Connected Safety Net (CSN) Capture – Safety, Facilities & Operations Management
Connected Safety Net is a secure SaaS platform using connected AI to manage safety, compliance and operational processes. Government organisations digitise audits, incidents, training, contractor controls, assets and documentation, with AI supporting monitoring, automation and proactive risk management across departments. New for 2026: Secure Document Repository and Auto Scheduling software.
Features
- Configurable digital forms aligned to organisational workflows
- Guided workflows standardise reporting and approvals
- Mobile and web access for field and office teams
- Capture photos, videos, files and speech-to-text evidence
- Centralised document repository with version control and permissions
- Connected AI automates monitoring, task assignment and escalation
- Automated scheduling for audits, inspections and operational activities
- Dashboards, analytics and Power BI integration
- Automatic GPS capture improves report accuracy and traceability
- QR code and URL access for rapid form completion
Benefits
- Standardises safety and compliance processes organisation-wide
- Improves data quality through guided digital workflows
- Reduces administrative effort using connected AI automation
- Increases accountability through clear ownership and deadlines
- Maintains complete audit trails for governance and assurance
- Enables fast frontline reporting via intuitive mobile tools
- Improves accuracy using location data and evidence capture
- Centralises documents with controlled access and version management
- Proactively manages risk through AI-driven scheduling
- Provides real-time insight through dashboards and reporting
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 3 1 0 5 9 0 6 3 7 0 6 9 4 3
Contact
CONNECTED SAFETY NET LIMITED
Paul Richardson
Telephone: 07850111561
Email: info@connectedsafetynet.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Adult Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
While our products offer robust functionalities, it's important to note some constraints. These may include planned maintenance arrangements to ensure system integrity and security.
The application must also be deployed on the Azure cloud environment. - System requirements
-
- Hosting: Microsoft Azure Cloud
- IOS or Android (Mobile app)
- Modern web browser (Web portal)
User support
- Email or online ticketing support
- Yes
- Support response times
- For live clients, we respond to questions within 2 hours on business days (Monday–Friday). Response times may be slightly longer over weekends and public holidays. 24/7 support is also available if required, at an agreed additional cost.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- EN 301 549
- Web chat accessibility testing
- We have tested our web chat functionality with assistive technologies, including screen readers and keyboard-only navigation, to ensure full accessibility. Testing confirms that all chat elements, notifications, and input fields are correctly announced, operable, and usable by users with disabilities, meeting EN 301 549 accessibility standards
- Onsite support
- Yes, at extra cost
- Support levels
-
On receiving a support request through email or a support-ticket on the support portal, the support coordinator will take following immediate actions:
• Creation of ticket in our support tool if a call received or any other scenario if the ticket has not been created, with relevant information, documents, priority and support level.
We provide 3 support levels:
Level-I
No code change is required. Eg, password reset.
Level-II
Code changes or server configuration required. Eg. Crashes and sever performance issue.
Level-III
Cross functional knowledge and coordination is required along with programming skills. The ticket type Incidents comes under this level if they are not resolved by the level II support. Service Requests with all urgencies/priorities come under this level. All these tickets are managed by mainstream teams in their regular releases.
All levels are included with our default service support package.
We provide both an account manager and a named support engineer for all our customers as the main contact. - Support available to third parties
- No
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Client onboarding is a critical process for CSN to ensure that new clients have a smooth and successful transition into using our software.
CSN follows this client onboarding process:
1. Introduction and Welcome
2. Gather Information
3. Training and Education
4. Customization and Configuration
5. Data Migration (if applicable)
6. Testing and Feedback
7. Go-Live
8. Client Support
9. Follow-Up and Review
10. Documentation and Resources
11. Account Management
By following these steps, CSN ensures a successful onboarding experience for our clients, setting them up for long-term satisfaction and success with our software and services. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Clients can request the data extraction, and we extract the data for them. Clients also have the ability to use the reporting feature in the desktop version to extract the data themselves without assistance.
- End-of-contract process
-
This is the default procedure that we would follow at the end of a contract (if it's not renewed):
1) All the data is extracted, sent and removed.
2) All of the users are removed from our systems.
3) We ensure that all customisations and assets are removed as per client request.
4) Any files held in our storage are deleted.
However (at the client request), we can hold onto any data that they would want us to hold temporarily e.g. 12 months. - Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Most features are common across both mobile and web, though there are some that are exclusive to web.
Specifically, there are enhanced functionalities on the web, the most important ones are: Reports Exports, User access and administration, Site/Incident administration, Data Import. - Service interface
- No
- User support accessibility
- WCAG 2.2 A
- API
- Yes
- What users can and can't do using the API
-
In order to use the API, CSN will provide API keys for integration.
Users are able to use the API to perform any action the Web/Mobile UI is capable of doing. This includes creating and managing all incidents as well as exporting and importing data from/to the system.
There are no limitations from the API, as long as the user performing the actions/connections have the right roles/permissions. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
White labelling of both the mobile and web applications are applicable out of the box, as well as the ability to customise the forms and workflows, including what fields are to be captured.
These can be set up through the web portal.
We will generally customise these together with the customer to ensure they are suitable, however, the customer can also customise some elements themselves.
We also offer custom development work if there are extra features and connections that are needed.
Scaling
- Independence of resources
- Our service is hosted on a secure, multi-tenant cloud infrastructure with dedicated resource allocation for each client. We use automated load balancing, horizontally scalable compute and storage resources, and performance monitoring to ensure that activity from one user or organisation does not affect the performance or availability experienced by others.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Our service provides metrics on user activity, module and workflow usage, task completion rates, action tracking, document and resource usage, and overall operational performance. These metrics enable organisations to monitor adoption, compliance, and efficiency.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data at rest is encrypted using industry-standard encryption. Physical access to storage media is tightly controlled, and our data centres comply with ISO 27001, CSA CCM, and other recognised security standards.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users are able to export data through the web portal. They can choose the format (Excel, CSV or PDF) of the output as well as other filters and parameters regarding the data. Example filters include, date range, sites and locations, status of the incidents.
While the data can be used on any platform the user wishes, we also have in-house expertise to support Power BI reports and is included in our service. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
We have a 99.99% uptime guarantee (excluding scheduled maintenance).
Our incident categories and response times are:
P1 | response: 2 hours | resolution: 24 hours
P2 | response: 24 hours | resolution: 48 hours
P3 | response: 48 hours | resolution: 1 week
P4 | response: 48 hours | resolution: 4 weeks
Response times are only valid during business hours (9am to 5pm, Monday to Friday).
We can also offer an enhanced 24/7 support package at additional cost. - Approach to resilience
-
The CSN infrastructure is highly resilient and all components are n+1 (redundancy).
● The front end is hosted on a CDN fronted elastic storage.
● The backend service cluster are all containerised and deployed on application services in n+1 configurations. The backend is also behind a load balancer, and will auto-scale with traffic.
● All databases backup and restore procedures are being used, and an additional replica instance have been created.
● The entire server stack is regularly chaos tested to ensure that every component is resilient to unexpected outage without affecting uptime. - Outage reporting
- We report service outages via email alerts. Our support desk will also be in direct contact with customers if it is a serious outage.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
All our systems are password and MFA protected. The system also has the concept of users being affiliated to one or more sites. A user can only use the permissions their role provides for sites to which they have been affiliated. Sites that a user is not affiliated to are completely hidden from them. We also support Single Sign-On.
The system has a three-tier approval workflow that can be configured for each site. Approvers can be chosen from a list of active users that are affiliated with the site and can have any role assigned to them. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Our organisation maintains a comprehensive Information Security Management System (ISMS) certified to ISO/IEC 27001, covering policies, procedures, and controls for people, processes, and technology. Core policies include information security, data protection, access control, incident management, and secure software development. All policies are reviewed regularly and updated to reflect regulatory and industry best practices.
Responsibility for information security sits with our Director Data Protection, supported by a dedicated IT and Security team. Security roles and responsibilities are clearly defined, and staff are trained on relevant policies during onboarding and through regular refresher training. Compliance with policies is monitored via internal audits, automated system checks, and reporting dashboards. Security incidents, policy breaches, or non-compliance are reported through a formal escalation process to senior management, with remediation tracked to closure.
All systems, including web and mobile applications, are deployed with security controls embedded in workflows. Regular penetration testing, vulnerability scanning, and access reviews ensure policies are effectively applied in practice, and findings are used to continuously improve controls. This approach ensures consistent adherence to information security standards and government best practices for secure cloud services. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
We follow the Agile methodology and following the SCRUM framework for our Software Development Processes. We are following a pure SCRUM approach to tackle Configuration and Change Management:
Clear Definition of Done (DoD)
Continuous Integration and Continuous Deployment (CI/CD)
Version Control
Sprint Planning
Change Control Board (CCB)
Regular Retrospectives
Documentation
Collaboration and Communication
Risk Management
By incorporating these practices into the Agile Scrum process, teams can effectively manage configuration and change, ensuring that the project remains adaptable and responsive to evolving requirements and priorities. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Regular penetration testing of the application and the infrastructure is a key part of CSN’s security approach. This testing is targeted to be conducted at least annually and will also be planned in (on an ad-hoc basis) following a major development release.
The testing identifies vulnerabilities of the system to the latest threats and gives the development team the guidance on where to focus security improvement activities. Generally, High and Medium level vulnerabilities will be addressed as soon as possible with a fix and release.
The latest penetration test was conducted by Crowe Advisory Services. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
We identify potential compromises by regularly doing internal security tests. These regular tests are done with accordance to web standards such as OWASP (top 10).
Potential compromises are treated with the highest priority and are dealt with as immediate hotfixes. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Support scripts are followed for the most common incidents.
Users report incidents via the standard support channels (email, phone, web chat).
The support team is then responsible for managing post production customer support. The support team uses a support portal (Jira) to manage the life cycle of support tickets.
Case Types
Ticket Status
Ticket Priority/Urgency
Support Level-I
Support Level-II
Support Level-III
We provide incidents reports from our support portal on demand. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
Week 1 discovery to help design your service.
Week 2 configure your digital solution specific to your needs.
Week 3-6 free pilot to enable the organisation procuring the service to test and demonstrate the value proposition and business case.
Week 7 the service will be chargeable assuming the company approves. - Link to free trial
- Www.connectedsafetynet.co.uk
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 20%
- Between £1,000,001 and £2,500,000
- 30%
- Between £2,500,001 and £5,000,000
- 40%
- Over £5,000,001
- 50%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- SMG (UKAS-accredited)
- ISO/IEC 27001 accreditation date
- Tuesday 10 September 2024
- What the ISO/IEC 27001 doesn’t cover
- Our ISO/IEC 27001 certification covers all in-scope information assets and processes according to internationally recognized best practices. Areas outside the defined scope, such as third-party services or locations not included in the ISMS, are managed under separate controls and agreements as needed.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B13dfd64-dc18-4cc5-8bfb-a3d1607b9601
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- ISO/IEC 27001 (Information Security Management)
- ISO/IEC 27701:2019 (Privacy Information Management System)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-