Homelessness, Housing Register, Housing Management, Private Sector and Renters’ Rights
LocataPro, modern configurable platform of modules for the Social Housing Sector comprising:
Social Housing Register and Allocations (Choice-Based Lettings or Direct-Lettings),
Homelessness Reduction, Homelessness Prevention Case Management & Homelessness Academy.
Temporary Accommodation Management, Rent Accounting and Arrears Management,
Support Referrals Gateway,
Housing Management,
Private Sector Housing and Renters' Rights Act
Features
- Integrated modules covering the various functions of Social housing
- User configurable communication templates, workflows, Personal Housing Plans
- Housing Client Portal - self-service referrals and keeping information current
- Single login and consistent design, creates consistent user experience
- Housing Management with rent arrears alerts, tracking, success reporting, monitoring
- Preconfigured report templates alongside custom report builder reporting on live
- Make notes, record communications, store unlimited documents, audit actions
- Legislatively Compliant (e.g. Homelessness Reduction Act), with integrated statutory reporting
- Meet Renters' Rights Act obligations with Private Sector Housing Module
- Detailed Knowledge Base Access, Community of Users and Support Site
Benefits
- Cross-module information sharing and reduced work duplication between services!
- Value for Money, Easy system configuration with no setup costs!
- Client self-service tasks and referrals saves time, reducing administrative burdens
- User-friendly, intuitive platform, easy training, quick on-boarding and simpler implementation
- Utilise latest features with system improvements included, without additional costs
- Simple KPI monitoring, need identification, easily respond to demand prioritisation
- Easily manage documents, no storage costs, simple case history auditing
- Statutory compliant processes, faster statutory reporting compliance (e.g H-CLIC)
- Prevent unauthorised access to sensitive information, control system configuration
- Cross-organisational collaboration, easily onboard users and access detailed training resources
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 3 0 2 7 3 8 2 9 2 9 1 9 9 6
Contact
LOCATA (HOUSING SERVICES) LIMITED
Meg Riley
Telephone: 01895 637595
Email: enquiries@locata.org.uk
About your service
- Service categories
-
Applications
Content workflow and management
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Maintenance is performed during times that will cause the least disruption to users, usually around midnight. Should site-specific maintenance be required, which could cause service disruption, we would only perform this with consent and agreement from the client.
Software is web-based so a modern, standards-compliant web browser (Chrome, Edge, Safari) and an internet connection are required.
All subscription fees include access to the software on an unlimited user basis. - System requirements
-
- Internet Access
- Modern, standards-compliant web browser (Chrome, Edge, iOS mobile safari)
- Proxy servers must not cache the LocataPro domain
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support is available via phone or email, Monday to Friday 9am - 5pm, excluding national bank holidays.
Support issues can be logged 24/7 by email, via the backoffice and via the support site, where users can also track the progress of their tickets. Tickets are prioritised and responded to in-line with the Service Level Agreements published below.
•Critical issues: Senior Technical Consultant assigned within 1 working hour, resolution within 1 working day
•For all other categories of support tickets: 99% of issues will be resolved within 5 working days but the average resolution time is less than 2 working days. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
When a fault is logged with our Support team, it is categorised on the following basis.
Critical - System is unavailable.
High - Critical functionality is unavailable.
Medium - Non-critical functionality is unavailable.
Low - Minor errors and cosmetic issues.
We aim to respond to and resolve faults in timescales relating to their priority, explained below:
Critical issues – Senior Technical Consultant assigned within 1 working hour, resolution within 1 working day.
For all other categories of support tickets, 99% of issues will be resolved within 5 working days and that the average resolution time is less than 2 working days.
In some scenarios, fixes for Medium and Low priority faults may be deployed with the next scheduled release. This will be clearly communicated and explained via the Support Site / ticket communication. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Onboarding is broken down into the below stages:
1. Scoping: Locata consult with you to define which modules and bolt-ons are required to fully satisfy service requirements.
2. Deployment: we setup/provide a fully functional live site based on our out the box solution. We will also perform Super User Training here, so you can configure the system to meet your exact requirements.
3. Configuration: Using the available functionality within the applicable modules, the system is configured to local requirements. This can be performed by Local Super Users with the relevant permissions using the powerful no code system functionality, or Locata can configure the system on your behalf as part of implementation consultancy.
4. Training and Go-Live: We provide end-user training and can also provide train-the-trainer training. During any training we also signpost to our detailed Helpsite articles which include videos and supplementary content to assist with learning to use all system functionality. Training can be via Microsoft Teams or on-site, with on-site being our recommended approach.
5. Business as Usual: We provide you with a dedicated Account Manager to assist you with day-to-day enquiries and to ensure you utilise our products to their fullest extent, maximising value for money - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Microsoft Word
- Microsoft Excel
- End-of-contract data extraction
-
For the entirety of the contract until the Expiry Date or End Date users are able to access and download data held on the system via our Reporting tools and GDPR functionality. If clients have the data warehouse bolt-on users can extract data from the data warehouse via ODBC or ADO.
If you require an alternative solution to the above, we are happy to discuss your requirements and this will be priced according to the Pricing document Rate Card. We recommend that if you have alternative requirements, you communicate them to us at least 3 months prior to your intended termination date, so we can ensure data is available for testing prior to termination of your contract.
We will destroy all copies of your data when we receive written instructions to do so or 30 days after the End or Expiry Date. Written confirmation will be provided to you that the data has been destroyed. - End-of-contract process
-
If you would like to opt to cease using our services, we will begin the off-boarding process, following the Data Exit Plan agreed as part of your initial Call-Off Contract. On an agreed date and time, access to back-office and public sites will be disabled and amendments to data will no longer be possible. For the entirety of the contract you will be able to access and download any data held on the system by utilising the core reporting functionality of LocataPro. Data can be downloaded for each record individually too.
Following termination of service, all copies of your data will be securely destroyed upon your written instruction or 30 days after the contract end date, whichever is sooner. Written confirmation will be provided of the data’s destruction.
Should you require us to provide data in bulk or to host your data after the expiry end date additional charges may apply dependent on your requirement. This will be priced as per the Pricing document Rate Card where extra costs are to be defined. We recommend that you put any requirements in writing at least 90 days prior to the end date of your contract. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- All public-facing sites offer the same experience on mobile and desktop. LocataPro uses responsive design so pages look great on any device or screen size, ensuring customers enjoy seamless access via mobiles, tablets, laptops, and desktops. With over 96% of interactions online and 85% through mobile or tablet, we’ve adopted a Mobile-First strategy. Back-office sites require a minimum screen resolution for some pages that display large amounts of data e.g. reports.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The web-based user interface allows both the back office and the client portal to access the system. The back office enables council’s staff and partner organizations achieve all actions using the same easy to use responsive platform. Moving between modules and screens is extremely easy and user friendly. System configuration is also done via the back office using the intuitive no code set up screens.
A programmatic interface is exposed via our API.
Additionally, our system supports import and export interfaces that enable bulk interactions via batch file that can be uploaded to our SFTP site. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
The back office and client portal are tested using Siteimprove and Axe accessibility testing tools to ensure that the meet public sector bodies accessibility requirements.
Public facing forms strictly adhere to the GOV.UK Design System (GDS) styling thus piggy backing off the research and experience of other service teams. By utilizing GDS styling it ensures customers are familiar with our forms because they are consistent with other government forms. - API
- Yes
- What users can and can't do using the API
-
LocataPro’s API provides a set of RESTful web services that allow you to access and manipulate data in your LocataPro modules. You can find these web services at [your LocataPro system url]/api.
To use these web services, you need to send and receive data in JSON format, and authenticate your web requests with JSON Web Tokens (JWT). You also need to use https for all your calls.
The API offers a wide range of functionality, which you can request in detail. Some of the things you can do with the API are:
- Search for properties, clients, cases, people and bids
- Create properties, clients, cases, people and bids
- Read and write journals
- View and edit data for properties, clients, cases, people and bids - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Various elements are available for users with the applicable permissions to customise. Permissions can be controlled at a granular level, allowing for specific parts of the system to be adjusted by those users most appropriate without granting full "admin" controls.
Functionality available to customise on all modules includes:
- Workflows, Tasks and Questions, Completion rules
- Communications Templates
- Standard User Roles / Templates
- Journal Categories
- Applicant "Flags" (e.g. 2-person visit)
Additional functionality can be customised, which is module specific, some examples of which are given below:
- Providers and Services (HRS)
- Plans including but not exclusive to Personal Housing Plans, Support Plans (HPA2)
- Patches (Lettings and Estates)
- Schedule of Rates (PSH)
- Other Case types (Estates and HPA2)
- Rent Arrears Rules (Estates and TARA)
Also Users with appropriate permissions can initiate these customisations, ensuring that adjustments align with their operational needs. This approach promotes flexibility and efficiency, allowing Users to tailor the system to their specific requirements without compromising system integrity or security. By empowering Users to customise elements within their scope, the system facilitates seamless adaptation to evolving organisational processes and preferences.
Scaling
- Independence of resources
- Each client has their own dedicated database hosted in our Microsoft Azure subscription. We use Microsoft Azure cloud computing services for all of our infrastructure, which allows us to easily and quickly scale up our system. Our architecture has been designed in such a way that resources can be scaled up without interruption to the service. We use load balancers to monitor traffic and server availability. If a server fails, traffic is automatically redirected to a healthy server. Traffic is dynamically directed to the server with the most capacity.
Analytics
- Service usage metrics
- Yes
- Metrics types
- All service issues are logged on the support site which is monitored by our dedicated UK based support team. At all times the support team includes a senior support consultant, and dedicated triage officer who accesses issues within 2 hours and determines the appropriate next steps for resolution. We have real-time dashboards reporting on issues logged, issue severity and issue age. Over the past 12 months we have had an uptime of 99.99% there were 3157 tickets logged from 153 different organisations. The average resolution time for all tickets was 1.58 days. Reporting on issue statistics is available to clients.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
The primary operational data extraction process is via our reporting tools. The majority of the data held within the system is accessible via our in built reporting tools. This can be output to csv and so subsequently ingested by other systems.
At an additional cost, charged as per the Pricing Document Rate Card, we can provide an Azure SQL database as a Data Warehouse that can be connected to via ADO or ODBC and used by other systems to perform an ETL process.
Documents can be downloaded via the GDPR functionality. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- HTML
- XML
- ZIP
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- .xlsx
- .bak
- .bacpac
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
We utilise Microsoft Azure's scalability infrastructure and deployment slots to ensure a high level of availability. We warrant to 99.8% uptime, and aim to ensure it is higher than this. In order to achieve these performance levels, the data centres are monitored 24/7 and the operators alert us to any issues immediately.
In terms of systems availability, if we do not meet our warranted values above (99.8% availability), we offer to refund a multiplied pro rata rate of 1.5 times for the downtime listed above, up to a maximum of the annual subscription fee, per year.
Thus, for the avoidance of doubt and as an example, if a Client is paying £10,000 per annum and the system was down for one day over and above the tolerances defined, we would refund 1.5 x £10,000/365 up to a max of £10,000. - Approach to resilience
-
Our solutions run on virtual machines that run Microsoft SQL server configured in an always on availability groups. The virtual machines are in an Azure availability set ensuring that they are on different fault domains which ensures that they don’t have a common power source and network switch. The virtual machine disk are stored in locally redundant storage replicated between both of Microsoft Azures’ UK South and UK West datacentres.
Full database backups are made weekly, with daily differential backups and transaction log backups taken every 15 minutes. This means that if all servers in a SQL server availability group fail we can do a point in time recovery with a maximin of 15mins of lost data.
The web servers are in availability sets of at least 2 servers each, so if a server fails or maintenance on a server is required, the load will be automatically switched to the other server in the set. So patches can be applied during office hours and zero day exploit patches can be applied as soon as Microsoft has the patch available. - Outage reporting
- In the event of outages, we ensure transparent communication and uninterrupted access to support. Our Support Site operates on separate infrastructure from public and back-office systems, allowing users to log tickets even during disruptions. Each client website and back-office system includes a public dashboard for real-time status updates. We can also display banner messages on the Support Site to inform users of known issues. As an added safeguard, our business websites are hosted independently and act as a fail-safe. Critical information is shared via email alerts, ensuring delivery regardless of system status. Additionally, users have access to community forums hosted on a third-party platform, unaffected by outages, where we proactively post known issues and updates. This multi-layered approach prioritizes transparency, accessibility, and reliability, keeping users informed and supported during challenging circumstances.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Other
- Other user authentication
-
Azure Role Based Access Control (RBAC) is used to control which members of staff have access to the azure subscription, and then which services and environments within that.
Access is strictly on a need-to-access basis, and restricted to senior staff with no access by default - Access restrictions in management interfaces and support channels
- Users are authenticated via their Microsoft Entra ID user account with enforced MFA.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Other
- Description of management access authentication
- Users are authenticated via their Microsoft Entra ID user account with enforced MFA. Access is restricted to users that are on the dedicated VPN. The VPN is only installed in dedicated devices used by staff who require access. This is strictly controlled.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Our processes and procedures promote a proactive approach to security in line with the ISO27001 standard. Regular reviews, internal and external audits ensure our policies and procedures are being correctly followed and our sites offer the highest standards of security.
Full training is provided to team members in current Data Protection legislation and the specific impact on us as an organisation and our customers. This includes for example how we handle Subject Access Requests and how to support our own client base in completing documents such as Data Protection Impact Assessments (DPIA). We can provide further information including our full processes and procedures should you require this. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Our Change Management process ensures all changes are assessed, planned, documented, with full audit trail maintained. Change is evaluated via ISO-27001 standards to mitigate potential security risks.
We use Git for source-code-control, providing complete version-history and traceability. All code-changes undergo a pull request process, including senior developer review, followed by automated/manual testing. GitHub Advanced Security scans code, any identified issues are promptly resolved. Access to code repository is controlled/limited to authorized personnel.
Deployment permissions to live are restricted to small group of senior-staff.
To prevent unauthorised changes, we monitor/closely control access to development environments. Only authorised/appropriately trained/experienced staff have access. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Our processes are designed to adhere to ISO27001, including regular reviews, risk assessments, and audits. Independent CHEST/CREST accredited consultants conduct penetration tests regularly, and any vulnerabilities are addressed immediately. Code changes are scanned for risks using GitHub Advanced Security. We encourage clients to perform additional penetration testing and respond promptly to findings. Security researchers can contact us via published channels for vulnerability reporting, and we take appropriate action. Servers are hosted in Microsoft Azure availability sets, enabling patches without service disruption. This multi-layered approach ensures robust security and continuous protection.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our protective monitoring combines multiple layers of defence. Microsoft runs threat analytics on all VMs, detecting suspicious activity and sending real-time alerts for rapid response. Servers have Sophos ransomware detection software that monitors file changes and enables rollback if needed. Public sites are protected by a web application firewall (OWASP 3.2) and Microsoft malicious bot detection. We monitor failed login attempts and block IPs after five failures. SSL configurations are regularly analysed using Qualys SSL Labs.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We have a defined incident Incident management process in place focusing on any possible security incidents. Any incident with security implications reported either by clients or technical staff is immediately escalated to senior management level to conduct a detailed threat assessment. Customers are informed of the issues, processes and procedures at all stages. Our security incident management approach has been developed with the aid of external data protection specialist consultants and is regularly reviewed.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Fcfcd526-a501-4e71-8c5a-6cb4bd60e1ed
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- C95fde2f-d2ea-45d1-9ede-162d61338401
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-