CentraOs
CentraOS is designed to unify the voice, video, and safety systems
organisations already rely on for daily operations and emergencies. Rather than replacing existing investments, it allows those systems to interoperate and provide users with a single, concise view of events significantly enhancing situational awareness across the organisation.
Features
- Real time instant comms 1-1, or 1-many
- GPS Locations, location based alerting (Geo-Fencing)
- Lone Worker Protection, event base alarm triggers and SOS button
- Open architecture to allow 3rd party system integrations
- Intelligent information routing to ensure correct information to correct people
- Cloud based storage, to replay media for event review
- Real time reporting
Benefits
- Instant real time information delivered to the right people anywhere
- Accurate location information for fast response in any situation
- Protecting your lone worker without the need for user interaction
- Integrations ensure accurate information utilising all systems available delivered concisely
- chronologically delivered information from multiple systems ensures easily understandable info
- Accessible anywhere information from secure cloud
- Reports give clear visibility of system use
- Predefine incident response logic
- Automatic triggering of incident response logic (scheduled or event)
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 1 6 7 5 1 8 7 0 2 4 0 9 7 0
Contact
RADIOCOMS SYSTEMS LIMITED
Mark Blythe
Telephone: 0333 939 0022
Email: bids@radiocoms.co.uk
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Any operational platform with an available restful API.
- Cloud deployment model
- Public cloud
- Service constraints
- Service is designed to be always available, we guarantee 4 x 9's with a target on a yearly basis is 5x9's availability to cover any unforeseen events. Customers should be aware that while the service is designed as always available, it does require connection to the internet therefore a SIM card, WiFi or ethernet connection will be required and this can mean service interruption should any of this internet connection fail. We operate on smart devices which also carry the threat of finger trouble severing connection, we use MDM to help guard against this.
- System requirements
-
- Client Apps Android level 6 and above
- Client Apps iOS level 16 and above
- PC interfaces are browser based - all common browsers supported
User support
- Email or online ticketing support
- Yes
- Support response times
-
Platform support 24x7x365.
Customer support for critical incidents responses are within 4 hours for Non Critical within 1 working day. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Cloud platform service subscriptions include business hours support for service, connectivity and device (if supplied by us). Out of hours support attracts a premium on the platform service subscription.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We offer QS guides and full training, we also have how 2 videos for quick reference if required.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- All data produced by our platforms is retained for a defined period and available for download/archive in that period. End-of-Contract data extraction makes use of the same capability.
- End-of-contract process
- Services cease in line with contract terms. Ample opportunity is available for customers to download and archive any relevant data produced by our platforms. Depending on contract terms, there may be a requirement to return devices and MNO SIMs.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- PDF reader.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Mobile is app based and desktop is browser based, desktop service has more features available and is more of a management tool.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Service (admin) interfaces are browser based and offer tenant admins the opportunity to create/edit user and channel settings and incident service logic.
- Accessibility standards
- None or don’t know
- Description of accessibility
- User mobile devices are tactile with easily accessible PTT,SOS and Channel change keys. TTS and screen based messaging can be enabled to allow accessible navigation of the client communications device.
- Accessibility testing
- None at this stage.
- API
- Yes
- What users can and can't do using the API
- A key aspect of our CentraOS product suite is to allow platforms to be integrated more easily and to simplify the logic that can be deployed by customers themselves to automate incident responses across their full set of deployed technology - the only prerequisite is the the technology platforms we provide support for have their own API that we can capture in a task library and make available to customers on our integration platform. We also have our own integration platform API for customers to use for event based triggers.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Customers can create and deploy their own incident service logic involving all their deployed technology (with an API). E.g. if a fire alarm panel or building entry system detects an event, this can be communicated to the customer's service logic and trigger messages to the security team indicating the location of the incident. The security team can respond as required. Event logs allow incident reports to be generated.
Services are created on our platform by the user using our service editor. Services consist of a series of tasks with task configuration also created by the user. Services, once created can be run and will automatically respond to the defined trigger event.
Service customisation is done via Customer administrator logins. Customer user logins can start/stop services and generate reports.
Scaling
- Independence of resources
- All platforms are multi-tenanted and fully scalable to meet demand as required.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Parallel incident service flow count and platform output transactions per second per transaction type (HTTPS, SMTP, SMS etc.).
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Synchio.com and MNO/MVNO connectivity
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Browser based download and archive.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- MP3
- MPW
- .txt
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Guarantee of 4 x 9's availability with aim for 5 9's. Service is designed to be always available.
- Approach to resilience
- Data Centres are with well established accredited providers in the UK with highly effective physical security measures. Data in encrypted in flight and properly sanitised when no longer required. Data storage is in multiple locations and backed up. Service architectures employ current containerised techniques and container management to provide resilience.
- Outage reporting
- We run a CAN (customer advice notice) service for planned maintenance, a 3 step notification. For unplanned outage we provide a full RCA (route cause analysis) that we send via e-mail upon full incident review. We can communicate platform issues via common alerting channels.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Admin and user roles on our various platforms restrict the logged in member of staff to permissions associated with their role.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Our information security policy and processes align with standards including ISO/IEC 27001 , Cyber Essentials Plus and legal requirements such as the UK GDPR and Data Protection Act 2018.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We deploy changes to our cloud platforms and client applications using an approach based on Customer Advice Notes (CANs). We typically use a 3 CAN approach to changes with a high level advanced notice (CAN #1), followed by a detailed notice prior to the change (CAN#2) and a follow up CAN summarising what has happened (CAN#3). In this way customers are made fully aware of what we are doing, why we are doing it and what steps they should take before and after the change to get the most from the change.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We monitor publicly available sources for threats and vulnerabilities and proactively review our code base for any exposure. We also run reflective practice to review any incidents that may occur which impact our services. Both may result in a change to our approach and a require a new release/version to parts of our solutions. Such releases/versions can be deployed in days. Our containerised software architecture generally ensures that such changes only occur at the periphery of our solutions.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- See answer to previous question.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We will always collect data during and after an incident and use it to establish a time line of events to record what happens. Inputs to this process can be many and varied and may come from multiple sources e.g platform alerts, customer reports, supplier notices, staff etc.. Once the incident has been recovered we will run reflective practice to establish ways in which we can improve and then build those improvements into our solutions and procedures. Root Cause Analysis reports and corrective actions that result can be shared with customers.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We will work with customers on trials, depending on the scale, time and hardware involved in the trial as to whether a charge will be required, this is not normal practice in our experience, we can prove the solution without the need for a paid trial or proof of concept.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12.5%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Tuesday 22 June 2021
- What the ISO/IEC 27001 doesn’t cover
- All parts of the service delivered inline with ISO27001 framework
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Thursday 19 October 2023
- What the ISO 9001 doesn’t cover
- All parts of the service delivered within ISO9001 framework
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- D7385fa3-3423-4b0f-b9c5-692eb3dd6f57
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 6820291E-427D-4454-B148-039CFE710A9F
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-