Metastreet - Private Housing Regulation Cloud Software and Inspector App
Private rented housing software, including case management, property licensing (Mandatory, Additional & Selective), hazard assessment (HHSRS) & Inspector App. Developed by sector experts.
Features
- Developed by sector experts - expert project support included
- Fully customisable - client branding & Gov.uk guidelines
- Security - single sign-on & two factor authentication
- Fully compliant - meets legal requirements out of the box
- Specialised mobile inspection app (hazards) with cloud integration
- Cloud based team management and workflow
- Integrated payment gateway & self service reports
- Open APIs & no exit fees
- Print, email, portal and direct post solution
- Full case management and hazard assessment (HHSRS)
Benefits
- Expert design and stand alone - limited integrations
- Drive up service efficiency and reduce administration costs
- Productivity boost - smart workflows & validation
- Designed by practitioners - experienced in delivering PRS services
- Mobile working - cloud based via any internet connected device
- Inspector App - integration to reduce officer data entry
- Open APIs & no exit fees
- Secure by design, 2FA, encrypted document storage, audit logs
- Auto scaling AWS architecture to support peaks in traffic
- Full payment integration (Stripe and Capita Pay
Pricing
£12,000.00 an instance a year
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 13
Service ID
7 0 5 7 8 7 8 5 0 2 1 5 2 3 3
Contact
Metastreet Ltd
Team Metastreet
Telephone: 02089383768
Email: team@metastreet.co.uk
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No
- System requirements
-
- Modern web browsers
- Smart phone for two factor authentication
- Each user needs unique e-mail address
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
Provide e-mail and on line support 9a.m to 5p.m Monday to Fridays. (except bank holidays) Response times set out in our service standards.
We also use Freshchat live chat support for clients 9a.m to 5p.m Monday to Friday (except bank holidays) - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 AA or EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Web chat
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.1 AA or EN 301 549
- Web chat accessibility testing
- Provided by third party
- Onsite support
- Yes, at extra cost
- Support levels
-
Technical account manager support
Support package can be tailored to clients requirements - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Training will be available online
User documentation available through the 'help centre'
Support line available
Training videos
A training/test system will be set up and available throughout the life of the contract - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- We will assist in the migration of data to the buyer or a new supplier as detailed in the agreed exit plan. This will be in a structured JSON format.
- End-of-contract process
- Obligations as required by the agreed exit plan and contract are included in the price of the contract.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Menu structure
- Service interface
- No
- User support accessibility
- WCAG 2.1 AAA
- API
- Yes
- What users can and can't do using the API
- No limitations
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
A wide range of elements are configurable on set up, including branding - e.g logo, favicon, accent colour; fee levels; licence conditions, notices and letters; bespoke additional conditions system e-mails; split payments (part B payment);
Configuration of application form - required documentation; public register configuration; message on payment screen .
Scaling
- Independence of resources
- Auto scaling infrastructure and a queue based messaging pipeline to stop blocking requests
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Applications submitted
Applications processed
Payment
Third party analytics (e.g Google analytics) - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Physical access control, complying with SSAE-16 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
- Can be provided on request
- Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
- Dtf 7.3
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- 99%
- Approach to resilience
- This is available on request
- Outage reporting
-
E-mail alerts
Public dashboard
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- We implement a role based access control list and have a policy using principle of least privilege
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- 2-factor authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- QMS
- ISO/IEC 27001 accreditation date
- 15/05/2022
- What the ISO/IEC 27001 doesn’t cover
- All software services covered
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Hacker Guardian
- PCI DSS accreditation date
- 22/02/2022
- What the PCI DSS doesn’t cover
- None
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- All software development and products are done to OWASP guidelines
- Information security policies and processes
- Full details are available on request
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Any new feature before it goes into development has a security impact assessment .Before any functional major release there is a regression test and a external penetration test before release.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We follow industry news bulletins for potential threats. Dependant on relevance and severity we provide patches within 48 hours. All threats are risk assessed and triaged
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We employ a range of AWS security tools which monitors any unauthorised access to production environments.
Our system administrators investigate immediately on being alerted with the relevant business and tech stakeholders - Incident management type
- Supplier-defined controls
- Incident management approach
- We have a pre-defined incident report process and all clients are notified by e-mail of the incident and our response and kept updated
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Fighting climate change
-
Fighting climate change
We recognise the urgent need to address greenhouse gas emissions because of the role they play in climate change.
We are committed to keeping our environmental footprint to a minimum. As Metastreet grows and develops we hope to achieve net zero business emissions .
Through our technology investments, Metastreet supports local authorities (customers) to help address poor energy performance of in the private rented sector. - Covid-19 recovery
-
Covid-19 recovery
Our technology investments have enabled our customers to stay productive throughout the pandemic.
Our services are now helping post pandemic recovery through productivity innovations in the public sector.
We are creating employment, re-training and other return to work opportunities for those left unemployed by COVID-19. - Tackling economic inequality
-
Tackling economic inequality
Our mission is to support Local Authorities in achieving their ambitions to protect tenants, drive up standards in the private rented sector and reduce economic inequality in part driven by poor management in parts of the rented sector.
We are also creating employment and training opportunities, particularly for people in
industries with known skills shortages or in high growth sectors. - Equal opportunity
-
Equal opportunity
Metastreet is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
We support in-work progression to help people, including those from disadvantaged or minority groups, to move into higher paid work by developing new skills. - Wellbeing
-
Wellbeing
We aim to create a healthy and safe workplace where our people can be themselves and feel and perform at their best. This means enabling our people to prioritise their health, safety, and wellbeing.
Through our digital innovation we seek to support suppliers, customers and communities to help build strong, fair and integrated communities.
Pricing
- Price
- £12,000.00 an instance a year
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We have a sandbox site which potential customers can access and test.