Planning Application AI Assistant
Planning Application AI Assistant helps Local Planning Authorities process planning applications and deliver pre-application advice more efficiently. It reduces administrative workload associated with planning research, application validation and assessment. The service supports development management teams and can also be used to provide structured pre-application guidance to the public.
Features
- Supports high-volume householder and common planning application types.
- Supports Lawful Development Certificates and Prior Approval applications.
- Connects to policy, GIS, historic decisions and other data sources.
- Converts legacy planning documents into structured, usable data.
- Simplifies complex planning contexts into clear considerations.
- Presents relevant policy, cases, constraints and environmental factors.
- Provides clear, consistent, project-specific planning information.
- Modular system scalable across datasets and project groups.
- Available as standalone, integrated platform or public-facing service.
- Role-based access, audit logging and configurable controls.
Benefits
- Improves efficiency for the most common planning application types.
- Reduces processing time for certificates and prior approval applications.
- Minimises time spent navigating multiple disconnected data sources.
- Removes manual review of historic and unstructured documents.
- Improves consistency in planning assessment and decision-making.
- Improves decision consistency by surfacing relevant information.
- Improves clarity and consistency for officers and applicants.
- Supports flexibility aligned to organisational workflows.
- Enables flexible deployment for internal and public-facing use.
- Supports governance, accountability and controlled use across teams.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 5 3 9 5 4 6 2 8 6 6 5 8 9 9
Contact
PlanningHub
Ewa Moskwiak
Telephone: 02035765476
Email: ewa@planning-hub.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Generative AI Software Services
- Document AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Planning Application AI Assistant extends existing local authority planning systems by integrating with back-office systems and modern digital planning tools. It can also extend public-facing planning services by embedding within applicant portals to support streamlined pre-application advice.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
-
The service is provided as a configurable standard, cloud-hosted platform and does not require specialist hardware or client-side software beyond a modern web browser. Customisation is limited to configuration options, workflows and data sources, rather than bespoke development.
Planned maintenance windows may apply and are communicated in advance. Support is provided during standard UK business hours, and service use is subject to agreed fair-use and acceptable-use policies. - System requirements
-
- Modern web browser (Chrome, Edge, Firefox, Safari)
- Internet connection with standard HTTPS access
- JavaScript enabled in browser
- Cookies enabled for authentication
- User account with role-based permissions
- Multi-Factor Authentication capable device
- PDF viewer for report downloads
- Secure email access for notifications
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support is provided during UK business hours (Monday to Friday, excluding public holidays).
System-critical failures: response within 4 hours
Urgent issues: response within 1 business day
Non-urgent or cosmetic issues: response within 5 business days
Requests received at weekends are acknowledged on the next business day. - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide standard support as part of the core service subscription, covering user assistance, issue resolution and service guidance during standard UK business hours. Support requests can be raised via email and are prioritised based on severity. There is no additional charge for standard support.
Each customer is assigned a Technical Account Manager, who acts as the primary point of contact for service coordination, technical queries and ongoing account support. Enhanced or extended support services, where required, are optional and priced separately by agreement. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We support users in getting started through a structured onboarding approach designed to minimise day-to-day disruption and enable rapid adoption. This includes online training sessions, supported by comprehensive user documentation, such as a service brochure and user guide. We also provide short, feature-specific video tutorials to support self-paced learning.
Additional support is available through in-platform guidance and email support during onboarding. Where required, introductory sessions can be provided to align the service with organisational needs. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
The service does not collect or store customer data other than user account information required for authentication and access management. As a result, there is no user-generated or business data that customers need to extract at the end of the contract.
Service performance monitoring data is collected for operational purposes only and does not constitute customer data. Upon contract termination, user accounts are disabled and all associated account information is securely deleted in line with our data retention policies. Where required, we can provide confirmation of deletion. - End-of-contract process
-
At the end of the contract, user access to the service is terminated and all associated user account information (name, email address and authentication credentials) is securely deleted in line with our retention and security policies. The service does not store customer content or business data, therefore no data export or GDPR data processing activities are required at contract end.
The contract price includes contract termination, account closure and secure deletion of account information at no additional cost. There are no mandatory exit fees. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is accessible on mobile devices using a responsive web interface. Core functionality is available on both mobile and desktop. On mobile devices, the interface is optimised for smaller screens, which may result in simplified layouts and reduced use of side-by-side views compared to the desktop experience.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, browser-based web interface. The interface allows users to submit and review planning information, view structured guidance reports, and manage outputs through role-based access controls. The service also provides an API interface to support integration with local authority back-office planning systems and related digital services.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Interface testing includes internal accessibility testing using common assistive technologies, such as screen readers and keyboard-only navigation, to identify and address basic usability and accessibility issues. Testing focuses on ensuring core functionality can be accessed without a mouse and that content is readable and navigable.
Accessibility is reviewed iteratively as part of ongoing development, with issues logged and prioritised for improvement. Formal user testing with assistive technology users can be undertaken where required by customer needs. - API
- Yes
- What users can and can't do using the API
-
The API enables integration with local authority back-office planning systems (such as Idox, Arcus and similar platforms) to automate secure data exchange within the planning evaluation workflow. This includes submitting case references, site details and structured planning context to the service, and retrieving generated outputs for use within existing systems.
The API supports configuration and data exchange, but does not provide full administrative control. Users cannot manage user accounts, security settings or core service configuration via the API. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Customisation includes planning data configuration, such as selecting relevant GIS layers or local planning policies, report configuration, including the inclusion of additional sections or outputs, and AI prompt configuration to reflect specific policy constraints or local interpretation.
Scaling
- Independence of resources
-
The service is built on a scalable, cloud-native architecture that dynamically allocates resources based on demand. This ensures individual users operate within isolated workloads and are not impacted by usage peaks from other users.
Performance is continuously monitored using availability, latency and throughput metrics. Automated scaling and alerting allow capacity to be adjusted proactively, maintaining consistent and reliable service performance for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide service usage and quality metrics to support transparency and service management. Usage metrics include the number of reports generated per month.
We also provide data quality metrics, highlighting identified data gaps or limitations that may affect outputs, such as missing or incomplete GIS spatial data or planning policy documentation. These metrics support user understanding of output context and service reliability. - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
The service does not collect or store customer data other than user account information required for authentication and access management. As a result, there is no user-generated or business data that customers need to extract at the end of the contract.
Service performance monitoring data is collected for operational purposes only and does not constitute customer data. Upon contract termination, user accounts are disabled and all associated account information is securely deleted in line with our data retention policies. Where required, we can provide confirmation of deletion. - Data export formats
- Other
- Data import formats
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is designed for high availability using a resilient, cloud-native architecture with automated scaling and monitoring. We target 99.9% service availability during working hours per calendar month, excluding planned maintenance notified in advance.
Availability is monitored continuously. If availability falls below the guaranteed level, users are eligible for service credits, applied as a proportionate reduction to the next billing period, in line with the agreed Service Level Agreement (SLA). Credits are the sole remedy for SLA breaches. - Approach to resilience
-
The service is designed for resilience using a cloud based, fault-tolerant architecture. Core components are containerised and deployed across multiple availability zones, with automatic failover, self-healing, and horizontal scaling to ensure continuity of service during component or infrastructure failures.
Datacentre resilience is provided by a hyperscale cloud provider, which implements physically secure, geographically separated facilities with redundant power, networking and cooling. Data is protected through replication, regular backups, and defined disaster-recovery procedures with documented recovery objectives. Detailed resilience and recovery arrangements are available on request. - Outage reporting
-
Service availability is monitored continuously and outages are identified automatically. Users are notified of service outages and significant incidents via email alerts, including updates on progress and resolution.
A service status dashboard is available to report current availability and historical incidents. Where required, service status information can also be made available via an API to support integration with customer monitoring or reporting tools.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted using role-based access control (RBAC), enforced through centralised authentication. Access is granted on a least-privilege basis and limited to authorised personnel only.
Administrative access requires strong authentication, including MFA, and is logged and monitored. Support access is controlled through approved channels, with identity verification and audit logging to ensure secure and accountable access. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- ISO/IEC 42001
- Information security policies and processes
-
We follow a set of information security policies aligned with Cyber Essentials, and conduct penetration testing aligned with ISO/IEC 27001, covering access control, secure configuration, patch management, malware protection, incident management, and acceptable use.
Responsibility for information security sits with senior management, with day-to-day oversight by the CIO acting as an information security lead. Policies are communicated to all staff and contractors and enforced through technical controls, access reviews, and management oversight. Security incidents are recorded, escalated as required, and reviewed to ensure corrective actions are implemented. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We operate configuration and change management processes to ensure services are securely configured and controlled throughout their lifecycle. Service components, including infrastructure, software and configurations, are documented and tracked from deployment through to retirement.
All changes are assessed prior to implementation to identify potential security and service impacts. This includes reviewing access controls, configuration settings, dependencies and risks to confidentiality, integrity and availability. Changes are approved by an authorised owner, tested where appropriate, and recorded. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We operate supplier-defined vulnerability management processes aligned with Cyber Essentials, CREST Penetration Testing and proportionate to the services provided. Potential threats to our services are assessed by reviewing vulnerability severity, exploitability, and relevance to the service environment, including potential impact on confidentiality, integrity, and availability.
Information on vulnerabilities is obtained from vendor security advisories, operating system and application updates, trusted security bulletins and public vulnerability disclosures (such as CVEs). Patches are prioritised by risk, with critical security updates deployed promptly and lower-risk updates applied during planned maintenance. Remediation actions are tracked to ensure effective resolution. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We operate supplier-defined protective monitoring processes aligned with Cyber Essentials, CREST Penetration Testing and proportionate to the services provided. Potential compromises are identified through continuous monitoring of system logs, access events, service performance metrics and security alerts, enabling detection of abnormal behaviour, unauthorised access attempts or service degradation.
When a potential compromise is identified, it is investigated promptly, with containment and remediation actions taken in line with documented incident response procedures. Incidents are escalated through our reporting structure and reviewed to identify root causes and corrective actions. Critical security incidents are responded to without undue delay. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We operate supplier-defined incident management processes with pre-defined procedures for common security and service events, including availability issues, security alerts and configuration incidents. These processes define roles, escalation paths, containment actions and recovery steps to ensure incidents are handled consistently and effectively.
Users can report incidents via email support, which are logged and prioritised. Incident updates and outcomes are communicated to affected users, with incident reports provided on request, summarising impact, root cause and corrective actions taken. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- PlanningHub offers a free, time-limited trial of the Planning Application AI Assistant for selected partner organisations. The trial lasts up to three months and provides access to core functionality. Data onboarding, configuration and integration costs are excluded and charged separately if required.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 4%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8bff6a36-1d40-480a-a728-50a89a3eebf0
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-