PlanX
Plan✕ is a content management system (CMS) for digital services. It enables local authorities to create, share and operate smart, dynamic-form services that make complex rules easy to navigate. Plan✕ is an open source tool, developed with local authorities and MHCLG. The aim is to make planning simpler for everyone.
Features
- Simple, seamless planning services for applicants and their agents
- Dynamic, 'smart' content that responds to users inputs
- Themed for your council identity
- Responsibly designed AI powered modular components
- Pulls in GIS data from Digital Land API
- Editor interface for content management by planning officers
- Managed service templates for all main planning services
- Accessible-as-standard
- Service analytics and feedback
- Includes shared service content across councils
Benefits
- Makes planning simpler and more transparent for applicants
- Increases user satisfaction and improves accessibility
- Reduces the volume of telephone and email enquiries
- Reduces the number of invalid planning applications
- Reduces application processing time downstream
- Reduces the number of refused/rejected applications
- Gives planning authorities control over their data, services and outcomes
- Allows planning authorities to better understand service usage
- Feedback and analytics reveal where improvements to guidelines are needed
- Ensures consistency of guidance and decisions
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 7 7 6 4 3 7 5 5 2 1 6 9 0 8
Contact
OPEN SYSTEMS LAB LTD
Laura Dewis
Telephone: 0330 229 6250
Email: enquiries@opensystemslab.io
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
The main constraints are:
1. Availability of data (eg GIS) data for planning constraints. Planning authorities will need to publish their GIS data via planning.data.gov.uk
2. Availability of integrations with back-office systems.
3. Customers will need to create a GOV.UK Pay account to receive payments. - System requirements
- Any modern web browser (Chrome, Safari, Edge, Firefox, IE11+)
User support
- Email or online ticketing support
- Yes
- Support response times
-
Email and Slack support for admins only. We will reply within 24 hours.
Urgent issues we will usually respond to more quickly. - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Customer admins can contact us by email or via a community Slack channel to ask questions or report or resolve issues.
Within working hours (Mon-Fri 9am-5pm, excluding bank holidays) we aim to respond to:
Critical issues within 2 working hours and put an at least temporary fix within 24 hours.
Major issues within 8 working hours, and we aim to put in place an at least temporary fix within 5 working days.
Minor issues we aim to respond within 16 working hours, if a reply is appropriate.
Additional support services such as training, co-writing and planning information and data auditing are available for an additional cost (see pricing). We may from time to time also provide these for free to the community, including support drop-ins. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
PlanX supports users in getting started through a structured, hands-on onboarding process designed to help councils move from initial setup to live services efficiently and confidently. Each customer is provided with a detailed onboarding guide, checklist, and progress dashboard, which clearly set out the required steps and allow users to track their onboarding status from start to launch.
The PlanX team works closely with council IT teams, planning officers, and delivery managers to align technical setup, service design, integrations, and governance, ensuring a smooth fit within existing council environments. Users are supported through one-to-one sessions to demonstrate the platform, explain core concepts, and provide practical guidance on using the editor.
Support is ongoing throughout onboarding. The team is available via Slack to answer questions, resolve issues quickly, and provide day-to-day guidance. PlanX also runs setup workshops and facilitates community-driven groups where councils and delivery partners can share knowledge, lessons learned, and best practice. In addition, comprehensive online documentation and training materials are available within the editor, guiding users step by step through service creation and publication. This combination of structured guidance, direct support, and peer learning helps users launch services with confidence and build capability over time. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Admins will be able to export all of the data relating to their Plan✕ services in a structured format (eg csv, json). The API affords flexibility to make custom queries. In the case of data that is available but cannot yet be self-exported, customers can request this data, and it will be made available to them.
- End-of-contract process
- A Council can request to terminate their Plan✕ subscription at any point in line with the termination terms, by notifying their Account Manager by email. They can extract any and all data available via the API, and request reasonable assistance in facilitating this. Any additional assistance – for example, working with a team to help them set up a replacement service – will have a cost based on a reasonable day-rate, to be agreed at the time.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The public-facing elements of the service are accessible on mobile devices and are designed to be responsive, allowing end users to view and complete tasks on smaller screens. Core functionality for creating, configuring, and managing services is provided through an editor interface that is optimised for desktop use. This editor involves complex workflows, detailed configuration, and multi-panel interactions that require larger screens and precise input, making desktop or laptop devices the recommended environment. While mobile access is supported for public use, full administrative and editorial functionality is best experienced on desktop devices to ensure usability, efficiency, and accuracy.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- PlanX provides three service interfaces. The public interface is used by applicants to access planning services online, complete forms, and submit information through a responsive, web-based experience. The editor interface is used by planning officers and service teams to design, configure, and manage planning services, content, and workflows; it is optimised for desktop use due to its complexity. The API interface allows PlanX to integrate with external systems, enabling secure data exchange and interoperability with other local authority or third-party services. Together, these interfaces support end-to-end digital planning delivery while separating public use, service management, and system integration.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
As well as carrying out accessibility audits (around annually, depending on what new features we release) we also have in place a suite of automated accessibility tests. We carry out user testing with users with accessibility needs at any opportunity.
WCAG 2.2 AA or EN 301 549 (last August, 14th 2025) - API
- Yes
- What users can and can't do using the API
-
PlanX has an API that allows users to:
– Access and interrogate the content and structure of digital services
– Request enquiry / application data from the database (if they have permission to do so). - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
PlanX is designed to be highly configurable so customers can tailor services to their local authority needs while using a shared platform.
Customers can customise their PlanX channel with their brand / web theme colours and logo, to provide end users with a clear, seamless experience when navigating from and to other council web pages. You will also need to add a privacy notice and help / contact information for users.
You can also use your own council subdomains. eg planningservices.council.gov.uk
Beyond visual branding, users can customise service content, structure, and behaviour. Through the editor interface, authorised users can create and manage service journeys, update guidance text, configure questions and validation rules, and control how information is presented to applicants. Users can also configure integrations with external systems using supported APIs, enabling data exchange with back-office or third-party services.
Scaling
- Independence of resources
-
Plan✕ procures hosting from AWS (or equivalent) which can scale in response to spikes in user demand.
Data (such as mapping or GIS) that is pulled in from third party sources will, as far as possible, be pulled in from sources that are also able to scale. In the event that demand spikes beyond the scaling capacity of these services, Plan✕ can continue to function independently without these data until demand normalises again.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
– Traffic
– User activity through flows (revealing, for example, the most common enquiry types, balance of responses, and revealing which areas of guidance / policy are proving to be key barriers to users).
Every service on PlanX has a dedicated analytics dashboard showing key analytics about that service. We are also improving our API to allow queries for the purposes of usage analysis. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Admins will be able to export all of the data relating to their Plan✕ services in a structured format (eg csv, json). The API affords flexibility to make custom queries. In the case of data that is available but cannot yet be self-exported, customers can request this data, and it will be made available to them.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- PDF (in the case of documents)
- Data import formats
-
- CSV
- Other
- Other data import formats
- PDF (in the case of documents)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is currently hosted on AWS and therefore benefits from their availability (99.9% uptime) and resilience. In the unlikely event that the PlanX service should go down, our team will be alerted automatically (or by the customer) and seek to restore the service as quickly as possible.
No refunds are currently agreed in the event of service downtime as part of the SLA. - Approach to resilience
-
Alongside the security and load-management measures we have in place, critical data is also backed-up regularly to minimise loss and restore the service as quickly as possible in the event of an incident.
Where PlanX services rely on integrations with third party data sources (such as Ordnance Survey or planning.data.gov.uk in the case of data), or back-office systems, these are separated. This means Plan✕ is designed to continue to function without that third party data, and failed submissions to back-office systems will be resent once that system comes back online again. - Outage reporting
- Customers will be notified of any planned outages by email in advance, and such outages will be timed to minimise disruption. In the event of any unplanned outage, the Customer will be informed as quickly as possible by email or through the community forum.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
-
The Plan✕ editor uses role-based access control for admins and editors. Users will be authenticated using federated identities (e.g. Google or Microsoft vis OAuth 2.0 standard). Attempts to circumvent these restrictions (e.g. via the API) would return an error and the request will be logged.
Third party support channels used by OSL enforce industry standard authentication and require two-factor authentication whenever possible.
An access log is kept centrally, detailing permission levels. Management access by OSL staff is controlled by company Directors. Access to the servers is monitored using third party application services. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- The Plan✕ tech lead is tasked with ensuring OSL security policies are complied with.
- Information security policies and processes
- The CEO is a Director of OSL and is ultimately responsible for ensuring policies and processes are well-designed and followed. Directors receive a report from the Plan✕ tech lead at Board Meetings. OSL maintains a risk register and issue identification and escalation process. Company procedures are regularly reviewed to ensure best practice compliance.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Whenever possible OSL provisions and manages infrastructure with code using services (such as Terraform). Configurations are stored in a Git repository so we can track changes in version control. All code deployments must pass a suite of Continuous Integration Tests before going live. We tag each build as part of the deployment process.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- OSL uses an automated service to constantly monitor for threats and identify attacks immediately. Whenever possible we intend to keep all dependencies up to date using an automated service (such as Dependabot).
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- OSL uses monitoring tools to help identify potential compromises with reports on server activity and email alerts. All code deployments must pass a suite of Automated Tests before going live.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Users can report incidents or issues at any time via email, community forum or in-service feedback. Many incidents may be automatically detected and logged.
We maintain a detailed incident response plan, the purpose of which is to contain the incident, minimise its impact and communicate clearly and quickly. Significant incidents will be reported via community forum and/or email. This reporting will describe the incident, its impact, any relevant evidence, and steps we are taking to respond or prevent it reoccuring in future. Customers can also request reports if they want further information about an incident. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We can provide a trial instance for potential customers to explore and test Plan✕ before subscribing. This may not include all data integrations, and customers will not be able to go live with any services.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- D3d0cd24-8c3a-4f4d-a986-971619cb8072
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- Penetration Testing - Jumpsec
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
-