NotLost - TfL's lost and found property management platform
NotLost transforms lost and found management into a fast and simple process for businesses. Utilise powerful AI to free up valuable staff time and return more items of lost property. Deliver an excellent customer experience and recoup the costs of managing lost property with integrated courier and payment services.
Features
- Image recognition software for quickly registering found items
- Powerful searching when handling customer enquiries
- AI Matching engine compares lost and found reports automatically
- Self-checkout for customers to select return options and make payment
- Integrated postage system for easy returns
- Detailed reporting dashboard
- Customisable fields, branding and outbound customer emails
- Configurable workflow rules for automating repeat tasks
- Real-time visibility across multiple access points and centralised enquiry management
- Digital receipt and audit trail for all items and users
Benefits
- Deliver memorable moments for your customers
- Reduce time spent managing lost and found by 50-80%
- Recoup costs and generate additional revenue
- Reduce team stress by implementing a consistent, simple process
- Generate positive customer feedback and reviews
- Establish best practices in lost and found management
- Respond to internal audits and external regulations
- Active development team provide weekly product updates
- Simple, intuitive design with training videos and guides
- UK based team provide support when you need it
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 5 2 2 2 8 9 6 4 1 9 7 2 4 9
Contact
NotLost
Sam Nash
Telephone: 02080373970
Email: sam@notlost.com
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Contact centre
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No constraints. Stand alone application that can also integrate with CRMs, Data analytics, Active Directories etc. Updates are commonly applied without any downtime to end users. NotLost will notify users of any planned outages.
- System requirements
-
- Internet connection
- Internet Browser - Chrome, Edge, Firefox, Safari
User support
- Email or online ticketing support
- Yes
- Support response times
- One working day, Monday - Friday
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We use Drift integrated Chat. Any queries are direct to the NotLost team
- Onsite support
- Yes, at extra cost
- Support levels
- NotLost provides an account manager who is accessible via phone, email or video call 9 am - 5 pm weekdays. The account managers work closely with our product team so can also provide technical support.
- Support available to third parties
- No
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Training videos and user guides are embedded in the "helphub" in the platform.
Online 'screen sharing' training / webinars provided as part of onboarding.
For larger teams, training days and bespoke materials can be organised.
We have multiple clients that have required deploying our software to thousands of users at hundreds of locations. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Defined Exit Strategy Policy that provides the client with a complete export of their data in standard CSV format, structured so it can be imported into any replacement system. We continue to operate the service during the agreed exit period and cooperate with the new provider to ensure a controlled, secure transition with no data loss or degradation of service, and without imposing technical or commercial barriers to migration.
- End-of-contract process
- All item reports can be provided as a CSV file. Service provided at no extra cost.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The same functionality is provided in the platform regardless of device. The platform has been designed with mobile in mind.
When taking photos or uploading images the experience is slightly different on a mobile or tablet, as PC's /laptops do not all have cameras. - Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
Clients can use our APIs to integrate our functionality with third party software such as CRM, Data analytics tools, to send push notifications, to retrieve customer specific information from their internal systems etc.
As a cloud native SaaS provide we can create custom endpoints to deliver novel integrations. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Account profile, roles/access and storage locations can be customised by administrators.
System allows for multiple configurable fields for data capture for both item registration and customer enquiry.
Outbound email content and customer-facing web enquiry form are also configurable.
NotLost's development team can support 'customisations' and integrations.
Scaling
- Independence of resources
- Verticle scaling of AWS servers. Additional resources are deployed automatically. We also continuously monitor our servers, API gateways and endpoints.
Analytics
- Service usage metrics
- Yes
- Metrics types
- All reported item data
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- In platform dashboard. For custom reports, users can schedule an export via their account manager
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
NotLost is delivered as a fully managed SaaS platform with high-availability architecture on AWS. Our standard SLA commits to at least 99.5% monthly service availability, measured across each calendar month and excluding agreed maintenance windows and events outside our reasonable control. Availability covers access to the core application and APIs.
Performance and availability are monitored 24/7. If we fail to meet the committed availability level, customers are entitled to service credits applied to subsequent invoices. Credits are calculated on a tiered basis according to the level of breach and duration of unplanned downtime, and can be supplemented by an agreed remediation plan for larger contracts. - Approach to resilience
-
NotLost servers are hosted in the EU, currently with Amazon Web Services.
Amazon’s data centres operate in alignment with the Tier III+ guidelines.
AWS will use commercially reasonable efforts to make Amazon EC2 and Amazon EBS each available with a Monthly Uptime Percentage of at least 99.99% - Outage reporting
-
Outages are reported to NotLost via email alerts.
also see live status page status.notlost.com
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Interfaces and support channels Each user is individually identified, authenticated and all actions audited. Role Based Access control is managed by administrators and users' access can be disabled, roles changed, or access revoked.
Access to the database is not permitted, even to management or account managers. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- NotLost operates an information security management system aligned to ISO 27001 and GDPR. We maintain a structured policy framework including (non-exhaustive): Information Security Policy, Data Protection & Privacy, Access Control & Identity Management, Asset Management, Secure Development, Change & Release Management, Backup & Recovery, Incident Management, Business Continuity, Supplier Security and Acceptable Use.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
NotLost uses a formal change management process where all components (infrastructure, services, code, configurations) are tracked in version control and documented inventories, with changes initiated and referenced via our ticketing system.
Changes are categorised (standard, normal, emergency), peer-reviewed and tested in non-production environments before release, with documented rollback plans. Security impact is assessed through code review, dependency scanning and, for material changes, risk assessment and (where appropriate) threat modelling and updated DPIAs. Production changes require authorised approval and are logged and auditable. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
AWS provides secure hosting infrastructure.
NotLost receives open source threat feed information.
Patches, bug fixes and updates are usually deployed every two weeks. High risk patches will be prioritised and deployed as soon as possible. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- NotLost responds to incidents immediately, as soon as they're detected. A variety of monitoring services are used to ensure NotLost are notified as soon as possible of any incident or downtime.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
We have a pre-defined process for managing incidents.
Users report incidents directly to their account manager.
Issues are recorded and prioritised by the Head of Product.
All relevant parties are notified as required by internal policies such as our Data Breach Response Policy and external standards such as GDPR. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Full access to the system for up to one month.
- Link to free trial
- https://notlost.com/request-a-demo/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification
- ISO/IEC 27001 accreditation date
- Thursday 11 August 2022
- What the ISO/IEC 27001 doesn’t cover
- No part of the service is not covered
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Stripe
- PCI DSS accreditation date
- Monday 26 November 2018
- What the PCI DSS doesn’t cover
- We are a card-not-present-vendor; so PCI DSS in certified only for only transactions using a third party payment provider.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 881da175-d5e7-45b5-8076-20d2fcd8b028
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-