Fleet Management Software
Chevin's Fleet management software solution is offered as a SaaS product. Our fleet management solution is fully web-based and is hosted on the Microsoft Azure Cloud in the UK.
We offer our fleet software product in two options FleetWave Core and FleetWave Advanced.
Features
- An easy to use web-based application.
- The complete lifecycle of vehicles and assets can be managed.
- Hierarchy of access, to reflect the profile of your users.
- Real-time visibility.
- All activity is date and time stamped, providing audit trails.
- Automated bespoke alerts and reminders for key events.
- Consolidates data into a centralised system.
- Easily integrates with 3rd party data sources with no code
- Companion mobile applications for Drivers and Technicians
- Mobile data capture using SmartForms and Driver App
Benefits
- Create, view analytics, and generate graphical reports in real-time.
- Dashboards that can be tailored to individual users.
- Stay organised, efficient, compliant with dashboard reminders at every step.
- Keep everyone connected and informed on their phones, laptops, tablets.
- Monitor drivers, vehicles, workshops and more from one place.
- Keep virtual paperwork in order.
- Grant secure access to colleagues when you need to.
- Keeps up regardless how large your organisation grows.
- Works with an ever growing directory of third-party apps.
- Real-time KPI tracking and analysis.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 5 6 9 0 6 2 8 3 4 7 7 5 3 9
Contact
CHEVIN COMPUTER SYSTEMS LIMITED
Gareth Roulston
Telephone: +44 (0)1773 821992
Email: bidmanagement@chevinfleet.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Asset life-cycle management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- None
- System requirements
-
- Modern web browser
- Internet connection
User support
- Email or online ticketing support
- Yes
- Support response times
-
Chevin provides support during weekday business hours, excluding public holidays. Response times are aligned to issue severity: Critical issues are responded to within 1 business hour, High priority issues within 4 business hours, and Normal priority issues within 12 business hours.
Support is delivered by regional support desks in the UK, US and Australia, allowing coverage to be handed between regions during weekdays and providing near round-the-clock weekday coverage for urgent priority issues. At weekends and public holidays, tickets can still be logged and urgent priority tickets will be responded to when the next regional support window opens. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
During onboarding, on-site support can be provided by Chevin’s project team. This typically includes in-person training, knowledge transfer and floor-walking style support at or around go-live, helping users adopt the system quickly while minimising disruption to day-to-day operations. On-site onboarding support is scoped and costed as part of the professional services engagement, with pricing dependent on duration, location and the Chevin resources required.
Following go-live, customers are supported by Chevin’s dedicated Customer Success Team. This includes on-site strategic business reviews delivered periodically throughout the year, focused on ensuring customers achieve maximum value from their investment, reviewing system usage, identifying optimisation opportunities and aligning future requirements with the FleetWave product roadmap. Customer Success services are included within the SaaS subscription.
Business as usual support, including the resolution of logged support tickets, is provided by Chevin's Support Team. This team does not provide on-site support. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Chevin can provide train-the-trainer sessions, direct end-user training, or a combination of both, depending on customer requirements. Training can be delivered either virtually or onsite.
An extensive range of support materials is available through Chevin’s online support portal, which is accessible to all users. This includes a comprehensive library of written guidance and video content.
All customers are also entitled to attend monthly Ask the Expert sessions, alongside regular live webinars that focus on specific system functionality and fleet management best practices.
Ongoing support is provided by Chevin’s dedicated help desk teams, while the Customer Success team offers proactive, strategic guidance to help customers maximise the value of their investment in the software. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Customers are able to export their data from our system at any time without restriction. This can be done by the customer themselves and does not attract any vendor fees.
Data can be exported in a range of standard formats, including .csv, .txt and .xlsx. - End-of-contract process
- There are no additional exit fees at the end of the contract. Customers have free access to export their data from our systems. Access to our systems will cease on the first day following the contract end date.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
FleetWave, the core application, is primarily designed for desk-based users functionality. It is mobile responsive, allowing access via mobile browsers where required, with screens adapting automatically to different device sizes.
Dedicated Technician and Driver applications are provided for mobile use and are purpose-built for field-based roles. These applications are available as native iOS and Android apps via the relevant app stores and are optimised for touch interaction, offline working where required, and streamlined task-focused workflows. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The service interface is designed for trained professionals within public-sector organisations such as local authorities and emergency services. It is not intended for public or citizen use. Users access the system via a web browser or via an application installed on their mobile device (in the case of our mobile applications).
In addition, interaction with FleetWave is possible from third party applications via an extensive API. API integrations can be managed in system using Smart Integrate, which is a no-code API integration builder. - Accessibility standards
- WCAG 2.2 A
- Accessibility testing
-
Chevin has not yet conducted formal interface testing with external users of assistive technology. Accessibility is addressed through standards-based assessment, with FleetWave currently aligned to WCAG 2.1 A and an active programme underway to achieve WCAG 2.1 AA compliance across the application.
Accessibility considerations are informed by day-to-day input from a visually impaired member of Chevin’s development team, alongside automated and manual accessibility checks. Identified issues are prioritised and addressed through normal change and release processes, with customer feedback also reviewed.
Chevin recognises the value of structured testing with assistive technology users and plans to introduce formal user-based accessibility testing as part of ongoing accessibility improvements. - API
- Yes
- What users can and can't do using the API
-
FleetWave provides API-based integration capabilities through its Smart Integrate platform, enabling users to configure and manage integrations between FleetWave and third-party systems.
Users can set up integrations using a visual, low-code interface to connect FleetWave with external services such as telematics, fuel, maintenance, finance or ERP systems. Through this interface, users can define data sources and targets, map data fields, test connections and schedule automated data exchanges without requiring bespoke development.
Once configured, users can make changes to integrations by updating mappings, schedules or transformation rules, adding or removing data sources, and enabling, pausing or disabling integrations as operational requirements change. These changes are managed directly in FleetWave through the Smart Integrate interface.
API usage is subject to certain limitations. Integration capabilities depend on the APIs and data made available by third-party systems. The platform is designed for configuration of API connections rather than unrestricted custom development. Access to API configuration and changes is also controlled through role-based permissions within FleetWave. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
FleetWave is designed to meet the most common public sector fleet management use cases out of the box. However, the service also supports extensive configuration to allow organisations to tailor it to their specific business processes and workflows.
Customers can customise page layouts, create custom fields and validation rules, configure workflows and status codes, control data visibility by role, define user roles and permissions, configure automated notifications, and tailor reports and dashboards. Forms used within the FleetWave Driver app can also be configured. In addition, customers can set up and manage API integrations with third-party systems using FleetWave’s Smart Integrate no-code integration builder.
Customisation is carried out through FleetWave’s secure, browser-based administration interface using structured configuration screens and visual tools. These changes can be made without bespoke development or access to the underlying infrastructure.
Customisation capabilities are typically restricted to designated system administrators to ensure appropriate governance and control. However, permissions can be configured to allow specific configuration activities to be delegated to other user roles or groups where required.
Scaling
- Independence of resources
- Data is separated in multiple tables within a relational database in Microsoft Azure cloud infrastructure. Each customer has their own independent version of the FleetWave database and application, which is logically secured. Utilising the Azure cloud, the scalability is effectively limitless and can be scaled at will to compensate for unusual circumstances.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Chevin's applications record a comprehensive Access and Audit history which can be used to to analyse system usage and monitor system adoption.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can export their data using in-system tools designed for non-technical users. Export criteria can be defined, including which data points to include on the export and any filtering to be applied.
Data can be export directly from each table (e.g. vehicles) or, for more complex requirements, reports can be exported to include data from more than one source table at a time.
Exports can be produced manually, or delivered automatically by email/sFTP on a set schedule. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Text
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- Text
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Chevin Fleet Solutions, its agents and sub-contractors shall use reasonable endeavours to maintain at least 99% availability of Software as a Service / System per calendar quarter.
- Approach to resilience
-
Chevin’s services are delivered as a fully SaaS-based solution hosted on Microsoft Azure, providing a highly resilient, secure, and scalable platform. Azure is designed for high availability and fault tolerance, with built-in redundancy across power, cooling, networking, and compute infrastructure.
FleetWave is deployed using resilient cloud architecture, ensuring that no single component failure results in service outage. The underlying Azure datacentre environment is protected by multiple layers of physical security, resilient power supplies, and geographically distributed infrastructure. Microsoft Azure datacentres are independently certified to internationally recognised standards, including ISO/IEC 27001, and are subject to regular third-party audits.
Data is protected through automated backups, secure storage, and robust disaster recovery capabilities, allowing services to be restored quickly in the event of an incident. Azure provides continuous monitoring, proactive fault detection, and rapid failover to maintain service availability.
Chevin complements Azure’s platform resilience with formal business continuity and incident management processes, ensuring controlled response, communication, and recovery in the unlikely event of a disruption.
Further detail on datacentre architecture, resilience controls, and recovery objectives is available on request to meet specific assurance or security requirements - Outage reporting
-
Chevin’s service is designed for high availability, and service outages are rare, with historical system uptime consistently exceeding 99%.
Chevin proactively reports any service outages through multiple channels. Our support team receives automatic notifications of any service disruption and will email affected customers to confirm the issue, outline the resolution steps being taken, and provide expected timescales where available.
Service availability and incident status are also published via a public system status dashboard hosted on Site24x7, providing customers with real-time visibility of system health.
At present, outage notifications are provided via email alerts and the public dashboard. An outage notification API is not currently provided.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is strictly controlled using role-based access controls and the principle of least privilege. Administrative access is granted only to authorised personnel whose roles require it and is reviewed regularly.
System access is protected through secure authentication mechanisms, logging, and monitoring to ensure accountability. Support channels, including the support portal and ticketing system, restrict visibility and actions based on user roles, ensuring that customers can access only their own data and requests.
All access is logged and monitored, with activity reviewed to detect unauthorised or inappropriate use, supporting effective operational and security oversight. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Chevin operates a comprehensive Information Security Management System (ISMS) that is certified to ISO/IEC 27001, defining the policies, procedures, and controls used to protect customer data and services.
Information security policies cover areas including access control, data protection, encryption, incident management, change management, vulnerability management, business continuity, and supplier assurance. These policies are formally documented, reviewed regularly, and approved by senior management.
Overall accountability for information security sits with senior leadership, with day-to-day governance and enforcement managed by designated security and IT roles. Security risks, incidents, and compliance matters are escalated through defined reporting lines to ensure appropriate oversight and timely decision-making.
Compliance with security policies is enforced through role-based access controls, secure system configuration, audit logging, and change control processes. Regular risk assessments, internal audits, and third-party audits are performed to verify that controls are operating effectively and that policies are being followed in practice.
All employees receive security awareness training and are required to adhere to information security policies as part of their employment. Any security incidents are managed through a formal incident response process, including investigation, remediation, and communication where required.
These measures ensure that information security is consistently applied across Chevin’s organisation and services. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Chevin operates formal configuration and change management processes in line with our ISO 27001 certification. All service components are version controlled and tracked throughout their lifecycle, from development through testing, release, and retirement. Changes are logged, reviewed, and approved through defined change control procedures.
Each change is assessed for security, stability, and operational impact prior to implementation and tested in controlled environments. FleetWave is continually enhanced, with major releases available quarterly. Customers control when upgrades are applied, and Chevin recommends two optional upgrades per year, delivered in line with the customer’s schedule. - Vulnerability management type
- Undisclosed
- Vulnerability management approach
-
Chevin operates a structured vulnerability management process aligned with ISO 27001 principles. Monthly vulnerability scanning is performed using Bulletproof, with findings reviewed to assess severity, exploitability, and potential service impact.
Vulnerabilities are prioritised using a risk-based approach, with higher-risk issues addressed first. Patch deployment timescales are determined by vulnerability severity, with critical issues remediated as a priority and lower-risk items addressed through planned maintenance or release cycles.
Information on potential threats is obtained from vulnerability scan results, vendor security advisories (including Microsoft Azure), and ongoing security monitoring. Customers retain control over deployment schedules, through liaison with Chevin’s support function. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Chevin operates protective monitoring processes aligned with ISO 27001 and cloud security best practice. Potential compromises are identified through continuous platform monitoring, security logging, alerting, and third-party security tooling across the hosted environment.
Alerts are reviewed by technical and support teams to assess impact and severity. Where a potential compromise is identified, Chevin follows a formal incident response process, including investigation, containment, remediation, and customer communication where required.
Incident response actions are prioritised by risk, with critical security incidents addressed immediately and escalated through defined reporting lines to ensure rapid investigation and resolution. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Chevin operates formal, documented incident management processes aligned with ISO 27001 and cloud security best practice. Pre-defined procedures are in place for common incident types, including service disruption, security events, and data-related issues, ensuring a consistent and controlled response.
Users report incidents via Chevin’s support portal or support desk, where incidents are logged, categorised, and prioritised based on severity and impact. Incidents are actively managed through investigation, remediation, and resolution, with escalation where required.
On resolution, customers are provided with incident summaries outlining the issue, root cause, actions taken, and any follow-up measures, ensuring transparency and continuous improvement. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Access can be granted to a trial system where the users can access all FleetWave (and moible app) functionality. Trial periods are time limited and duration will be agreed with Chevin's Account Executive, depending on requirements.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Tuesday 18 September 2012
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Tuesday 18 September 2012
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Working conditions which promote an inclusive working environment and promote retention and progression
-