Skip to main content

Help us improve the Digital Marketplace - send your feedback

OPEN SYSTEMS LAB LTD

PlanX

Plan✕ is a content management system (CMS) for digital services. It enables local authorities to create, share and operate smart, dynamic-form services that make complex rules easy to navigate. Plan✕ is an open source tool, developed with local authorities and MHCLG. The aim is to make planning simpler for everyone.

Features

  • Simple, seamless planning services for applicants and their agents
  • Dynamic, 'smart' content that responds to users inputs
  • Themed for your council identity
  • Responsibly designed AI powered modular components
  • Pulls in GIS data from Digital Land API
  • Editor interface for content management by planning officers
  • Managed service templates for all main planning services
  • Accessible-as-standard
  • Service analytics and feedback
  • Includes shared service content across councils

Benefits

  • Makes planning simpler and more transparent for applicants
  • Increases user satisfaction and improves accessibility
  • Reduces the volume of telephone and email enquiries
  • Reduces the number of invalid planning applications
  • Reduces application processing time downstream
  • Reduces the number of refused/rejected applications
  • Gives planning authorities control over their data, services and outcomes
  • Allows planning authorities to better understand service usage
  • Feedback and analytics reveal where improvements to guidelines are needed
  • Ensures consistency of guidance and decisions

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at enquiries@opensystemslab.io. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 7 7 6 4 3 7 5 5 2 1 6 9 0 8

Contact

OPEN SYSTEMS LAB LTD Laura Dewis
Telephone: 0330 229 6250
Email: enquiries@opensystemslab.io

About your service

Service categories

Applications

Content workflow and management

Content services

  • Enterprise Content Management Applications
  • Content Sharing and Collaboration Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The main constraints are:

1. Availability of data (eg GIS) data for planning constraints. Planning authorities will need to publish their GIS data via planning.data.gov.uk

2. Availability of integrations with back-office systems.

3. Customers will need to create a GOV.UK Pay account to receive payments.
System requirements
Any modern web browser (Chrome, Safari, Edge, Firefox, IE11+)

User support

Email or online ticketing support
Yes
Support response times
Email and Slack support for admins only. We will reply within 24 hours.
Urgent issues we will usually respond to more quickly.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Customer admins can contact us by email or via a community Slack channel to ask questions or report or resolve issues.

Within working hours (Mon-Fri 9am-5pm, excluding bank holidays) we aim to respond to:

Critical issues within 2 working hours and put an at least temporary fix within 24 hours.

Major issues within 8 working hours, and we aim to put in place an at least temporary fix within 5 working days.

Minor issues we aim to respond within 16 working hours, if a reply is appropriate.

Additional support services such as training, co-writing and planning information and data auditing are available for an additional cost (see pricing). We may from time to time also provide these for free to the community, including support drop-ins.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
PlanX supports users in getting started through a structured, hands-on onboarding process designed to help councils move from initial setup to live services efficiently and confidently. Each customer is provided with a detailed onboarding guide, checklist, and progress dashboard, which clearly set out the required steps and allow users to track their onboarding status from start to launch.

The PlanX team works closely with council IT teams, planning officers, and delivery managers to align technical setup, service design, integrations, and governance, ensuring a smooth fit within existing council environments. Users are supported through one-to-one sessions to demonstrate the platform, explain core concepts, and provide practical guidance on using the editor.

Support is ongoing throughout onboarding. The team is available via Slack to answer questions, resolve issues quickly, and provide day-to-day guidance. PlanX also runs setup workshops and facilitates community-driven groups where councils and delivery partners can share knowledge, lessons learned, and best practice. In addition, comprehensive online documentation and training materials are available within the editor, guiding users step by step through service creation and publication. This combination of structured guidance, direct support, and peer learning helps users launch services with confidence and build capability over time.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Admins will be able to export all of the data relating to their Plan✕ services in a structured format (eg csv, json). The API affords flexibility to make custom queries. In the case of data that is available but cannot yet be self-exported, customers can request this data, and it will be made available to them.
End-of-contract process
A Council can request to terminate their Plan✕ subscription at any point in line with the termination terms, by notifying their Account Manager by email. They can extract any and all data available via the API, and request reasonable assistance in facilitating this. Any additional assistance –  for example, working with a team to help them set up a replacement service – will have a cost based on a reasonable day-rate, to be agreed at the time.
Documentation accessibility standard
EN 301 549

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The public-facing elements of the service are accessible on mobile devices and are designed to be responsive, allowing end users to view and complete tasks on smaller screens. Core functionality for creating, configuring, and managing services is provided through an editor interface that is optimised for desktop use. This editor involves complex workflows, detailed configuration, and multi-panel interactions that require larger screens and precise input, making desktop or laptop devices the recommended environment. While mobile access is supported for public use, full administrative and editorial functionality is best experienced on desktop devices to ensure usability, efficiency, and accuracy.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
PlanX provides three service interfaces. The public interface is used by applicants to access planning services online, complete forms, and submit information through a responsive, web-based experience. The editor interface is used by planning officers and service teams to design, configure, and manage planning services, content, and workflows; it is optimised for desktop use due to its complexity. The API interface allows PlanX to integrate with external systems, enabling secure data exchange and interoperability with other local authority or third-party services. Together, these interfaces support end-to-end digital planning delivery while separating public use, service management, and system integration.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
As well as carrying out accessibility audits (around annually, depending on what new features we release) we also have in place a suite of automated accessibility tests. We carry out user testing with users with accessibility needs at any opportunity.

WCAG 2.2 AA or EN 301 549 (last August, 14th 2025)
API
Yes
What users can and can't do using the API
PlanX has an API that allows users to:

– Access and interrogate the content and structure of digital services

– Request enquiry / application data from the database (if they have permission to do so).
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
PlanX is designed to be highly configurable so customers can tailor services to their local authority needs while using a shared platform.

Customers can customise their PlanX channel with their brand / web theme colours and logo, to provide end users with a clear, seamless experience when navigating from and to other council web pages. You will also need to add a privacy notice and help / contact information for users.

You can also use your own council subdomains. eg planningservices.council.gov.uk

Beyond visual branding, users can customise service content, structure, and behaviour. Through the editor interface, authorised users can create and manage service journeys, update guidance text, configure questions and validation rules, and control how information is presented to applicants. Users can also configure integrations with external systems using supported APIs, enabling data exchange with back-office or third-party services.

Scaling

Independence of resources
Plan✕ procures hosting from AWS (or equivalent) which can scale in response to spikes in user demand.

Data (such as mapping or GIS) that is pulled in from third party sources will, as far as possible, be pulled in from sources that are also able to scale. In the event that demand spikes beyond the scaling capacity of these services, Plan✕ can continue to function independently without these data until demand normalises again.

Analytics

Service usage metrics
Yes
Metrics types
– Traffic
– User activity through flows (revealing, for example, the most common enquiry types, balance of responses, and revealing which areas of guidance / policy are proving to be key barriers to users).

Every service on PlanX has a dedicated analytics dashboard showing key analytics about that service. We are also improving our API to allow queries for the purposes of usage analysis.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Admins will be able to export all of the data relating to their Plan✕ services in a structured format (eg csv, json). The API affords flexibility to make custom queries. In the case of data that is available but cannot yet be self-exported, customers can request this data, and it will be made available to them.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • PDF (in the case of documents)
Data import formats
  • CSV
  • Other
Other data import formats
PDF (in the case of documents)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is currently hosted on AWS and therefore benefits from their availability (99.9% uptime) and resilience. In the unlikely event that the PlanX service should go down, our team will be alerted automatically (or by the customer) and seek to restore the service as quickly as possible.

No refunds are currently agreed in the event of service downtime as part of the SLA.
Approach to resilience
Alongside the security and load-management measures we have in place, critical data is also backed-up regularly to minimise loss and restore the service as quickly as possible in the event of an incident.

Where PlanX services rely on integrations with third party data sources (such as Ordnance Survey or planning.data.gov.uk in the case of data), or back-office systems, these are separated. This means Plan✕ is designed to continue to function without that third party data, and failed submissions to back-office systems will be resent once that system comes back online again.
Outage reporting
Customers will be notified of any planned outages by email in advance, and such outages will be timed to minimise disruption. In the event of any unplanned outage, the Customer will be informed as quickly as possible by email or through the community forum.

Identity and authentication

User authentication needed
Yes
User authentication
Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
The Plan✕ editor uses role-based access control for admins and editors. Users will be authenticated using federated identities (e.g. Google or Microsoft vis OAuth 2.0 standard). Attempts to circumvent these restrictions (e.g. via the API) would return an error and the request will be logged.

Third party support channels used by OSL enforce industry standard authentication and require two-factor authentication whenever possible.

An access log is kept centrally, detailing permission levels. Management access by OSL staff is controlled by company Directors. Access to the servers is monitored using third party application services.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
The Plan✕ tech lead is tasked with ensuring OSL security policies are complied with.
Information security policies and processes
The CEO is a Director of OSL and is ultimately responsible for ensuring policies and processes are well-designed and followed. Directors receive a report from the Plan✕ tech lead at Board Meetings. OSL maintains a risk register and issue identification and escalation process. Company procedures are regularly reviewed to ensure best practice compliance.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Whenever possible OSL provisions and manages infrastructure with code using services (such as Terraform). Configurations are stored in a Git repository so we can track changes in version control. All code deployments must pass a suite of Continuous Integration Tests before going live. We tag each build as part of the deployment process.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
OSL uses an automated service to constantly monitor for threats and identify attacks immediately. Whenever possible we intend to keep all dependencies up to date using an automated service (such as Dependabot).
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
OSL uses monitoring tools to help identify potential compromises with reports on server activity and email alerts. All code deployments must pass a suite of Automated Tests before going live.
Incident management type
Supplier-defined controls
Incident management approach
Users can report incidents or issues at any time via email, community forum or in-service feedback. Many incidents may be automatically detected and logged.

We maintain a detailed incident response plan, the purpose of which is to contain the incident, minimise its impact and communicate clearly and quickly. Significant incidents will be reported via community forum and/or email. This reporting will describe the incident, its impact, any relevant evidence, and steps we are taking to respond or prevent it reoccuring in future. Customers can also request reports if they want further information about an incident.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We can provide a trial instance for potential customers to explore and test Plan✕ before subscribing. This may not include all data integrations, and customers will not be able to go live with any services.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
D3d0cd24-8c3a-4f4d-a986-971619cb8072
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
Penetration Testing - Jumpsec

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of issues relating to entering the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at enquiries@opensystemslab.io. Tell them what format you need. It will help if you say what assistive technology you use.