CAFM Explorer - Estates and Facilities Management
CAFM Explorer a scalable off the shelf SAAS solution, helps Facilities Managers manage: Helpdesks, Planned & Reactive Maintenance, Risk Assessments, Compliance, Asbestos, COSHH, Soft Services, Mobile Workforces, Service Providers, Property Portfolios, Leases, Asset Management, Stock Control, Purchasing, Document Cabinet, Projects, Customer Portal, Entity Booking, CAD Drawings, Space Planning, IWMS.
Features
- Enterprise solution: Functionality to manage facilities within one CAFM/IWMS system
- Maintenance: PPM planned maintenance, SFG20, Reactive Helpdesk and Compliance
- Asset Management: Full lifecycle management, cost planning, reporting, barcode scanning
- Automatic notification, monitoring and alerting of health and safety information
- Compliance Management: Monitoring, planning and scheduling of planning activities
- Mobile access with full visibility of risks, documentation, and history
- Dashboards: Monitoring works, key SLA reports, KPIs and full auditability
- Document Control: Expiry, notification and tracking of key documents
- Property Management: Lease, tenure, break tracking, notifications, and reminders
- Cost Control: Operation costs, budget assignment, stock control and forecasting
Benefits
- Fast ROI: Financial savings, extended asset life, reduced service downtime
- Improve decision making: Access to real-time information
- Increase efficiency: Streamlining of processes, better utilisation of resources
- Single source of truth: Central source for all information
- Reduce risk: Compliance monitoring, dynamic risk assessments, checklists, audit trail
- Maximise operational efficiency: Best utilisation of resources, scheduling, time management
- Manage contractors better: Traffic-light reporting, SLA Monitoring, Contract reminders
- Accurate Forecasting: Budget preparation based on full cost analysis
- Business Process Support: Solution driven by facilities professionals
- Mobile updates: Onsite job updates and end user portal
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 0 7 7 0 3 2 6 7 9 5 7 0 4 2
Contact
IDOX SOFTWARE LTD
Jen.roberts@idoxgroup.com
Telephone: 0333 011 1200
Email: bidteam@idoxgroup.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No
- System requirements
-
- Accessed from a web browser
- CAFM Explorer database engine is Microsoft SQL Server
- For smaller installations SQL Server Express can be used
- Values currently are: Exchange 2016, Exchange 2019, Office 36
- CAFM Web Offline website must be configured to use HTTPS.
- CAFM Web using Android and iOS supported web browsers
- ASP.NET and WCF enabled (32bit application pool for 64bit Windows)
User support
- Email or online ticketing support
- Yes
- Support response times
- The support desk is available Monday to Friday between the hours of 09:00 to 17:30, excluding weekends and Bank Holidays.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- The customer portal is accessible via a standard web-browser (e.g. Microsoft Edge, Chrome, Firefox and Safari 6.1.5 or above), therefore browser accessibility features may be utilised.
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
-
High priority issues such as a total system failure will be subject to a target response time of within 2 working hours of request being logged(*elapsedtime). The target resolution time is within 2 working days of request being logged(*elapsedtime).
Medium priority issues such as an important or critical component that has failed causing a partial failure will be subject to a target response time of within 4 working hours of request being logged(*elapsedtime). The target resolution time is within 5 business days of request being logged(*elapsedtime).
Low priority issues such as isolated faults that do not fall into the categories listed above will be subject to a target response time of within 4 working hours of request being logged(*elapsedtime). The target resolution time is within 90 business days of request being logged(*elapsedtime).
Enquiries will be subject to a target response time of within1 working day of request being logged(*elapsedtime) and will be resolved according to best of endeavours depending on the nature of the enquiry.
*Elapsed time refers to the duration of the request where it is with Idox Service Desk for action and does not include periods of time when the request is with the customer to action/respond. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- There are a number of training courses customised to client requirements based on the type of user. Full Administrator training is provided along with "train the trainer" courses. End users do not typically require training as the system is easy to use and video links and crib sheets are provided.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Every field within CAFM Explorer can accept imports of data and can export to Excel so the customer at all times has full control and access to all their data. There is also a SQL backup of the database and offsite licence of the software available if required.
- End-of-contract process
- CAFM Explorer allows every item of data to be exported into csv or Excel format. As such transfer to an alternative service provider is achievable at no additional cost.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- NA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
CAFM Explorer can be accessed from mobile devices using any standard web-browser. The administration module can be accessed via Remote Desktop.
The Web and mobile components of the solution support access and delivery on mobile devices, thus supporting remote and onsite working.
CAFM Web is a web-based Help Desk solution which enables your organisation to deliver support services to employees and customers through a central web-based Help Desk. It supports user helpdesk requests and contractor and engineer access. CAFM Mobile enhances the efficiency of a Maintenance Team by enabling Work-Orders to be issued to a Trades Person’s mobile device onsite. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service users access the service using a web browser.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Standard browser accessibility features
- Accessibility testing
- N/A
- API
- No
- Customisation available
- Yes
- Description of customisation
-
All reference data such as service levels, property codes and activity categories.
Web look and feel
Labels, wording and terminology
Reference data (such as group codes, SLAs, asset types, building categorisation)
Workflow – to reflect customer business processes and escalation procedures
Scaling
- Independence of resources
- The solution can be scaled to provide resilience by implementation of load balanced Application Servers and replication of Databases across multiple servers with failover where required.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data is encrypted at rest within the data centre and on any offsite data backups, using FIPS140-2 capable self-encrypting drives.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Via the admin user console
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- CAFM offers 98% availability per 30 day period.
- Approach to resilience
- All components of the system have redundancy built in to remove single failure points, and the application is horizontally scalable. We also use HA at the VM level where appropriate and SANs etc. We can provide more information on request.
- Outage reporting
- Outages are reported via the Idox Service Desk and where applicable the login page.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Management access is permitted only from internal networks, themselves requiring two factor authentication to access. Access control lists restrict access.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Idox recognises that information security important in the development and implementation of all systems delivered to its customers, to Idox as a corporate entity, and our supply chain.
To ensure a consistent and effective approach, Idox operates an externally audited and certified, organisation wide Information Security Management System(Security Management Plan) which implements and enforces controls on all business functions covering but not limited to:
information classification, storage, and transfer, network security,
secure software development, corporate and hosted commercial physical environments, incident/threat/vulnerability management and response,
regular corporate and hosted commercial system security testing and monitoring, project & contract management, access control,
personnel security & infosec training.
The system and controls are also externally verified and certified annually as part of the ISO 27001 certification process.
Risks raised through internal and external audits are reviewed at management meetings by the information security manager, the appropriate head of business and a board representative. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All changes to the service must go through a change management process which incorporates a business case/justification for the change, a backout plan, and a final approval with scheduling for the change to be implemented. Customers will be notified in advance of any service affecting changes outside of the prescribed maintenance windows.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Hosts scanned in real-time using deployed scanning agents. Networks scanned externally (weekly) using Qualys VMDR. Alerts of identified vulnerabilities are viewable by system administrators. Weekly aggregated reports are sent to system admins.
Web applications scanned monthly by Idox and during pre-release development phases using Qualys WAS Scanner and OWASP Zap.
System administrators evaluate, test and implement patching on an ongoing basis. Patches to live systems generally applied during pre-agreed maintenance windows after being confirmed safe for deployment in test environment.
Patches are classified by severity level, triaged and applied in accordance with the timeframe allocated to that severity level. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Monitoring tools are used to measure server performance metrics as well as storage and network/bandwidth utilisation and unusual server/network/perimeter activity. The alerts from these systems are actively monitored and reviewed and any potential intrusion attempt is raised in line with our security incident reporting procedure for further investigation.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Our incident management process is central to ISO27001 Information Security Management System(ISMS). In line with Incident Management Policy and Process, incidents are raised to the Service-desk or detected by monitoring such as SIEM, triaged and escalated as required. All tickets are allocated a reference-number and tracked to conclusion. Results are monitored, documented and preventative action taken to prevent re-occurrence. The incident team maintain contact with relevant internal and external stakeholders within predefined timeframes. For GDPR related incidents this is 24 hours from confirmation.
Security incidents raised to the internal incident register are subject to regular reviews by the senior team. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Monday 27 May 2024
- What the ISO/IEC 27001 doesn’t cover
- Our ISMS is certified and tested to ISO27001 standards annually and covers our entire organisation.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Thursday 11 April 2024
- What the ISO 9001 doesn’t cover
- Our ISMS is certified and tested to ISO9001standards annually and covers our entire organisation.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5c6de739-c45d-4eee-916a-013a0c2ce8f7
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 26018f8f-da19-4856-8fd2-b719e0c21047
- Other security certifications
- Yes
- Any other security certifications
- ISO 22301
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-