THEIA360 Digital Twins Virtual Tours
THEIA360 is a cloud-based virtual tour and visual inspection platform for housing and property services organisations. It enables users to capture, manage and share immersive 360-degree tours to support inspections, condition assessments, remote collaboration and asset understanding across property portfolios.
Features
- Real-time automated digital twin virtual tour creation with AutoStich technology
- Tag and identify assets within the virtual tour
- Embed THEIA360 within your own platform
- Customisability branding, content embedding (videos, images, documents)
- High resolution 360 photography
- Systems Integration: Connects with housing and asset management systems
- Enterprise organisation management
Benefits
- Lifecycle Property Condition Tracking: Before/after assessments for move-ins/outs, works, audits
- Safer Asset Surveys, reducing risks in roof, and confined space
- Reduced travel expenses using remote viewing to reduce site visits
- Environmental impact reduced by reduction in on-site visits
- Improved Asset Management: Data-driven decisions, proactive maintenance
- Asbestos Management: Pinpoint locations, embed surveys
- Enhanced Lettings: High-quality virtual tours to streamline viewings
- Lifecycle Property Condition Tracking: Before/after assessments for move-ins/outs, works, audits
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 9 1 1 1 6 4 0 9 3 1 2 6 7 8
Contact
EXACTLY TECH LTD
Richard Libby
Telephone: 07376 782551
Email: info@exactly.tech
About the service
- Service categories
-
Applications
Content workflow and management
Content services
- Enterprise Content Management Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Housing management systems, asset management systems, property and facilities management systems, and customer or contractor portals. THEIA360 integrates with existing platforms via secure APIs and embedded views to extend them with virtual tours, visual inspections and digital twin capabilities.
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires a reliable internet connection for uploading and viewing virtual tours. Capture quality depends on the camera hardware used. Planned maintenance and updates are scheduled outside core UK business hours where possible and communicated in advance. Integration with third-party systems depends on their available interfaces.
- System requirements
-
- Modern web browser with JavaScript and WebGL enabled
- Reliable internet connection for uploading and viewing virtual tours
- User device capable of displaying high-resolution 360 imagery
- Supported 360-degree camera or image capture device
- Secure user authentication credentials provided by buyer
- Email access for notifications and account communications
- Buyer-managed endpoint security and antivirus controls
- Firewall rules allowing secure outbound HTTPS connections
- Optional API access for integration with third-party systems
- Administrative access for user and content management
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support requests submitted via email or our online ticketing are acknowledged within one business day.
Standard support is provided Monday to Friday, 9am–5pm UK time, excluding public holidays.
Weekend support is not included as standard but may be available by prior agreement. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support levels
Standard support (included)
Standard support is included with the service subscription. Support is provided via email or online ticketing during UK business hours (Monday to Friday, 9am–5pm, excluding public holidays). Requests are acknowledged within one business day. Standard support covers incident reporting, service usage queries, and general troubleshooting.
Enhanced support (optional, chargeable)
Enhanced support can be provided by prior agreement at an additional cost. This may include extended support hours, prioritised response times, and enhanced assistance during critical service periods such as go-live or major changes.
Onsite support (optional, chargeable)
Onsite support is available by prior agreement and charged separately. This may include implementation assistance, workshops, training, or on-site troubleshooting.
Cost of support levels
Standard support: included in the service price
Enhanced support: additional cost, priced on a time-and-materials or agreed support package basis
Onsite support: additional cost, charged at agreed day or hourly rates plus expenses where applicable
Technical account management
A dedicated technical account manager or cloud support engineer is not provided as standard.
Where required, a named technical contact or cloud support engineer can be made available as part of an enhanced or project-based support arrangement. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Exactly Tech supports buyers through onboarding with structured implementation planning, configuration and deployment within the buyer’s cloud tenant. Users are provided with online documentation, configuration guides and integration runbooks. Remote knowledge-transfer sessions and training are included, with optional onsite support available by agreement.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, buyers can request extraction of their service data in a commonly used, machine-readable format.
Data that can be extracted may include configuration data, journey and event data, and customer notification records, subject to data retention policies and contractual requirements.
Data extraction is coordinated by the supplier to ensure data integrity, security, and compliance with applicable data protection obligations.
Data is typically provided securely via electronic transfer within an agreed timeframe following contract termination.
After confirmation of successful data extraction, service access is removed and customer data is securely deleted in line with contractual terms and applicable retention policies. - End-of-contract process
-
At the end of the contract, service access is maintained until the agreed contract end date. Buyers may request extraction of their service data in a commonly used, machine-readable format within the agreed notice period.
Data extraction and secure handover are included in the contract price, subject to standard data volumes and formats.
Following confirmation that data extraction has been completed, service access is removed and customer data is securely deleted in line with contractual terms, data protection requirements, and applicable retention policies.
Standard contract close-out activities, including account deactivation and data deletion, are included in the contract price.
Additional services such as bespoke data extraction formats, extended data retention, support beyond the contract end date, or assistance with migration to alternative services may be provided at additional cost by prior agreement. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is accessible on mobile devices through a responsive, browser-based interface for capturing and viewing virtual tours on site. The desktop interface provides full administration, tour management, configuration, integrations and reporting capabilities. Mobile access prioritises usability and performance for on-site inspections and reviews.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- THEIA360 is accessed through a secure, browser-based web interface that allows users to capture, manage, view and share virtual tours. The interface supports role-based access, asset tagging and controlled sharing. Secure APIs and embedded views are available for integration with third-party systems.
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
- The service interface has been tested against WCAG 2.1 AA principles using automated accessibility testing tools and manual checks. Testing includes keyboard-only navigation, screen reader compatibility and colour contrast review. Accessibility feedback from users is incorporated into ongoing interface improvements.
- API
- Yes
- What users can and can't do using the API
- THEIA360 provides secure APIs that allow authorised users to upload, retrieve and associate virtual tour content with properties or assets, manage metadata and synchronise data with third-party systems. APIs support initial configuration and ongoing updates. User management, permissions and advanced configuration are managed through the web interface rather than the API. API availability depends on agreed integration scope and security controls.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Authorised administrators can customise branding, tour structures, metadata fields, asset tags, access permissions and sharing options using built-in configuration tools. Customisation is performed through the web interface without code changes. Additional configuration and integration support can be provided by the supplier under an agreed statement of work.
Scaling
- Independence of resources
- THEIA360 is delivered using a multi-tenant cloud architecture hosted within Exactly Tech’s Azure environment, with logical separation of customer data. Resources are monitored and scaled to manage demand, ensuring that usage by one organisation does not adversely impact the performance or availability of the service for other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides usage and operational metrics to help buyers understand how the service is being used. Metrics may include journey volumes, notification delivery status, customer engagement with tracking links, and basic service usage activity.
These metrics support operational monitoring, service optimisation, and reporting on customer communication effectiveness. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can export their data by submitting a request to the supplier via the support process.
Data is provided in a commonly used, machine-readable format, such as CSV or JSON, depending on the data type.
Exports are delivered securely via electronic transfer within an agreed timeframe.
Access controls and verification steps are applied to ensure data security and integrity. - Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is designed to be highly available and is hosted on resilient public cloud infrastructure. The supplier targets 99.9% service availability measured on a monthly basis, excluding scheduled maintenance.
Planned maintenance activities are scheduled where possible outside of UK business hours and customers are provided with advance notice.
Availability is monitored continuously and incidents affecting service availability are managed in line with the supplier’s incident management process.
Where guaranteed availability levels are not met, service credits may be applied in accordance with the agreed service level agreement. Service credits are calculated as a proportion of the affected service charges for the relevant period and are applied against future invoices.
Availability guarantees and any associated service credits are defined contractually and may vary depending on the support level and service configuration agreed with the buyer. - Approach to resilience
-
The service is designed to be resilient and is hosted on scalable public cloud infrastructure. It is deployed using redundant components and is monitored to support continued operation in the event of component or service failures.
The underlying datacentre infrastructure is provided by a third-party cloud provider and is designed for high availability and resilience, including redundant power, networking, and environmental controls. Datacentres are geographically separated within the hosting region to reduce the impact of localised failures.
Service performance and availability are continuously monitored, and automated alerting is used to identify and respond to incidents.
Backup and recovery processes are in place to support service continuity and data protection.
Detailed technical information regarding resilience architecture and recovery processes is available to buyers on request, subject to appropriate confidentiality arrangements. - Outage reporting
-
Service availability is continuously monitored and incidents affecting service availability are identified and managed through the supplier’s incident management process.
Where an outage or significant service disruption occurs, affected buyers are notified via email alerts providing information on the issue, its impact, and progress towards resolution. Updates are provided as appropriate until service is restored.
The service does not currently provide a public status dashboard or outage reporting API.
Following resolution, incident information may be shared with buyers on request, including a summary of the issue and actions taken to restore service and prevent recurrence.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted to authorised users through authenticated accounts with role-based access controls. Permissions are assigned based on job role and the principle of least privilege.
Administrative access is limited to approved personnel and protected using strong authentication, including multi-factor authentication where enabled.
Support channels are restricted to named customer contacts and authorised supplier staff. Requests are verified before action is taken to prevent unauthorised changes or disclosure of information.
User access is reviewed and updated as part of joiner, mover, and leaver processes. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
Security governance is overseen at board level, with overall responsibility assigned to a named director.
The organisation maintains documented security policies and procedures covering areas such as access control, data protection, incident management, and supplier assurance.
Security risks are assessed and managed as part of ongoing operational and project activities.
Third-party services are selected based on their security and compliance posture, and supplier assurance is reviewed as part of service delivery.
Security incidents are managed through a defined incident management process, with lessons learned incorporated into continuous improvement activities. - Information security policies and processes
-
Exactly Tech follows documented information security policies covering access control, data protection, incident management, change control and business continuity. Security responsibilities are defined and overseen by senior management, with day-to-day enforcement managed by nominated technical leads.
Policies are implemented through role-based access controls, secure configuration standards, least-privilege principles and audit logging. Compliance is monitored through regular reviews, staff awareness activities and technical controls within cloud environments. Security incidents are recorded, investigated and reported in line with agreed escalation and customer notification processes. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Service components are tracked throughout their lifecycle using documented configuration records and version control for configuration and integration artefacts.
Changes are managed through a defined change management process that includes assessment, approval, and testing prior to release.
Proposed changes are reviewed for potential security impact, including access control, data handling, and dependency considerations.
Changes are implemented in a controlled manner, with rollback procedures in place where appropriate.
Significant changes are communicated to customers where they may affect service operation or security. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Potential threats to the service are assessed through a combination of risk assessment, vulnerability scanning, and review of security advisories.
Vulnerabilities are prioritised based on severity, potential impact, and exploitability. Security patches and mitigations are deployed in a timely manner, with critical vulnerabilities addressed as a priority.
Information on emerging threats is obtained from trusted sources including cloud provider advisories, software vendor notifications, third-party security partners, and industry security bulletins.
Vulnerability remediation activities are tracked and reviewed to support continuous improvement of the service’s security posture. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Protective monitoring is used to identify potential security compromises through service monitoring, logging, and alerting. Indicators such as unusual access patterns, authentication failures, and service anomalies are reviewed to detect potential issues.
When a potential compromise is identified, incidents are investigated promptly in line with the incident management process, with actions taken to contain, remediate, and recover from the issue.
Security incidents are triaged and responded to without undue delay, with escalation to senior management where required and communication to affected customers as appropriate. - Incident management type
- Supplier-defined controls
- Incident management approach
-
The organisation operates a defined incident management process with pre-defined response procedures for common security and service events.
Users can report incidents via email or the online support ticketing system. Incidents are logged, triaged, and managed in line with severity and impact.
Where appropriate, affected customers are kept informed of progress during an incident.
Incident reports, including a summary of the issue, impact, and remedial actions, can be provided to buyers on request following incident resolution. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
- SOC 2 Type 2
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce