documentation is provided in accessible digital formats at the start of the contract and is also available online via the THERMOS website. The written content follows accessibility best practice and is presented in jargon‑free plain English.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed through a standard browser‑based web interface designed with a clear layout, consistent navigation and standard HTML controls.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Our service has been designed to be as accessible as practicable for a geospatial mapping service. The interface follows recognised accessibility good practice, including a clear visual hierarchy, consistent layouts, and keyboard navigation for core features. The service does not use flashing content, video, or time‑dependent interactions, and users can adjust their own browser settings to increase text size, contrast, or apply high‑contrast modes. However, some map‑based interactions, are not fully accessible to users. These limitations are inherent in geospatial solutions.
- Accessibility testing
- We have not conducted formal usability testing with assistive technology users. However, we follow general good‑practice web design principles to support clarity and ease of use. During routine development and QA, we focus on ensuring the interface behaves predictably and consistently for all users, with attention to straightforward navigation and clear layouts. We will respond positively to accessibility‑related feedback and would consider making reasonable adjustments where feasible.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- The service is designed so that typical user activity does not create excessive load on the underlying system. We monitor server performance and capacity regularly to ensure that the service continues to perform reliably for all users. Our development and database design follow good practice to minimise resource‑heavy operations, and we periodically review performance and make infrastructure or configuration improvements where needed. While we do not operate a multi‑tenant auto‑scaling architecture, we actively manage capacity and system health to minimise the risk that demand from one user affects the experience of others.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Users can export their own user‑generated data directly through the service interface, including heat‑network diagrams and maps. If a customer requires a single comprehensive extract of all data for one or multiple projects, we can provide this as an additional chargeable service.
- Data export formats
- Other
- Other data export formats
-
- XLSX (Office open xml).
- GeoJSON
- Data import formats
- Other
- Other data import formats
-
- XLSX (Office Open XML)
- GeoJSON
- ESRI ShapeFile
- GeoPackage (GPKG)
- LAS/LAZ (LiDAR point cloud formats)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Administrative access to our servers is performed only via SSH, secured through strong authentication, hardened configurations, and tightly controlled network paths.
Availability and resilience
- Guaranteed availability
- We operate to a monthly uptime percentage of 99.5%. We don't have a set refund policy.
- Approach to resilience
- Our resilience approach focuses on maintaining a stable environment, keeping recoverable backups, and ensuring that we can restore or recreate the service in a timely manner if the need arises. We follow standard good‑practice measures to support stability and continuity. These include routine monitoring, applying security and system updates, and maintaining regular backups and snapshots.
- Outage reporting
- We notify customers of any service outage or significant disruption via email. If an issue is identified, we provide an initial notification with details of the impact and our current assessment, followed by updates as the issue progresses. A final communication is sent once the service is fully restored. For planned maintenance or expected downtime, we provide advance notice by email to all customer contacts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Individual account
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We operate a risk‑based security governance model overseen by a named senior security owner. Our security policies are reviewed at least annually and updated as required. We enforce least‑privilege access, strong authentication for administrative roles, and peer‑reviewed, controlled change processes. All staff complete mandatory annual security awareness training covering phishing, data handling, incident reporting and acceptable use. Software engineers receive additional role‑specific guidance on secure coding and change control to ensure secure development practices are consistently followed.
- Information security policies and processes
-
We follow documented information security policies and processes that align with the UK Cyber Essentials scheme, which we are certified against. This includes controls for secure configuration, access management, malware protection, boundary firewalls, and the management of security updates.
System and software patches are applied in accordance with Cyber Essentials requirements, ensuring that supported versions are used and security updates are installed promptly as part of our regular maintenance process. Vulnerability checks are carried out during updates, and high‑risk issues are prioritised for rapid remediation.
Operational policies cover account management (joiners, movers, leavers), logging and monitoring, incident management, business continuity, supplier management, and data handling. Customer‑provided datasets are handled in accordance with contractual and licensing requirements, including secure deletion at contract end.
All policies and procedures are reviewed regularly and updated when risks, technology, or customer needs change. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We operate a documented configuration and change management process to ensure all updates are controlled and secure. All source code is managed in GitHub using branch protection, pull requests and mandatory peer review before changes are merged. Only authorised personnel can approve or deploy changes. Releases follow a defined release process that includes testing, review, and sign‑off before deployment to production. All changes are logged, version‑controlled, and traceable, with rollback procedures available if required. This approach ensures consistent, secure, and auditable change control across the service.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We follow supplier-defined vulnerability management controls aligned to Cyber Essentials requirements. We monitor vendor advisories and security updates for our operating systems, third-party services and software dependencies, prioritise remediation based on severity and exposure, and apply patches through our documented maintenance and release process. High-risk vulnerabilities are escalated and addressed as a priority, with changes tracked and deployed via controlled release procedures.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- System, application and access logs are collected and reviewed as part of normal operations, with alerts for error conditions or abnormal behaviour. Administrative access is logged and restricted to authorised personnel. Security‑related events identified through monitoring or reported by customers are triaged and responded to based on severity and potential impact. Critical issues are prioritised and can be acted on rapidly, with actions tracked through to full resolution.
- Incident management type
- Supplier-defined controls
- Incident management approach
- All incidents detected through monitoring, internal review or customer reports follow the same documented process. Users report incidents by emailing our support team, where they are logged and triaged by severity. High‑severity issues are prioritised and actioned rapidly. All actions are tracked through to closure, and full incident reports can be provided on request as PDF email attachments. Significant incidents undergo a post‑incident review to identify opportunities for service improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- The free trial is available to anyone but is limited in the following ways: up to 10 optimisations every 7 days, a maximum of 8,000 uploaded assets (roads or buildings), a maximum one‑hour runtime per optimisation, and all optimisation jobs run outside of peak times.
- Link to free trial
- https://tool.thermos-project.eu.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Bf58754f-9688-4661-a10a-bfd241c49382
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-