Driving Licence Checking
DriverCheck reports Driver Licence & Grey Fleet data electronically via Cloud Based Portal, ensuring your employees are eligible to drive and their vehicles are fully compliant. Our solution lets you check and validate driver licence credentials and makes sure they meet all the legal requirements to drive for your business
Features
- UK Electronic Driving Licence Checks
- Immediate Online Response
- Direct DVLA Data
- Grey Fleet Service and Management
- Foreign Licence Checking via DVLA
- Northern Ireland Licence Checking via DVA
- CPC & Tacho Data via DVLA
- Automated Check Frequency (to suit each business)
- ISO27001 Accredited
- Cyber Essentials Accredited
Benefits
- Attractive Modern System with great reporting and analytics
- Process checks in a secure and stable environment
- Fully Managed Service - on hand team to provide support
- Self Checking functionality
- Driver and Vehicle Type Allocation (for accurate reporting)
- 2FA and single sign on available
- 6 methods to gain driver permissions
- Customisation on rechecks
- Data Encryption - In transit and in rest
- System generated emails and notifications to highlight risks
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 0 0 4 1 6 8 1 4 1 5 0 8 1 1
Contact
DRIVERCHECK LTD
Yvette Giannini
Telephone: 0141 428 3448
Email: admin@mydrivercheck.co.uk
About your service
- Service categories
-
Applications
Supply chain management
- Logistics and transportation management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No
- System requirements
- No special system requirements
User support
- Email or online ticketing support
- Yes
- Support response times
-
Available in Support hours – Monday to Friday 8.30 to 17.00.
Calls answered during working hours by a dedicated team on hand to support, or pass to relevant person to action.
Emails / enquiries responded to within 12 hours.
Processing requests actioned within 24 hours.
Training Requests actioned within 5 working days.
Account support – actioned within 24 hours - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
We provide onsite training and account set up, if required.
All clients have a dedicated account manager, at no extra cost, to support them with any enquiries they may have.
We then have a central support team on hand to support clients every weekday. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
DriverCheck provides full training to all users (in person or by conference calls) An onboarding pack of documents is provided to each client (available via a web browser or to download as they require it).
We support all clients via a managed service, and are on hand to take clients on our onboarding journey to make the process as easy as possible. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of a clients contract, all data can be downloaded by the client in an excel format or DriverCheck can share this with the client via our data transfer application within our platform.
- End-of-contract process
-
At the end of the contract our clients have the ability to leave or renew their contract. There would be no additional fees.
Clients only pay for the licence checks that are carried out during the duration of their contact, there are no exit fees or onboarding fees. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding / offboarding documentation is shared via links or attachments in emails to clients and any data shared is done so via our fully secure and encrypted file transfer application within our platform.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- We offer a variety of options on API for our clients, depending on their needs. Our swagger supports clients with the set up and we have a dedicated team on hand to discuss unique requirements.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Each client account is set up depending on their specific requirements. Clients can customise frequencies of licence checks, customise each user set up and can also customise reports to suit their requirements.
Scaling
- Independence of resources
- Our service expands through our cloud infrastructure to unsure all clients receive the same level of service.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Metrics are delivered through our platform dashboards
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Licence Check - DAVIS
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- Data at rest is encrypted using Microsoft’s DEK (Database Encryption Key)process, utilising AES256 encryption).
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can only download / export data from the platform if they have user permission to do so.
The platform offers a large suite of reports available to customise before export in excel format. - Data export formats
- Other
- Other data export formats
-
- Excel
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The following is offered under DriverCheck's SLA:
Platform core hours – Monday to Friday 8.00 to 19.00.
Platform supported hours – Monday to Friday 8.30 to 17.00
Support hours – Monday to Friday 8.30 to 17.00
There is no charge to the client if DriverCheck do not deliver the service to them. - Approach to resilience
- Available on request
- Outage reporting
- When the platform has an outage, messaging is displayed on the web browser / within the users login page.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- When setting up a client account, we review each user access, the levels they require and the email notifications they should / should not receive.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
DriverCheck Ltd – is registered with the ICO (Information Commissioners Office) our data protection number is Z9074119.
DriverCheck Ltd – is ISO27001 certified via BSI, as part of Ebbon Group (parent company)
We have a group Compliance team and follow weekly reporting, monthly reviews, and continuous improvement via Risk Assessments and internal audits.
Cyber Essentials Certified. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our product management team work with a team of developers to continually support and implement new features, function and tools, where required. Change is managed via a sprint based planning schedule with risk scoring, priority planning and pre release testing in UAT and staging environments.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- DriverCheck is committed to review its cryptographic infrastructure on an ongoing basis. DriverCheck has other forms of security checks in place such as penetration testing, non-destructive tests, intrusion detection, protection against DDoS attacks, internal audits, an annual network vulnerability assessment plus an annual web application vulnerability assessment.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We adhere to our Secure Authentication Policy, and Password Management Procedure, the Secure Authentication Policy is available on request.
2FA and SSO are available on request. Password resets are sent every 3 months.
Resets for users, must be verified by main users or a full reset request must be verified at director level. - Incident management type
- Supplier-defined controls
- Incident management approach
- This is defined, in line with ICO, we can provide documentation to support, if required.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Following a demonstration, a testing account can be created for the client along with dummy data for them to test. Regular check-ins then take place between DriverCheck and the client until they are ready to switch to live.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 20%
- Between £1,000,001 and £2,500,000
- 30%
- Between £2,500,001 and £5,000,000
- 30%
- Over £5,000,001
- 40%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Sunday 15 October 2023
- What the ISO/IEC 27001 doesn’t cover
- -
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Fb6c86c7-81a0-4043-a34e-43637b04eddb
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-