Skip to main content

Help us improve the Digital Marketplace - send your feedback

CSS EUROPE LIMITED

Pro-Cloud Bluelight

Pro-Cloud Bluelight is a cloud-based operational platform tailored for Fire, Rescue and Police services. It provides real-time asset, equipment, and evidence management, automates maintenance, inventory, and workflows, and ensures compliance and traceability across locations. It enhances situational awareness, reduces manual tasks, and improves readiness and decision-making for emergency response teams.

Features

  • Real-time asset and equipment tracking across operational locations.
  • Mobile access for field updates and incident record management.
  • Automated maintenance scheduling with compliance alerts.
  • Evidence and asset chain-of-custody tracking.
  • Inventory management with real-time stock visibility.
  • Secure cloud-based access with role-based permissions.
  • Audit trails and reporting for regulatory compliance.
  • Integration with barcode, RFID, and QR scanning.
  • Incident readiness reporting and operational dashboards.

Benefits

  • Access operational data remotely to support frontline decision-making.
  • Reduce administrative effort by automating asset and equipment tracking.
  • Improve readiness through real-time visibility of critical equipment.
  • Maintain compliance with automated audits and traceable records.
  • Speed up incident preparation with accurate asset availability information.
  • Coordinate teams effectively using shared, up-to-date operational data.
  • Minimise equipment downtime with proactive maintenance alerts.
  • Simplify inspections by digitising checks and evidence records.
  • Improve accountability through secure chain-of-custody tracking.
  • Enhance operational efficiency by centralising systems and workflows.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at emma.strain@csseurope.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 8 5 8 6 2 6 2 1 6 2 5 9 0 5

Contact

CSS EUROPE LIMITED Emma Strain
Telephone: 08448794531
Email: emma.strain@csseurope.co.uk

About your service

Service categories

Applications

Supply chain management

  • Supply chain planning
  • Warehousing and inventory management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Not applicable.
System requirements
Access to the internet.

User support

Email or online ticketing support
Yes
Support response times
First response within 10 minutes.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We offer three support levels: Basic, Standard, and Premium.

Basic Support is included in the subscription and provides up to 10 incidents per month, one named contact, access to online self-help resources, and helpdesk case submission during Monday–Friday business hours, with an initial response time of 1–3 business days.

Standard Support is available at an additional cost (pricing on request). It includes unlimited incidents, two named contacts, next business day response times, telephone technical setup support, remote assistance, configuration setup support, enterprise setup support, and support for custom web services and third-party integrations during Monday–Friday business hours.

Premium Support pricing is detailed in the pricing documentation. It includes unlimited incidents, six named contacts, extended support hours (7 days, 7am–8pm GMT), a four-hour response time, priority case handling, Power BI report assistance, webinars and telephone consultations, logical and physical platform separation, and technical support for third-party hosted solutions. Premium Support includes a dedicated Technical Account Manager.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We support users in starting to use our service through a structured, phased onboarding and training approach designed to ensure confident adoption and long-term success. From the outset, customers are provided with a comprehensive Project Pack, which outlines the full implementation journey, key milestones, roles, responsibilities, and what to expect at each stage. This is introduced during a formal project handover and kick-off meeting, ensuring alignment and clarity before delivery begins.

Training is delivered during a dedicated Training and User Acceptance Testing phase and is tailored to user roles. We provide both digital and, where required, onsite training sessions. Designated “Champions” or super users receive in-depth training first, enabling them to support and train wider teams internally. This approach helps embed best practices and builds internal capability across the organisation.

Users also gain access to a “Learn” environment, allowing them to practice real-world scenarios in a safe test system before go-live. Comprehensive user documentation, including user guides and workflow instructions, is provided to support day-to-day use and reinforce learning.

Following go-live, users benefit from ongoing support, including access to a dedicated helpdesk and a structured handover to business-as-usual support, ensuring continued confidence, stability, and effective use of the service.
Service documentation
Yes
Documentation formats
Other
Other documentation formats
Online
End-of-contract data extraction
At the end of the contract, users are supported through a structured and controlled data extraction process to ensure continuity and data ownership. Upon request, we work with the customer to agree the scope, format, and timing of the data extract. This typically includes all relevant system data such as asset records, stock information, user data, audit history, and reports.

Data is exported in commonly used, open formats (such as CSV or Excel) to ensure it can be easily accessed, reviewed, and imported into alternative systems if required. Where appropriate, supporting documentation is provided to explain data structures and field definitions, helping users interpret the extracted data accurately.

The extraction process is carried out in line with data protection and security requirements to ensure confidentiality and integrity throughout. Once the data has been successfully transferred and confirmed by the customer, system access is decommissioned in line with contractual and data retention policies.

If required, professional services support can be provided to assist with more complex data extraction requirements or transition planning, ensuring a smooth and controlled exit from the service.
End-of-contract process
At the end of the contract, the service is formally closed in a structured and controlled manner to ensure continuity, transparency, and data ownership. Users may request a data extract of their system information, including assets, stock, audit history, and related records. Where data is extracted using the standard system templates and in the same format in which it was originally imported, this extraction is included within the contract at no additional cost.

If users require data to be extracted in a different format, mapped to bespoke structures, or tailored for migration into another system, this is considered a custom data extract. Custom extraction requests may involve additional data transformation, validation, or consultancy effort and are therefore chargeable.

Once data extraction has been completed and confirmed, system access is decommissioned in line with contractual terms and data protection requirements. Any retained data is handled according to agreed retention and deletion policies.

The contract price includes standard system access for the agreed term, user documentation, and the ability to export data via standard templates. Additional costs only apply where users request non-standard, customised data outputs or enhanced transition support beyond the standard offboarding process.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
No difference.
Service interface
No
User support accessibility
WCAG 2.2 AAA
API
Yes
What users can and can't do using the API
Multiple API options.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Pro-Cloud Bluelight has multiple flags within the contract settings allowing users to customize the software to their contract.

Scaling

Independence of resources
We guarantee independence of resources through a fully scalable architecture designed to ensure consistent performance for all users, regardless of overall demand. The systems are built to scale both vertically and horizontally, allowing capacity to be increased as usage grows or during peak periods. Continuous monitoring tools track key resource metrics such as CPU, memory, and storage, with automated alerts to CSS IT and hosting provider teams when thresholds are approached. This enables proactive capacity management and timely scaling, ensuring that increased demand from one user does not negatively impact the performance or experience of other users.

Analytics

Service usage metrics
Yes
Metrics types
We provide service metrics through our online ticketing system and regular service reporting. All support requests are logged, tracked, and managed within the ticketing system, allowing us to monitor volumes, priorities, response times, resolution times, and escalation activity. These metrics are used to measure performance against agreed service levels and identify trends or recurring issues. Monthly account reports are automatically sent to customers, providing visibility of support activity, service performance, and any key observations or improvement actions. This approach ensures transparency, accountability, and continuous improvement in the delivery of our support services.
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data using built-in reporting and business intelligence (BI) tools within the service. These tools allow users to generate reports across key data areas, apply filters, and tailor outputs to their operational needs. Reports can be exported in commonly used formats such as CSV or Excel, enabling easy analysis, sharing, or archiving of data outside the system. This self-service capability ensures users retain access to their information throughout the contract, supports data ownership.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee a high level of service availability for our online services, underpinned by a formal Service Level Agreement (SLA). We commit to 99.9% availability for our core services, including Pro-Cloud™, TCES Community™, TCES Connections™, TCES Configurator™, and Pro-Cloud Bluelight™ solutions. In addition, we guarantee 99.9% availability for Power BI Embedded, enabling users to reliably execute API calls and access embedded reports.

Availability is measured on a monthly basis using a clearly defined uptime calculation, excluding planned and scheduled maintenance. Downtime is recorded only where a service is unavailable for fifteen consecutive minutes or more.

If we fail to meet the guaranteed availability levels in any applicable monthly period, customers may be eligible for service credits. Where monthly uptime falls below 99.9%, a 10% credit of the applicable monthly service fees may be applied. If availability falls below 99%, the service credit increases to 25%. Service credits are applied to future invoices following validation of a claim submitted within the defined timescales.

Service credits are the sole remedy for availability failures and are capped at the value of the affected monthly service fees. This SLA provides transparency, accountability, and assurance that service availability is actively monitored and managed.
Approach to resilience
Available on request.
Outage reporting
Our service reports outages through a combination of public visibility and direct customer communication. We provide a publicly accessible status page and dashboard, available via a dedicated URL, which displays current service availability and historical uptime information. This allows customers and stakeholders to independently check service status at any time.

In the event of a service outage or service degradation, customers are proactively informed through in-application notifications and email alerts. These updates provide clear information on the nature of the issue, its impact, and progress towards resolution. Once service is restored, follow-up communications are issued to confirm resolution and provide reassurance

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
SSO.
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is strictly controlled to protect our services. Full administrative and management interfaces are restricted to authorised CSS staff only and protected using role-based access control, least-privilege principles, and multi-factor authentication. Access is approved, logged, and reviewed regularly.

CSS staff and customers access services through limited interfaces that provide only the functionality required for their role. These interfaces prevent access to underlying management systems and sensitive configurations. Support channels, including the ticketing system, are restricted to authorised users, with role-based permissions and audit logging in place to monitor access and detect unauthorised activity.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
SSO

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
We operate a formal Information Security Management System (ISMS aligned with ISO/IEC 27001 and Cyber Essentials Plus, ensuring the confidentiality, integrity, and availability of information.

Our policies include an overarching Information Security Policy supported by policies for risk management, access control, acceptable use, asset management, incident management, supplier security, business continuity, and data protection. All policies are approved by senior management, reviewed at least annually, and updated to reflect changes in risk, technology, or regulation.

Key processes include regular risk assessments and treatment, role-based access control with least-privilege principles, multi-factor authentication, vulnerability management, patching, and security monitoring. We maintain defined incident response procedures covering detection, reporting, investigation, escalation, and lessons learned. Third-party suppliers are assessed for security risks and managed through contractual controls.

Overall accountability for information security rests with senior management. Day-to-day responsibility for implementing and maintaining the ISMS is assigned to a designated Information Security Lead, who reports regularly on risks, incidents, audit findings, and compliance.

Compliance with policies is ensured through mandatory staff training, ongoing security awareness, technical controls, internal audits, and management reviews. Non-compliance is addressed through corrective actions, supporting continual improvement of our security posture.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We maintain formal configuration and change management processes aligned with ISO/IEC 27001.
All service components, including infrastructure, applications, and endpoints, are recorded in a controlled asset and configuration register. Each component has an assigned owner and is tracked throughout its lifecycle from deployment to secure decommissioning. Secure configuration baselines are defined and maintained.

All changes are managed through a documented change process. Proposed changes are logged, assessed&approved by the Information Security Panel before implementation. Each change includes an assessment of potential security impact, including access controls, data protection, availability, and compliance. Post implementation reviews confirm effectiveness and update configuration records.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We operate a formal vulnerability management process to protect the confidentiality, integrity, and availability of our services. Potential threats are assessed through regular risk reviews, vendor security advisories, and scheduled vulnerability scanning using Nessus credentialled patch audits conducted every two weeks. Results are reviewed by the CSS IT team and tracked to remediation.

Security patches are deployed based on risk classification.Critical and High within 14 days, Medium within 21 days, and Low within 28 days. Patches are tested prior to deployment, Microsoft patches applied to development before production. Threat intelligence is obtained from vendors, security bulletins, and vulnerability scan outputs.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We operate a structured protective monitoring process to identify and respond to security threats promptly. System, application, and security logs are collected centrally and monitored 24/7 by a dedicated Security Operations Centre using SIEM technology and threat intelligence feeds. Monitoring identifies potential compromises such as suspicious logins, privilege escalation, malware activity, and anomalous network traffic.

If a potential compromise is detected, alerts are immediately raised to the CSS for investigation and containment. Incidents are triaged, escalated where required, and managed in line with our incident response procedures. Security incidents are reviewed without delay, with response initiated immediately upon detection.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We operate a formal incident management process with pre-defined procedures for common events, as outlined in our SLA documentation. These procedures cover incident identification, classification, escalation, communication, and resolution.

Users report incidents through our dedicated ticketing system or via a dedicated support telephone line. All incidents are logged, prioritised, and tracked through to resolution by CSS.
We maintain structured internal and external reporting processes. For infrastructure outages or major incidents, incident reports and status updates are communicated to affected parties by email. Post-incident reviews are conducted where appropriate to capture lessons learned and support continual service improvement.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
1%
Between £1,000,001 and £2,500,000
1%
Between £2,500,001 and £5,000,000
1%
Over £5,000,001
1%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Monday 30 September 2024
What the ISO/IEC 27001 doesn’t cover
NA
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Saturday 30 August 2025
What the ISO 9001 doesn’t cover
NA
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
91395cee-140c-4683-a295-e14eaff9a00a
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
66a8320e-6186-48fb-899e-313d273798ec
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at emma.strain@csseurope.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.