CalCommuter Platform
CalCommuter Platform is a secure, UK-hosted SaaS service built around an intelligent staff commute survey. It helps public sector organisations measure and reduce commuting and home-working emissions by providing Scope 3 reporting, workforce travel insights, and costed, tailored commute plans that support informed decision-making and sustainability objectives and net zero.
Features
- Intelligent staff commute survey
- Automated calculation of commuting and home-working emissions
- Scope 3 emissions reporting aligned to public sector requirements
- Costed, tailored commute plans generated for individual staff
- Comparison of current commutes with viable alternative travel options
- Aggregated workforce travel insights and analytics dashboard
- Supports hybrid working patterns and multiple worksite configurations
- Car share viability analysis available
- Configurable questions available
- Targeted follow-up messaging based on current and alternative commute options
Benefits
- Simplifies collection of staff commuting and home-working data
- Reduces manual effort in Scope 3 commuting emissions reporting
- Enables faster analysis of workforce travel patterns and impacts
- Supports evidence-based decisions on travel and sustainability policies
- Improves staff engagement through relevant, targeted commute information
- Identifies viable lower-cost and lower-emission commuting alternatives
- Provides consistent reporting across multiple worksites and organisations
- Saves time compared to spreadsheet-based or manual survey approaches
- Supports monitoring progress toward net zero and sustainability targets
- Enables scalable delivery across large / geographically dispersed organisations
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 7 0 9 3 1 8 8 2 8 7 1 0 4 5
Contact
CALCOMMUTER LIMITED
David Smith
Telephone: +447912277602
Email: david@calcommuter.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- CalCommuter Platform is a web-based SaaS service accessed via a modern internet browser and does not require specialist hardware. End users can access the staff commute survey and their individual results on their own device if preferred. Planned maintenance and updates are carried out outside normal UK business hours where possible and may result in brief periods of reduced availability, with advance notice provided. The service requires internet access and standard organisational IT permissions. Support is provided remotely during UK business hours. No on-premise deployment is required.
- System requirements
-
- Modern web browser supporting current HTML5 and JavaScript standards
- Reliable internet connection for web-based access and data submission
- Standard organisational IT permissions to access external web applications
User support
- Email or online ticketing support
- Yes
- Support response times
- Support queries submitted by email or online are typically responded to within one UK business day. Support is provided during standard UK business hours, Monday to Friday, excluding public holidays. Responses may be slower outside these hours, including evenings and weekends.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
CalCommuter Platform includes standard support for all customers at no additional cost. Standard support is provided via email during UK business hours, Monday to Friday, excluding public holidays. Support covers general service queries, user access issues, configuration guidance, and investigation of service related issues. Queries are typically responded to within one UK business day.
There are no tiered support levels and no additional paid support packages offered under this framework. The service does not include 24/7 support, phone support, or onsite support.
A dedicated technical account manager or named cloud support engineer is not provided as standard. Support requests are handled by the CalCommuter delivery and technical team as appropriate, ensuring continuity and effective issue resolution.
Additional implementation or advisory services, where required, are agreed separately outside the standard support model. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
CalCommuter supports buyers in getting started through a structured onboarding process. During onboarding, the buyer completes a standard organisation onboarding form, which is used to configure the service to reflect their organisation, worksites, and survey requirements. Service setup is completed by the CalCommuter team prior to launch.
Authorised organisational users are provided with guidance on accessing the administrative interface, interpreting outputs, and managing survey deployment. Support is provided remotely via email and scheduled video calls during UK business hours.
End users require no training to use the service. Staff access the survey and view their individual results through a simple, guided web interface designed for self-service use on desktop or mobile devices.
User documentation and written guidance are provided where appropriate, and additional advisory support can be agreed separately if required. No onsite training is required to use the service. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, buyers are offered the option to receive a final export of their data before deletion. At least 30 days prior to scheduled deletion, CalCommuter notifies the buyer and confirms whether a final export is required. Where requested, data is exported in a standard machine-readable format (CSV) and securely shared with the buyer using an encrypted file-sharing method. Responsibility for any onward handling of exported data then passes to the buyer as Data Controller.
Following export (if requested), all personal data relating to the buyer is deleted from the live production system in line with CalCommuter’s data deletion procedure. Deletion from the live system triggers expiry from platform backups in accordance with the hosting provider’s backup retention schedule.
Prior to deletion, CalCommuter may generate an anonymised dataset for its own internal research, benchmarking, and service improvement purposes. Anonymisation removes direct identifiers and reduces location granularity so that retained datasets no longer constitute personal data. Anonymised datasets are not provided to buyers.
Buyers may request written confirmation once deletion has been completed. - End-of-contract process
-
At the end of the contract term, CalCommuter will notify the buyer in advance that the service is due to end and confirm whether the buyer intends to renew. If the contract is not renewed, the buyer retains access to the service for the remainder of the contract period only.
As part of the standard contract price, buyers may request a final export of their data prior to contract end. Data is provided in a standard, machine-readable format and shared securely. Following contract expiry, personal data is deleted from the live system in line with CalCommuter’s data deletion procedure, with deletion propagating through backups in accordance with hosting provider retention schedules. Written confirmation of deletion can be provided on request.
The standard contract price includes service access for the agreed term, standard support, and end-of-contract data export and deletion.
Any additional advisory work, bespoke analysis, extended access beyond the contract term, or additional reporting requested after contract expiry is not included and would be subject to separate agreement and additional cost. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The end-user staff commute survey and individual results are designed to work on mobile devices and can be completed using a smartphone or tablet. Administrative and analytical features, including the employer data dashboard and advanced reporting tools, are optimised for desktop and larger screen devices to support detailed analysis and visualisation. Users can access all core functionality via a web browser, with no separate mobile application required.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- CalCommuter is accessed through a secure web-based interface. End users complete a short staff commute survey and view their individual commute results and viable alternatives through a simple, guided interface. Authorised organisational users access an administrative dashboard to manage surveys, view aggregated results, and analyse commuting patterns and emissions. The interface is browser-based, requires no software installation, and supports role-based access controls.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
CalCommuter has been developed using standard, accessible web technologies and reviewed internally against WCAG 2.2 AA principles. Internal testing has included keyboard-only navigation, use of semantic HTML and form labelling, colour contrast checks, and testing with common browser accessibility features such as screen magnification and built-in screen readers.
Accessibility considerations are prioritised in the staff survey and individual results interfaces, which are the primary end-user interactions with the service. While formal user testing with assistive technology users and third-party accessibility audits have not yet been undertaken, accessibility is considered as part of ongoing development, and reasonable adjustments can be made where required. - API
- No
- Customisation available
- Yes
- Description of customisation
-
CalCommuter is configured for each buyer during onboarding, based on information provided by the buyer via a structured onboarding form. Customisation includes organisational details, worksites and staff numbers, survey parameters (such as viable walking, cycling and public transport thresholds), parking costs, travel policy context, and links to organisation-specific internal resources. Buyers can also specify survey branding, administrative users, optional custom survey questions, and optional analytical features.
Customisation is defined by the buyer at the point of onboarding and implemented as part of service setup. This ensures a consistent, auditable configuration without requiring bespoke software development. Once live, authorised administrative users can manage users and access results, but core survey logic and configuration remain aligned to the agreed onboarding specification.
Only authorised representatives of the buyer can request or approve customisation. End users interact with the service based on the configuration agreed during onboarding.
Scaling
- Independence of resources
- CalCommuter is delivered as a multi-tenant SaaS service hosted on scalable cloud infrastructure. Compute and storage resources are managed to ensure sufficient capacity for concurrent use by multiple organisations. Logical separation is applied between customer datasets, and service performance is monitored to identify and address capacity issues. This approach ensures that demand from one customer does not materially impact the availability or performance experienced by other users.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Buyers request data exports by contacting CalCommuter support via email. Upon request, CalCommuter prepares and provides the export in a standard, machine-readable format (for example, CSV) and shares it securely with the buyer. Access to exports is restricted to authorised buyer representatives, and requests are handled in line with data protection and security procedures.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
CalCommuter Platform is designed to be available during standard operating conditions and is hosted on resilient cloud infrastructure. While no formal uptime percentage SLA is guaranteed under this framework, the service is monitored and maintained to support high availability for users.
Planned maintenance is scheduled outside normal UK business hours where possible, with advance notice provided to buyers. Unplanned service interruptions are investigated and resolved as a priority.
The standard contract price does not include service credits or automatic refunds linked to availability levels. Where a material service disruption occurs, CalCommuter will work with the buyer to understand the impact and agree appropriate remedial actions on a case by case basis. - Approach to resilience
-
CalCommuter Platform is designed as a resilient, cloud-hosted SaaS service. The service is hosted on UK-based cloud infrastructure provided by a third-party hyperscale provider, which includes built-in redundancy, physical security, and environmental controls across multiple availability zones within the region.
The application architecture is designed to tolerate individual component failures without loss of customer data. Data is stored on managed cloud services that provide automated replication and backup in line with the hosting provider’s standard resilience and durability features.
Service health and availability are monitored to identify issues promptly, and incidents are investigated and resolved as a priority. Planned maintenance is scheduled outside normal UK business hours where possible to minimise disruption.
Detailed technical architecture and datacentre resilience information is available on request, where appropriate, to support buyer assurance and information governance reviews. - Outage reporting
-
Where a service outage or significant service degradation occurs, CalCommuter will notify affected buyers via email as soon as reasonably practicable.
Unplanned outages are investigated and addressed as a priority, and updates are provided to buyers where appropriate until service is restored. Planned maintenance is scheduled outside normal UK business hours where possible, with advance notice provided by email.
Buyers can also contact CalCommuter support via email to report issues or request updates on service status.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Administrative and reporting users authenticate using a username and password with mandatory multi-factor authentication (MFA) to access the CalCommuter data dashboard. Survey participants do not create accounts; instead, they access surveys and their personal commute plans via secure, unique links sent to their designated email address. Access controls are role based and aligned to the sensitivity of the data being accessed.
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted to authorised users only through role based access controls and mandatory multi-factor authentication. User permissions are granted on a least privilege basis and reviewed as required. Support channels are restricted to named contacts within each client organisation, with identity verified via registered email addresses. Sensitive information is shared only with authorised users, and access is removed promptly when no longer required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- CalCommuter takes a risk based approach to security governance appropriate to a managed SaaS service. Responsibility for service security sits with a named director at board level, ensuring clear accountability and oversight. Security considerations are integrated into service design, development, and operations, including access control, data protection, vulnerability management, and incident response. The service is hosted on a third party cloud platform that meets recognised security standards, with responsibilities managed in line with the shared responsibility model. Security policies and procedures are reviewed periodically and updated as the service evolves.
- Information security policies and processes
-
Overall responsibility for information security sits with the company director, who has board-level authority and is accountable for security, data protection, and compliance across the service.
Day-to-day security responsibilities are managed directly by the director, supported where necessary by subcontracted software developers operating under contractual confidentiality and data protection obligations. Any administrative staff access is strictly limited and role-based.
Information security policies and processes cover data protection, access control, secure system configuration, vulnerability management, incident response, and data retention and deletion. These are informed by UK GDPR requirements and the UK government cloud security principles.
Controls are enforced through technical measures within the cloud hosting environment, documented procedures, and regular checks such as access reviews and vulnerability scanning. Security incidents or suspected breaches are escalated directly to the director for assessment and response, including external notification where required. Policies and processes are reviewed periodically and updated as the service and risk profile evolve. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- CalCommuter uses supplier defined configuration and change management processes proportionate to a managed SaaS service. Service components, configurations and dependencies are tracked through version control and documented environments. Changes are planned, reviewed and tested prior to deployment, with production releases controlled and reversible where required. Security impact is assessed as part of change review, including data protection, access control and dependency changes. Hosting and infrastructure changes follow cloud provider best practice within the shared responsibility model, with monitoring in place to identify issues post deployment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- CalCommuter operates a proportionate, risk based vulnerability management process appropriate for a SaaS service. Potential threats are identified through automated vulnerability scanning conducted monthly and prior to any deployment to production, alongside dependency monitoring and cloud platform security alerts. Runtime monitoring and alerting tools are used to detect unexpected application behaviour in production. Identified issues are assessed and prioritised based on severity and potential impact. Patches and configuration updates are deployed promptly through controlled release processes, with critical issues addressed as soon as practicable. Threat intelligence is informed by scanning outputs, cloud provider advisories, and software dependency security notifications.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- CalCommuter uses proportionate protective monitoring appropriate to a SaaS service. Potential compromises are identified through application logging, automated alerts from runtime monitoring tools, and cloud platform monitoring for abnormal behaviour or access patterns. Alerts are reviewed promptly and investigated to determine impact and root cause. Where a potential compromise is identified, access is restricted as appropriate, affected components are isolated, and remediation actions are prioritised based on risk. Incidents are responded to as soon as practicable, with critical issues investigated and acted upon without delay.
- Incident management type
- Supplier-defined controls
- Incident management approach
- CalCommuter follows a documented incident management process proportionate to a SaaS service. Common incident scenarios, such as service availability issues or security alerts, have predefined response steps covering assessment, containment and resolution. Incidents may be identified through monitoring or reported by users via email. Users are kept informed of material incidents impacting service delivery, and incident summaries or reports are provided on request, including details of impact, actions taken and any follow up measures implemented.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-