Xylo Core
Xylo Core is an AI workspace for development management planning officers in local planning authorities. It researches each planning application, drafts the officer report and planning conditions, summarises public comments and answers questions in AI chat, working alongside existing planning systems to boost planning officer capacity and improve decision quality.
Features
- Specialist workspace to streamline development management planning officer caseloads
- Automated planning research: site history, policies, and constraints
- AI-drafted officer report templates based on each planning application's context
- Integrated maps with GIS layers, site history and commenter locations
- AI chat with contextual understanding of the planning application
- AI categorisation and summarisation of public representations and consultee responses
- Verifiable reasoning and sources for all AI suggestions
- Full audit trail of AI and officer actions
- Web-based and compatible with all devices
- AI support for planning conditions drafting and edits
Benefits
- Save up to a day per week per planning officer
- Cut planning officer report writing time by up to 75%
- Reduce planning research time by up to 80%
- Process more planning applications without increasing team headcount
- Reduce determination times and reliance on extensions of time
- Lower appeal and judicial review risk through consistent decisions
- Improve officer satisfaction and support retention
- Onboard new officers faster with guided, pre-populated workflows
- Maintain decision quality during peak application volumes
- Built with 300+ hours of planning officer input
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 3 5 0 7 0 4 1 5 6 1 5 9 8 4
Contact
Xylo
Dermot O'Riordan
Telephone: 07584198840
Email: contact@buildxylo.ai
About the service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Generative AI Software Services
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/A
- System requirements
-
- Internet connection
- Web browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Users are able to raise non-urgent support requests via email. Xylo will respond to all support tickets by the end of the following business day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- The buyer will get a dedicated Xylo Account Manager who owns and manages the account. They will be available for queries via email and phone. They will be present in-person during mobilisation to support set-up. The Account Manager will work alongside Xylo engineers to support technical troubleshooting. Support is provided at no extra cost.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Xylo provides on-site training sessions over a 4 week mobilisation period. Alongside group sessions, Xylo will provide 121 support for caseworkers as needed. All users will be provided with documentation - both text and video - covering set-up, FAQs, and basic troubleshooting.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Xylo Core includes a self-service option to export all written data in a number of different formats. This can be used at any time. At contract conclusion the dedicated Account Manager will support the client to ensure that all data has been extracted by the client. This is provided at no extra cost.
- End-of-contract process
- Xylo will agree a 4 week exit plan with clients concluding their use of the service. The Account Manager will support the client to ensure all data has been extracted from the platform. The Account Manager will share a data deletion plan for removing all client data from Xylo servers in line with GDPR requirements. This is provided at no additional cost.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No difference in functionality. Layout depends on screen size.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Web-based application accessed through modern browsers (Chrome, Edge, Firefox, Safari). Responsive design adapts to screen size. No plugins or software installation required.
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
- Xylo Core provides a RESTful API enabling councils and third-party systems to integrate with our platform. The API supports read and write access to case data, documents, comments, and workflow status - allowing data to flow to and from existing back-office systems. We are committed to open integration and will work with councils to support their data sharing requirements. API scope can be tailored during onboarding
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Report templates can be configured to match council requirements. GIS layers and mapping data tailored to local authority boundaries and datasets. Planning policy documentation specific to each council's Local Plan
Scaling
- Independence of resources
- Xylo Core is hosted on AWS using serverless architecture (Lambda) which scales automatically and instantly in response to demand. There is no fixed capacity - resources are allocated per-request, ensuring one council's usage cannot affect another's performance. Database infrastructure is managed via Supabase with built-in connection pooling and scaling.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Usage metrics include cases processed, reports generated, and time savings achieved. We provide regular performance reviews with stakeholders. Management dashboards for real-time visibility into team productivity and service adoption are also available.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Summaries and case information are copied and pasted by the user from Xylo Core into their internal case management system as needed. Officer reports are downloaded on demand via an ’Export' button. Aggregated data can be exported to CSV or PDF by system administrators.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
-
- CSV
- Other
- Other data import formats
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% uptime target. No refunds are offered.
- Approach to resilience
-
Xylo Core utilises a cloud-native, serverless architecture on AWS (London Region). This ensures automatic high availability and fault tolerance, as compute resources (AWS Lambda) automatically scale across multiple Availability Zones (AZs) to handle load or zone failures without manual intervention.
Database resilience is managed via Supabase (PostgreSQL), utilising Write-Ahead Logging (WAL) for point-in-time recovery and continuous backups. All infrastructure is defined as code (IaC), allowing for rapid disaster recovery and identical environment replication within minutes. - Outage reporting
- System administrators and nominated contacts are notified of confirmed outages via email alerts. We are currently implementing a public status page to provide real-time visibility into system health, API status, and scheduled maintenance windows.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
We restrict access to management interfaces using Role-Based Access Control (RBAC) and the Principle of Least Privilege.
Authentication: Multi-Factor Authentication (MFA) is mandatory for all administrative accounts.
Device Security: Access is restricted to authorised personnel using secure, managed corporate devices.
Monitoring: All privileged activity is logged. We utilise automated alerting to detect and respond to suspicious access attempts or anomalies in real-time.
Review: Access rights are reviewed quarterly and revoked immediately upon staff departure. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- CyberEssentials Plus
- Information security policies and processes
-
Xylo Core operates an Information Security Management System (ISMS) certified to ISO 27001 and Cyber Essentials Plus.
Reporting Structure Dermot, one of the two Co-Founders, retains ultimate authority for security governance (acting as Senior Information Risk Owner). Tim, the CTO, acts as the Information Security Officer (ISO) reports directly to the founders, holding overall responsibility for establishing and monitoring the ISMS, supported by Department Heads who implement controls in their areas.
Policies We maintain a holistic policy suite including Access Control, Asset Management, Risk Assessment, and Incident Management. These align with NCSC Cloud Security Principles and the AWS Shared Responsibility Model.
Compliance & Enforcement We ensure policies are followed through:
Automation: We utilise the Sprinto platform to automate control monitoring and track real-time adherence to procedures.
Audit: We conduct annual internal audits and formal management reviews to verify control effectiveness.
Disciplinary Framework: Compliance is mandatory for all staff. Violations result in formal disciplinary actions ranging from warnings to termination, depending on severity.
Training: Security awareness training is mandatory upon induction and refreshed annually. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We utilise a GitOps methodology. All service components—from infrastructure to AI prompts—are version-controlled in GitHub. This provides a complete audit trail of every change through its lifetime.
Security Impact Assessment:
Automated Testing: CI/CD pipelines execute unit tests and security scans. Braintrust runs regression tests on AI prompts to ensure changes do not degrade output quality or safety.
Peer Review: A mandatory code review by a second engineer is required for all changes.
Staging: Changes are deployed to a segregated environment for integration testing before production. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We assess threats across the full stack:
Code: CI/CD pipelines run automated dependency checks (SCA) on every build.
AI Models: We use Braintrust evaluations to assess our AI models for safety and reliability risks before deployment.
Infrastructure: AWS GuardDuty continuously scans for network and account vulnerabilities.
Information Sources: We monitor NCSC threat alerts, AWS Security Bulletins, and the CVE database. We also rely on internal intelligence from PostHog regarding usage anomalies.
Patching Speed:
Critical Vulnerabilities: We aim to deploy patches within 24 hours of identification.
Infrastructure: As a serverless platform, OS-level patching is handled automatically by AWS. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We identify compromises using a multi-layered stack: AWS GuardDuty for infrastructure threats, Axiom and PostHog for application anomalies, and Braintrust to monitor LLM interactions for prompt injection.
Upon detection, alerts route to engineering. We follow our ISO 27001 Incident Response Plan:
Triage: Verify threat via Axiom.
Contain: Isolate user/key.
Remediate: Deploy fixes via GitHub.
Automated alerts are instant. We acknowledge critical alerts within 4 hours, taking immediate action for high-severity threats. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow a formal Incident Response Plan aligned with ISO 27001, covering the NCSC 4-stage lifecycle: Detection, Analysis, Containment, and Recovery. We have specific playbooks for common events (e.g., service outage, data breach).
Reporting Incidents: Users can report incidents via email or directly through their dedicated Account Manager.
Providing Reports:
During Incident: We provide regular status updates via email to affected users until resolution.
Post-Incident: For major incidents, we produce a formal Root Cause Analysis (RCA) report, detailing the timeline, impact, and preventative actions taken. These are provided to customers upon request. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- Intercert Inc
- ISO/IEC 27001 accreditation date
- Wednesday 1 October 2025
- What the ISO/IEC 27001 doesn’t cover
- Exclusions: IT systems not under Xylo AI Ltd’s management or contractual control. This includes customer-managed systems and environments (for example, customer networks, end-user devices, identity providers or internal back-office systems managed by the customer), and any third-party services not contracted/managed by Xylo for delivery of the service.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 5da21286-82c0-4892-aa31-7d26d4fa4aca
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- 5e7ac434-0e24-4fdf-9ab2-657903e39614
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce