Skip to main content

Help us improve the Digital Marketplace - send your feedback

QROUTES LIMITED

QPaths

QPaths is a tool that helps local authorities quickly assess eligibility for home to school transport based on safe walking routes, catchment areas, and closest appropriate schools. QPaths is particularly useful for Eligibility Officers and can cut down on manual processing and provide consistent, auditable results that support efficient decision-making.

Features

  • Fast, automated calculation of walking routes & distances
  • Multi-route and distance calculation in batch mode
  • Accurate and up-to-date calculations using Ordnance Survey maps
  • Mark path and road segments as unsuitable for walking
  • Map-based interface showing calculated routes
  • Ability to set configuration of multiple destinations, e.g., school gates
  • View any point on a route using Google Street View
  • Address validation using Ordnance Survey's AddressBase
  • Automated catchment and closest school checks
  • Ability to allow parents/guardians to self-serve an immediate eligibility indication

Benefits

  • Delivers highly accurate walking distance assessments
  • Produces consistent results, supporting appeals handling and clear audit trails
  • Stores and digitises paths and roads deemed unsafe for walking
  • Significantly reduces manual processing time through efficient bulk processing
  • Improves eligibility accuracy, reducing unnecessary transport provision and associated costs
  • Supports fair assessments by reflecting realistic school access points (gates)
  • Combines both distance and catchment area checks, simplifying decision-making
  • Provides evidence to support business cases for infrastructure improvements
  • Reduces response times to parent and stakeholder queries and appeals
  • Supports automated online applications using an API

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at david.stewart@qroutes.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 0 4 1 0 4 7 0 5 0 1 2 4 4 0

Contact

QROUTES LIMITED David Stewart
Telephone: 0117 3329499
Email: david.stewart@qroutes.co.uk

About your service

Service categories

Applications

Supply chain management

  • Logistics and transportation management
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Hybrid cloud
Service constraints
QPaths must be accessed through an up-to-date web browser (Chrome, Edge, Firefox or Safari).
System requirements
  • An up-to-date web browser (Chrome, Edge, Firefox or Safari)
  • A program to view and edit CSV files (e.g. Excel)

User support

Email or online ticketing support
Yes
Support response times
The user can contact support via the in-application help. Tickets can also be raised by email to support@qroutes.co.uk.

QRoutes will reply to all emails and tickets within 1 business day.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
QRoutes is proud of its close working relationship with customers. The subscription price includes example processing of the customer's data, tailored training for all users, and unlimited online support.

Each customer has access to a Customer Success Manager and a Training and Support Manager.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Training is typically provided online (although onsite can be arranged) using the customer's own data, wherever possible. QPaths is a relatively straightforward product and most users find it intuitive and easy to use. It also has user documentation built into the application.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
The application does not retain any customer data with respect to walking route or other eligibility calculations. The customer uploads their data, processes it and downloads the output.

The application stores establishment (school) information which can be downloaded as a CSV file. Path and road segments which have been marked as unsuitable for walking can also be downloaded at any time in a CSV or GeoJSON file.

The application also stores any catchment area polygons uploaded by the customer. These can be exported in a standard format at any time.
End-of-contract process
The customer simply decides whether to re-subscribe or not. There is no tie-in of any sort.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
QPaths provides a GIS-based user interface through a web browser. There is a map view with the user able to control what is shown with respect to the students whose transport eligibility is being assessed.

There is also an API interface to support an online application workflow where data on transport eligibility and/or safe walking distances between home and various schools is returned automatically.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
QRoutes commissioned an accessibility audit of QPaths. The interface was tested by visually impaired, blind, colour-blind, and deaf users.

The testers used assistive technology, including screen readers (JAWS, NVDA, Dragon) and a zoom tool (ZoomText), and navigated QPaths using only a keyboard.

The testers carried out a live session with the QRoutes team, including developers and product managers, to demonstrate their experiences, and produced a written report of recommendations that QRoutes is using in the development of new and existing features.
API
Yes
What users can and can't do using the API
Customers first create a log-in account on the web interface. They can then use those same authentication details to begin a session via the API. The core batch calculation of safe walking route distances between home and school for multiple students is provided, alongside additional functionality previously requested by customers.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Customers can manage and maintain their list of schools / educational establishments along with associated attributes such as phase of education, age range, and the gate locations.

Users can also mark segments of paths or roads as unsuitable for walking. Subsequent safe walking route calculations and associated transport eligibility assessments will not use these unsuitable sections.

Road or path segments marked as unsuitable for walking are set at the account level, i.e. they affect the processing of all users, including API calls, where relevant.

Scaling

Independence of resources
QPaths has a scalable hosting architecture, whereby processing is sent to a single server but additional server resource is available for the potentially extensive back-end computations. Customer processing requests are allocated to free resource, meaning no one customer's usage affects another. The servers are used exclusively by QRoutes applications.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users download their processed data directly from the application as CSV files.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
QRoutes aims to provide 99.5% monthly uptime, excluding scheduled maintenance and force majeure events. Uptime is defined as the percentage of total minutes in a calendar month during which the service is available and functioning as intended.

Scheduled maintenance will be performed either a) between 10:00 pm and 02:00 am UK time, or b) between 08:00 pm and 08:00 am UK time provided that QRoutes has used reasonable endeavours to provide users notice of such at least one business day in advance.

Customers are eligible for service credits if the monthly uptime falls below the committed levels: 5% of the monthly fee if the uptime is still above 98.5%, or 10% of the monthly fee if the uptime falls below 98.5%.
Approach to resilience
QRoutes' services are hosted by iomart (https://www.iomart.com) or Microsoft Azure (https://azure.microsoft.com). Each application is backed up to isolated locations and has two permanently available dedicated disaster recovery environments, both in separate geographical locations to the production environment.
Outage reporting
QRoutes notifies its users of any scheduled service downtime (outside the 10:00 pm to 02:00 am maintenance window) via the relevant application's log-in page.

When an outage or service disruption is expected to last longer than 15 minutes, an email (including the expected time of the return of services) is sent to users. QRoutes will email users again once the service is restored, providing detail on the cause of the outage.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to user accounts is controlled by username and password. Customers can configure the password policy for their users and choose whether to mandate the use of multi-factor authentication (MFA).

There are two levels of customer user: Standard and Administrator. The latter can control account configuration settings, including user access, as well as view audit history logs of account usage. MFA can be mandated for customer Administrator accounts independently of Standard accounts.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
QRoutes maintains a structured security governance framework that combines policy, oversight, and continuous assurance.

All of its potential production environments undergo annual independent penetration testing, and least-privilege principles are enforced through Just Enough Access to restrict internal access to sensitive systems.

Staff receive role-specific security training and are vetted to BS7858:2019 standards. Governance activities are supported by documented processes, regular reviews, and clear accountability, to ensure risks are identified, monitored, and managed effectively across the organisation.
Information security policies and processes
QRoutes consistently reviews its approach to data protection and cyber security, notably through the agenda in its weekly operations meeting. Best practice is captured and disseminated across the company through internal communication and/or dedicated meetings, and the company provides data protection and cyber security awareness training for all its staff at least annually. The company maintains documentation detailing how its approach meets the National Cyber Security Centre's Cloud Security Principles.

The CEO is also the company's Data Protection Officer and ensures that any data or security concerns are raised with other directors in a timescale befitting their severity.

QRoutes also operates software which automically alerts staff of potential service delivery problems and/or vulnerability concerns.

QRoutes' services are hosted by iomart (https://www.iomart.com) or Microsoft Azure (https://azure.microsoft.com). The former is accredited for ISO standards 9001, 27001, 22301, and 50001, the latter for ISO standards 27001, 27017, 27018, and 27701, and Cyber Essentials Plus in the UK.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Customer change requests are logged in the company's support site, and their resolution tracked alongside other tickets in the Jira product management software.

All software changes are triple tested manually for functionality, usability, and performance. QRoutes also maintains an automated test capability, which includes functional, regression, performance, stress, and security tests. All releases must pass automated regression and security tests in a staging environment prior to release, and then again in the production environment afterwards.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
QRoutes scans for vulnerability issues in both its deployment and development environments.

For deployment, it uses a leading third party service to monitor the vulnerability of its production, disaster recovery, staging, and test environments. QRoutes staff are notified of potential issues daily, and establish their severity and immediacy within 1 business day. Critical vulnerabilities are patched within 24 hours, others in a timescale befitting the assessment.

For development, an OWASP checker is run automatically following source code builds. It identifies potential security vulnerabilities within the code itself and highlights when any third-party libraries become outdated.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
QRoutes' protective monitoring processing includes third party penetration testing, data centre security, customer account monitoring, and the proactive patching of its servers and/or software as described in vulnerability management.

The firewalls in QRoutes' data centres provide protection against unauthorised network access, malware and exploit attacks, application-layer attacks, and Distributed Denial of Service (DDoS) attacks.

QRoutes operational staff also monitor account log-in attempts and usage for abnormal activity on a daily basis.
Incident management type
Supplier-defined controls
Incident management approach
QRoutes has pre-defined processes for handling all common IT system incident types, covering service availability, performance, and, as described above, security.

Availability is provided through the maintenance of two disaster recovery servers, both in separate geographical locations to its production server. Service performance adheres to the company's published Service Level Agreement.

Any incidents concerning data protection are logged separately. The Data Protection Officer determines what follow-on actions may be necessary in each case.

QRoutes reviews incidents at its weekly operations meeting, escalating the visibility of more serious incidents to the monthly board meeting.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
UK local authorities responsible for assessing home to school transport eligibility can access a restricted service free of charge for a two week trial period. Other organisations should contact info@qroutes.co.uk to determine if there is a free trial option.

Trials are restricted to 5 establishments (schools).

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0.0%
Between £250,000 and £500,000
1.0%
Between £500,001 and £1,000,000
2.0%
Between £1,000,001 and £2,500,000
3.0%
Between £2,500,001 and £5,000,000
4.0%
Over £5,000,001
5.0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at david.stewart@qroutes.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.