Skip to main content

Help us improve the Digital Marketplace - send your feedback

PlanningHub

Planning Application AI Assistant

Planning Application AI Assistant helps Local Planning Authorities process planning applications and deliver pre-application advice more efficiently. It reduces administrative workload associated with planning research, application validation and assessment. The service supports development management teams and can also be used to provide structured pre-application guidance to the public.

Features

  • Supports high-volume householder and common planning application types.
  • Supports Lawful Development Certificates and Prior Approval applications.
  • Connects to policy, GIS, historic decisions and other data sources.
  • Converts legacy planning documents into structured, usable data.
  • Simplifies complex planning contexts into clear considerations.
  • Presents relevant policy, cases, constraints and environmental factors.
  • Provides clear, consistent, project-specific planning information.
  • Modular system scalable across datasets and project groups.
  • Available as standalone, integrated platform or public-facing service.
  • Role-based access, audit logging and configurable controls.

Benefits

  • Improves efficiency for the most common planning application types.
  • Reduces processing time for certificates and prior approval applications.
  • Minimises time spent navigating multiple disconnected data sources.
  • Removes manual review of historic and unstructured documents.
  • Improves consistency in planning assessment and decision-making.
  • Improves decision consistency by surfacing relevant information.
  • Improves clarity and consistency for officers and applicants.
  • Supports flexibility aligned to organisational workflows.
  • Enables flexible deployment for internal and public-facing use.
  • Supports governance, accountability and controlled use across teams.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ewa@planning-hub.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 5 3 9 5 4 6 2 8 6 6 5 8 9 9

Contact

PlanningHub Ewa Moskwiak
Telephone: 02035765476
Email: ewa@planning-hub.com

About your service

Service categories

Application Development and Deployment

AI platforms

AI software services

  • Generative AI Software Services
  • Document AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Planning Application AI Assistant extends existing local authority planning systems by integrating with back-office systems and modern digital planning tools. It can also extend public-facing planning services by embedding within applicant portals to support streamlined pre-application advice.
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
The service is provided as a configurable standard, cloud-hosted platform and does not require specialist hardware or client-side software beyond a modern web browser. Customisation is limited to configuration options, workflows and data sources, rather than bespoke development.

Planned maintenance windows may apply and are communicated in advance. Support is provided during standard UK business hours, and service use is subject to agreed fair-use and acceptable-use policies.
System requirements
  • Modern web browser (Chrome, Edge, Firefox, Safari)
  • Internet connection with standard HTTPS access
  • JavaScript enabled in browser
  • Cookies enabled for authentication
  • User account with role-based permissions
  • Multi-Factor Authentication capable device
  • PDF viewer for report downloads
  • Secure email access for notifications

User support

Email or online ticketing support
Yes
Support response times
Support is provided during UK business hours (Monday to Friday, excluding public holidays).
System-critical failures: response within 4 hours
Urgent issues: response within 1 business day
Non-urgent or cosmetic issues: response within 5 business days

Requests received at weekends are acknowledged on the next business day.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide standard support as part of the core service subscription, covering user assistance, issue resolution and service guidance during standard UK business hours. Support requests can be raised via email and are prioritised based on severity. There is no additional charge for standard support.

Each customer is assigned a Technical Account Manager, who acts as the primary point of contact for service coordination, technical queries and ongoing account support. Enhanced or extended support services, where required, are optional and priced separately by agreement.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We support users in getting started through a structured onboarding approach designed to minimise day-to-day disruption and enable rapid adoption. This includes online training sessions, supported by comprehensive user documentation, such as a service brochure and user guide. We also provide short, feature-specific video tutorials to support self-paced learning.
Additional support is available through in-platform guidance and email support during onboarding. Where required, introductory sessions can be provided to align the service with organisational needs.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
The service does not collect or store customer data other than user account information required for authentication and access management. As a result, there is no user-generated or business data that customers need to extract at the end of the contract.
Service performance monitoring data is collected for operational purposes only and does not constitute customer data. Upon contract termination, user accounts are disabled and all associated account information is securely deleted in line with our data retention policies. Where required, we can provide confirmation of deletion.
End-of-contract process
At the end of the contract, user access to the service is terminated and all associated user account information (name, email address and authentication credentials) is securely deleted in line with our retention and security policies. The service does not store customer content or business data, therefore no data export or GDPR data processing activities are required at contract end.
The contract price includes contract termination, account closure and secure deletion of account information at no additional cost. There are no mandatory exit fees.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is accessible on mobile devices using a responsive web interface. Core functionality is available on both mobile and desktop. On mobile devices, the interface is optimised for smaller screens, which may result in simplified layouts and reduced use of side-by-side views compared to the desktop experience.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, browser-based web interface. The interface allows users to submit and review planning information, view structured guidance reports, and manage outputs through role-based access controls. The service also provides an API interface to support integration with local authority back-office planning systems and related digital services.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Interface testing includes internal accessibility testing using common assistive technologies, such as screen readers and keyboard-only navigation, to identify and address basic usability and accessibility issues. Testing focuses on ensuring core functionality can be accessed without a mouse and that content is readable and navigable.

Accessibility is reviewed iteratively as part of ongoing development, with issues logged and prioritised for improvement. Formal user testing with assistive technology users can be undertaken where required by customer needs.
API
Yes
What users can and can't do using the API
The API enables integration with local authority back-office planning systems (such as Idox, Arcus and similar platforms) to automate secure data exchange within the planning evaluation workflow. This includes submitting case references, site details and structured planning context to the service, and retrieving generated outputs for use within existing systems.

The API supports configuration and data exchange, but does not provide full administrative control. Users cannot manage user accounts, security settings or core service configuration via the API.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Customisation includes planning data configuration, such as selecting relevant GIS layers or local planning policies, report configuration, including the inclusion of additional sections or outputs, and AI prompt configuration to reflect specific policy constraints or local interpretation.

Scaling

Independence of resources
The service is built on a scalable, cloud-native architecture that dynamically allocates resources based on demand. This ensures individual users operate within isolated workloads and are not impacted by usage peaks from other users.

Performance is continuously monitored using availability, latency and throughput metrics. Automated scaling and alerting allow capacity to be adjusted proactively, maintaining consistent and reliable service performance for all users.

Analytics

Service usage metrics
Yes
Metrics types
We provide service usage and quality metrics to support transparency and service management. Usage metrics include the number of reports generated per month.
We also provide data quality metrics, highlighting identified data gaps or limitations that may affect outputs, such as missing or incomplete GIS spatial data or planning policy documentation. These metrics support user understanding of output context and service reliability.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
The service does not collect or store customer data other than user account information required for authentication and access management. As a result, there is no user-generated or business data that customers need to extract at the end of the contract.
Service performance monitoring data is collected for operational purposes only and does not constitute customer data. Upon contract termination, user accounts are disabled and all associated account information is securely deleted in line with our data retention policies. Where required, we can provide confirmation of deletion.
Data export formats
Other
Data import formats
Other

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is designed for high availability using a resilient, cloud-native architecture with automated scaling and monitoring. We target 99.9% service availability during working hours per calendar month, excluding planned maintenance notified in advance.

Availability is monitored continuously. If availability falls below the guaranteed level, users are eligible for service credits, applied as a proportionate reduction to the next billing period, in line with the agreed Service Level Agreement (SLA). Credits are the sole remedy for SLA breaches.
Approach to resilience
The service is designed for resilience using a cloud based, fault-tolerant architecture. Core components are containerised and deployed across multiple availability zones, with automatic failover, self-healing, and horizontal scaling to ensure continuity of service during component or infrastructure failures.

Datacentre resilience is provided by a hyperscale cloud provider, which implements physically secure, geographically separated facilities with redundant power, networking and cooling. Data is protected through replication, regular backups, and defined disaster-recovery procedures with documented recovery objectives. Detailed resilience and recovery arrangements are available on request.
Outage reporting
Service availability is monitored continuously and outages are identified automatically. Users are notified of service outages and significant incidents via email alerts, including updates on progress and resolution.
A service status dashboard is available to report current availability and historical incidents. Where required, service status information can also be made available via an API to support integration with customer monitoring or reporting tools.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access control (RBAC), enforced through centralised authentication. Access is granted on a least-privilege basis and limited to authorised personnel only.

Administrative access requires strong authentication, including MFA, and is logged and monitored. Support access is controlled through approved channels, with identity verification and audit logging to ensure secure and accountable access.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
ISO/IEC 42001
Information security policies and processes
We follow a set of information security policies aligned with Cyber Essentials, and conduct penetration testing aligned with ISO/IEC 27001, covering access control, secure configuration, patch management, malware protection, incident management, and acceptable use.
Responsibility for information security sits with senior management, with day-to-day oversight by the CIO acting as an information security lead. Policies are communicated to all staff and contractors and enforced through technical controls, access reviews, and management oversight. Security incidents are recorded, escalated as required, and reviewed to ensure corrective actions are implemented.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We operate configuration and change management processes to ensure services are securely configured and controlled throughout their lifecycle. Service components, including infrastructure, software and configurations, are documented and tracked from deployment through to retirement.
All changes are assessed prior to implementation to identify potential security and service impacts. This includes reviewing access controls, configuration settings, dependencies and risks to confidentiality, integrity and availability. Changes are approved by an authorised owner, tested where appropriate, and recorded.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate supplier-defined vulnerability management processes aligned with Cyber Essentials, CREST Penetration Testing and proportionate to the services provided. Potential threats to our services are assessed by reviewing vulnerability severity, exploitability, and relevance to the service environment, including potential impact on confidentiality, integrity, and availability.
Information on vulnerabilities is obtained from vendor security advisories, operating system and application updates, trusted security bulletins and public vulnerability disclosures (such as CVEs). Patches are prioritised by risk, with critical security updates deployed promptly and lower-risk updates applied during planned maintenance. Remediation actions are tracked to ensure effective resolution.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We operate supplier-defined protective monitoring processes aligned with Cyber Essentials, CREST Penetration Testing and proportionate to the services provided. Potential compromises are identified through continuous monitoring of system logs, access events, service performance metrics and security alerts, enabling detection of abnormal behaviour, unauthorised access attempts or service degradation.
When a potential compromise is identified, it is investigated promptly, with containment and remediation actions taken in line with documented incident response procedures. Incidents are escalated through our reporting structure and reviewed to identify root causes and corrective actions. Critical security incidents are responded to without undue delay.
Incident management type
Supplier-defined controls
Incident management approach
We operate supplier-defined incident management processes with pre-defined procedures for common security and service events, including availability issues, security alerts and configuration incidents. These processes define roles, escalation paths, containment actions and recovery steps to ensure incidents are handled consistently and effectively.
Users can report incidents via email support, which are logged and prioritised. Incident updates and outcomes are communicated to affected users, with incident reports provided on request, summarising impact, root cause and corrective actions taken.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
PlanningHub offers a free, time-limited trial of the Planning Application AI Assistant for selected partner organisations. The trial lasts up to three months and provides access to core functionality. Data onboarding, configuration and integration costs are excluded and charged separately if required.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
3%
Between £500,001 and £1,000,000
4%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
8bff6a36-1d40-480a-a728-50a89a3eebf0
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ewa@planning-hub.com. Tell them what format you need. It will help if you say what assistive technology you use.