Visibeat
Cloud-based operational policing platform for UK police forces. Supports evidence-based hotspot policing including Koper patrols with real-time officer tracking, geofenced patrol management, and command & control capabilities. Features activity heatmaps, mobile field app, and comprehensive audit logging. UK hosted with configurable data retention policies.
Features
- Real-time GPS officer tracking with 2-10 second updates
- Geofenced patrol zones with automatic entry and exit detection
- Koper hotspot patrol timing and compliance monitoring
- Interactive command dashboard with live mapping
- Native Android mobile app with offline capability
- Activity heatmaps for evidence-based deployment decisions
- Role-based access control with need-to-know security
- UK hosted with configurable data retention policies
Benefits
- Reduce response times by instantly locating nearest available officers
- Optimise patrol coverage with data-driven deployment decisions
- Eliminate manual patrol logging through automatic geofence detection
- Maintain real-time situational awareness across entire force area
- Ensure patrol compliance with automated Koper timing alerts
- Deploy officers instantly with commands delivered under 2 seconds
- Access complete audit trails for investigations and legal proceedings
- Monitor multiple teams simultaneously from single command dashboard
- Continue field operations offline with automatic data synchronisation
- Evidence patrol activity for community reassurance and accountability
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 8 0 2 2 0 6 8 6 0 0 3 9 4 9
Contact
THUMBMUNKEYS LTD
Mark Bryan
Telephone: 07476296450
Email: mark@thumbmunkeys.com
About the service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Police
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Requires deployment on force-managed infrastructure within VPN or DMZ environment. Microsoft SQL Server 2016+ required (2022 recommended). Active Directory integration required for user authentication. GPS-enabled mobile devices needed for officer tracking. Force must provide Google Play Console account for private app distribution. SSL/TLS certificates required for API and dashboard. Supported server OS: Debian 11+, Oracle Linux 7+, or RHEL 7+. Two virtual machines required (application server and database server). Internet connectivity required for initial login and token refresh; full offline capability for daily operations.
- System requirements
-
- Microsoft SQL Server 2016 or later (2022 recommended)
- Application server: 4 vCPUs, 8GB RAM, 100GB SSD minimum
- Database server: 4 vCPUs, 32GB RAM, 1TB SSD minimum
- Debian 11+, Oracle Linux 7+, or RHEL 7+ operating system
- Active Directory for user authentication and officer import
- VPN or DMZ protected network environment
- SSL/TLS certificates for API and dashboard endpoints
- Google Play Console account for mobile app distribution
- GPS-enabled mobile devices for field officers
User support
- Email or online ticketing support
- Yes
- Support response times
- Support requests received during business hours (Monday to Friday, 9am-5pm) are acknowledged within 4 hours and responded to within 1 business day. Critical issues affecting operational capability are prioritised and addressed within 4 hours. Weekend and bank holiday support is available for critical issues by prior arrangement. Response times may vary for non-urgent queries during peak periods.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Standard Support is included with all licences. This provides 3rd line application support during business hours (Monday to Friday, 9am-5pm UK time excluding bank holidays). Support includes ticket-based incident management, proactive application monitoring, quarterly software updates, and a designated Service Delivery Manager for the account. Response times are tiered by priority: critical issues (P1) receive 1-hour response with 4-hour restoration target; high priority (P2) 1-hour response with 8-hour restoration; medium (P3) 4-hour response; low priority (P4) 8-hour response. Out-of-hours urgent support is available by prior arrangement at additional cost based on time and materials.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Deployment includes initial system configuration, Active Directory integration, application branding, and mobile app distribution setup. Remote training sessions are provided for command staff and administrators covering dashboard operation, patrol zone creation, team management, and reporting. Onsite training is available at additional cost. User documentation is provided including administrator guides and end-user reference materials. A designated Service Delivery Manager supports the customer through go-live and initial operational period.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Data is held on the customer's own infrastructure throughout the contract. Customers have direct access to the SQL Server database and can extract data at any time using standard database tools and queries. At contract end, all data remains on the customer's systems. Thumbmunkeys can provide data schema documentation and extraction support on request. No data is held on Thumbmunkeys systems requiring transfer or retrieval.
- End-of-contract process
- At contract end, all data remains on the customer's own infrastructure with full database access retained. Customers can extract data at any time using standard SQL Server tools. Data schema documentation is available to support migration to alternative systems. Transition support and migration assistance are available at additional cost if required.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation is provided in HTML and PDF formats. HTML documentation supports standard browser accessibility features including text resizing and screen reader compatibility. PDF documents can be provided in alternative formats on request to meet specific accessibility requirements.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile app (Android) is designed for field officers and provides GPS location transmission, geofence entry/exit notifications, command receipt, and offline operation capability. The desktop browser interface is designed for command staff and supervisors, providing real-time officer tracking on interactive maps, patrol zone management, activity heatmaps, team administration, and comprehensive audit log access. Both interfaces connect to the same backend and data is synchronised in real-time. The mobile app prioritises battery efficiency and reliable operation in areas with intermittent connectivity.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
What can be customised: Application branding (logos, colour schemes), patrol zone definitions (geofence boundaries, timing parameters), team hierarchies and command structures, user roles and permissions, data retention periods, and alert thresholds for patrol compliance monitoring.
How users customise: Administrators configure settings through the web dashboard interface. Patrol zones are created using interactive mapping tools. Branding and initial configuration are applied during deployment.
Who can customise: Force administrators can manage day-to-day configuration including zones, teams, and users. Initial branding and system-level settings are configured by Thumbmunkeys during deployment and can be modified through change requests.
Scaling
- Independence of resources
- Each customer deployment is fully isolated on dedicated infrastructure managed by the customer. There is no shared tenancy or shared resources between organisations. Each force operates their own independent instance of the application on their own servers, ensuring complete resource isolation and no performance impact from other users of the service.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Usage metrics available include patrol activity reports, officer tracking statistics, geofence compliance rates, and activity heatmaps. Audit logs provide detailed records of system access and user activity.
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Never
- Protecting data at rest
- Other
- Other data at rest protection approach
- Data is stored on customer-managed infrastructure. Physical access controls and storage encryption are managed by the customer in accordance with their own security policies and datacentre standards. Application-level access controls and audit logging protect data from unauthorised access.
- Data sanitisation process
- No
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
- Data is held on the customer's own SQL Server database throughout the contract. Customers have direct database access and can export data at any time using standard SQL Server tools, queries, or reporting applications of their choice. Common export formats include CSV, Excel, and direct database connections for integration with other systems. No dependency on supplier involvement for routine data extraction.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- XML
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Customer data is held on customer-managed infrastructure, not on supplier networks. Internal support tools use TLS encryption
Availability and resilience
- Guaranteed availability
- The service is deployed on customer-managed infrastructure. System availability is dependent on the customer's hosting environment, network, and infrastructure resilience. Thumbmunkeys provides support SLAs for incident response: critical issues (P1) receive 1-hour response with 4-hour target restoration; high priority issues (P2) receive 1-hour response with 8-hour target restoration during business hours. Support is available Monday to Friday, 9am-5pm UK time, with out-of-hours urgent support available by arrangement. Availability refunds are not applicable as the service is not hosted by Thumbmunkeys.
- Approach to resilience
- The service is deployed on customer-managed infrastructure with resilience configured according to customer requirements. Application-level resilience includes mobile app offline capability allowing field officers to continue operations during connectivity loss, with automatic data synchronisation when connection is restored. The application supports deployment across staging and production environments enabling testing before updates are applied. Database backup and disaster recovery are managed by the customer as part of their infrastructure responsibilities. Guidance on recommended backup procedures and system recovery is available on request. Infrastructure resilience details are specific to each customer deployment.
- Outage reporting
- The service is deployed on customer-managed infrastructure. Customers monitor their own system availability through their existing infrastructure monitoring tools. Thumbmunkeys provides proactive application monitoring and reports any detected issues directly to the customer's nominated support contacts via email. Monthly service reports summarise any incidents and system performance. Critical issues identified through application monitoring are communicated immediately to nominated customer contacts. A public status dashboard is not applicable as each deployment is independent and customer-specific.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Management interface access is controlled through role-based access control integrated with customer Active Directory. Administrative functions are restricted to authorised users assigned appropriate roles. User permissions are managed by customer administrators through the dashboard. Support channel access is restricted to nominated customer representatives who are authorised to raise tickets. Remote support access to customer systems requires explicit customer authorisation and is provided via VPN or secure connection as specified by the customer. Support staff hold appropriate vetting (NPPV) for access to police systems. All access and administrative actions are recorded in the application audit log.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance follows practices established during previous ISO 27001 and ISO 9001 certification. Security policies and procedures remain in place covering access control, data protection, incident management, and secure development practices. Staff are trained in security awareness and handling of sensitive law enforcement data. Application development follows secure coding practices with code review and testing before release. Customer data is held exclusively on customer-managed infrastructure with no data transferred to supplier systems. Security practices are reviewed regularly and updated in response to emerging threats and customer requirements.
- Information security policies and processes
- Security policies and processes are based on practices established during previous ISO 27001 certification. The directors maintain responsibility for information security with regular review of policies and practices. Key controls include: role-based access control for all systems including code repositories and customer environments; secure development practices with code review and testing prior to release; encrypted devices and secure authentication for all staff; incident response procedures for security events; data handling procedures ensuring customer information is protected. Security awareness is maintained through ongoing training and review. Policies are reviewed annually and updated as required.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
They may ask you to describe these. Draft response:
Configuration and change management follows established internal processes. Source code is managed through version control with all changes tracked and attributed. Code changes require review before merging to main branches. Releases follow a defined process including testing in staging environments before production deployment. Quarterly consolidated software updates are provided to customers with changelogs documenting all changes. Customer deployments are documented with configuration records maintained. Change requests from customers follow a formal process including feasibility review, written specification, and customer approval before development begins. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Security vulnerabilities identified during development or testing are assessed and remediated based on severity. Critical vulnerabilities affecting system security or data protection are prioritised for immediate remediation and deployed as emergency updates. Non-critical security improvements are included in quarterly software releases. Information about potential threats is gathered from development framework security advisories (.NET, Android), industry publications, and customer-reported issues. Customer infrastructure security (server patching, network security) is managed by the customer as part of their operational responsibilities.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Application monitoring is provided through mobile analytics tracking application errors and performance. The application includes comprehensive audit logging recording user access and activity for security review. Customer infrastructure monitoring (server logs, intrusion detection) is managed by the customer as part of their operational responsibilities. Security events identified through monitoring are investigated and addressed through the incident management process.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management follows a defined process with tiered priority classification. Incidents are logged through the service management tool and triaged by severity: P1 (system unavailable) receives 1-hour response with 4-hour restoration target; P2 (partially unavailable) receives 1-hour response with 8-hour restoration target; P3 (inconvenient to use) receives 4-hour response; P4 (no operational impact) receives 8-hour response. Incidents requiring code changes are escalated to Problem Records for investigation and resolution. Root cause analysis is performed and documented for significant incidents. A designated Service Delivery Manager maintains communication with the customer throughout incident lifecycle. Monthly service reports summarise incident activity and resolutions.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce