Skip to main content

Help us improve the Digital Marketplace - send your feedback

THUMBMUNKEYS LTD

Visibeat

Cloud-based operational policing platform for UK police forces. Supports evidence-based hotspot policing including Koper patrols with real-time officer tracking, geofenced patrol management, and command & control capabilities. Features activity heatmaps, mobile field app, and comprehensive audit logging. UK hosted with configurable data retention policies.

Features

  • Real-time GPS officer tracking with 2-10 second updates
  • Geofenced patrol zones with automatic entry and exit detection
  • Koper hotspot patrol timing and compliance monitoring
  • Interactive command dashboard with live mapping
  • Native Android mobile app with offline capability
  • Activity heatmaps for evidence-based deployment decisions
  • Role-based access control with need-to-know security
  • UK hosted with configurable data retention policies

Benefits

  • Reduce response times by instantly locating nearest available officers
  • Optimise patrol coverage with data-driven deployment decisions
  • Eliminate manual patrol logging through automatic geofence detection
  • Maintain real-time situational awareness across entire force area
  • Ensure patrol compliance with automated Koper timing alerts
  • Deploy officers instantly with commands delivered under 2 seconds
  • Access complete audit trails for investigations and legal proceedings
  • Monitor multiple teams simultaneously from single command dashboard
  • Continue field operations offline with automatic data synchronisation
  • Evidence patrol activity for community reassurance and accountability

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at mark@thumbmunkeys.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 8 0 2 2 0 6 8 6 0 0 3 9 4 9

Contact

THUMBMUNKEYS LTD Mark Bryan
Telephone: 07476296450
Email: mark@thumbmunkeys.com

About the service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Police
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Requires deployment on force-managed infrastructure within VPN or DMZ environment. Microsoft SQL Server 2016+ required (2022 recommended). Active Directory integration required for user authentication. GPS-enabled mobile devices needed for officer tracking. Force must provide Google Play Console account for private app distribution. SSL/TLS certificates required for API and dashboard. Supported server OS: Debian 11+, Oracle Linux 7+, or RHEL 7+. Two virtual machines required (application server and database server). Internet connectivity required for initial login and token refresh; full offline capability for daily operations.
System requirements
  • Microsoft SQL Server 2016 or later (2022 recommended)
  • Application server: 4 vCPUs, 8GB RAM, 100GB SSD minimum
  • Database server: 4 vCPUs, 32GB RAM, 1TB SSD minimum
  • Debian 11+, Oracle Linux 7+, or RHEL 7+ operating system
  • Active Directory for user authentication and officer import
  • VPN or DMZ protected network environment
  • SSL/TLS certificates for API and dashboard endpoints
  • Google Play Console account for mobile app distribution
  • GPS-enabled mobile devices for field officers

User support

Email or online ticketing support
Yes
Support response times
Support requests received during business hours (Monday to Friday, 9am-5pm) are acknowledged within 4 hours and responded to within 1 business day. Critical issues affecting operational capability are prioritised and addressed within 4 hours. Weekend and bank holiday support is available for critical issues by prior arrangement. Response times may vary for non-urgent queries during peak periods.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Standard Support is included with all licences. This provides 3rd line application support during business hours (Monday to Friday, 9am-5pm UK time excluding bank holidays). Support includes ticket-based incident management, proactive application monitoring, quarterly software updates, and a designated Service Delivery Manager for the account. Response times are tiered by priority: critical issues (P1) receive 1-hour response with 4-hour restoration target; high priority (P2) 1-hour response with 8-hour restoration; medium (P3) 4-hour response; low priority (P4) 8-hour response. Out-of-hours urgent support is available by prior arrangement at additional cost based on time and materials.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Deployment includes initial system configuration, Active Directory integration, application branding, and mobile app distribution setup. Remote training sessions are provided for command staff and administrators covering dashboard operation, patrol zone creation, team management, and reporting. Onsite training is available at additional cost. User documentation is provided including administrator guides and end-user reference materials. A designated Service Delivery Manager supports the customer through go-live and initial operational period.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data is held on the customer's own infrastructure throughout the contract. Customers have direct access to the SQL Server database and can extract data at any time using standard database tools and queries. At contract end, all data remains on the customer's systems. Thumbmunkeys can provide data schema documentation and extraction support on request. No data is held on Thumbmunkeys systems requiring transfer or retrieval.
End-of-contract process
At contract end, all data remains on the customer's own infrastructure with full database access retained. Customers can extract data at any time using standard SQL Server tools. Data schema documentation is available to support migration to alternative systems. Transition support and migration assistance are available at additional cost if required.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Documentation is provided in HTML and PDF formats. HTML documentation supports standard browser accessibility features including text resizing and screen reader compatibility. PDF documents can be provided in alternative formats on request to meet specific accessibility requirements.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • Linux or Unix
  • MacOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile app (Android) is designed for field officers and provides GPS location transmission, geofence entry/exit notifications, command receipt, and offline operation capability. The desktop browser interface is designed for command staff and supervisors, providing real-time officer tracking on interactive maps, patrol zone management, activity heatmaps, team administration, and comprehensive audit log access. Both interfaces connect to the same backend and data is synchronised in real-time. The mobile app prioritises battery efficiency and reliable operation in areas with intermittent connectivity.
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
Yes
Description of customisation
What can be customised: Application branding (logos, colour schemes), patrol zone definitions (geofence boundaries, timing parameters), team hierarchies and command structures, user roles and permissions, data retention periods, and alert thresholds for patrol compliance monitoring.
How users customise: Administrators configure settings through the web dashboard interface. Patrol zones are created using interactive mapping tools. Branding and initial configuration are applied during deployment.
Who can customise: Force administrators can manage day-to-day configuration including zones, teams, and users. Initial branding and system-level settings are configured by Thumbmunkeys during deployment and can be modified through change requests.

Scaling

Independence of resources
Each customer deployment is fully isolated on dedicated infrastructure managed by the customer. There is no shared tenancy or shared resources between organisations. Each force operates their own independent instance of the application on their own servers, ensuring complete resource isolation and no performance impact from other users of the service.

Analytics

Service usage metrics
Yes
Metrics types
Usage metrics available include patrol activity reports, officer tracking statistics, geofence compliance rates, and activity heatmaps. Audit logs provide detailed records of system access and user activity.
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
Never
Protecting data at rest
Other
Other data at rest protection approach
Data is stored on customer-managed infrastructure. Physical access controls and storage encryption are managed by the customer in accordance with their own security policies and datacentre standards. Application-level access controls and audit logging protect data from unauthorised access.
Data sanitisation process
No
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Data is held on the customer's own SQL Server database throughout the contract. Customers have direct database access and can export data at any time using standard SQL Server tools, queries, or reporting applications of their choice. Common export formats include CSV, Excel, and direct database connections for integration with other systems. No dependency on supplier involvement for routine data extraction.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • XML
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Customer data is held on customer-managed infrastructure, not on supplier networks. Internal support tools use TLS encryption

Availability and resilience

Guaranteed availability
The service is deployed on customer-managed infrastructure. System availability is dependent on the customer's hosting environment, network, and infrastructure resilience. Thumbmunkeys provides support SLAs for incident response: critical issues (P1) receive 1-hour response with 4-hour target restoration; high priority issues (P2) receive 1-hour response with 8-hour target restoration during business hours. Support is available Monday to Friday, 9am-5pm UK time, with out-of-hours urgent support available by arrangement. Availability refunds are not applicable as the service is not hosted by Thumbmunkeys.
Approach to resilience
The service is deployed on customer-managed infrastructure with resilience configured according to customer requirements. Application-level resilience includes mobile app offline capability allowing field officers to continue operations during connectivity loss, with automatic data synchronisation when connection is restored. The application supports deployment across staging and production environments enabling testing before updates are applied. Database backup and disaster recovery are managed by the customer as part of their infrastructure responsibilities. Guidance on recommended backup procedures and system recovery is available on request. Infrastructure resilience details are specific to each customer deployment.
Outage reporting
The service is deployed on customer-managed infrastructure. Customers monitor their own system availability through their existing infrastructure monitoring tools. Thumbmunkeys provides proactive application monitoring and reports any detected issues directly to the customer's nominated support contacts via email. Monthly service reports summarise any incidents and system performance. Critical issues identified through application monitoring are communicated immediately to nominated customer contacts. A public status dashboard is not applicable as each deployment is independent and customer-specific.

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Management interface access is controlled through role-based access control integrated with customer Active Directory. Administrative functions are restricted to authorised users assigned appropriate roles. User permissions are managed by customer administrators through the dashboard. Support channel access is restricted to nominated customer representatives who are authorised to raise tickets. Remote support access to customer systems requires explicit customer authorisation and is provided via VPN or secure connection as specified by the customer. Support staff hold appropriate vetting (NPPV) for access to police systems. All access and administrative actions are recorded in the application audit log.
Access restriction testing frequency
At least once a year
Management access authentication
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance follows practices established during previous ISO 27001 and ISO 9001 certification. Security policies and procedures remain in place covering access control, data protection, incident management, and secure development practices. Staff are trained in security awareness and handling of sensitive law enforcement data. Application development follows secure coding practices with code review and testing before release. Customer data is held exclusively on customer-managed infrastructure with no data transferred to supplier systems. Security practices are reviewed regularly and updated in response to emerging threats and customer requirements.
Information security policies and processes
Security policies and processes are based on practices established during previous ISO 27001 certification. The directors maintain responsibility for information security with regular review of policies and practices. Key controls include: role-based access control for all systems including code repositories and customer environments; secure development practices with code review and testing prior to release; encrypted devices and secure authentication for all staff; incident response procedures for security events; data handling procedures ensuring customer information is protected. Security awareness is maintained through ongoing training and review. Policies are reviewed annually and updated as required.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
They may ask you to describe these. Draft response:

Configuration and change management follows established internal processes. Source code is managed through version control with all changes tracked and attributed. Code changes require review before merging to main branches. Releases follow a defined process including testing in staging environments before production deployment. Quarterly consolidated software updates are provided to customers with changelogs documenting all changes. Customer deployments are documented with configuration records maintained. Change requests from customers follow a formal process including feasibility review, written specification, and customer approval before development begins.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Security vulnerabilities identified during development or testing are assessed and remediated based on severity. Critical vulnerabilities affecting system security or data protection are prioritised for immediate remediation and deployed as emergency updates. Non-critical security improvements are included in quarterly software releases. Information about potential threats is gathered from development framework security advisories (.NET, Android), industry publications, and customer-reported issues. Customer infrastructure security (server patching, network security) is managed by the customer as part of their operational responsibilities.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Application monitoring is provided through mobile analytics tracking application errors and performance. The application includes comprehensive audit logging recording user access and activity for security review. Customer infrastructure monitoring (server logs, intrusion detection) is managed by the customer as part of their operational responsibilities. Security events identified through monitoring are investigated and addressed through the incident management process.
Incident management type
Supplier-defined controls
Incident management approach
Incident management follows a defined process with tiered priority classification. Incidents are logged through the service management tool and triaged by severity: P1 (system unavailable) receives 1-hour response with 4-hour restoration target; P2 (partially unavailable) receives 1-hour response with 8-hour restoration target; P3 (inconvenient to use) receives 4-hour response; P4 (no operational impact) receives 8-hour response. Incidents requiring code changes are escalated to Problem Records for investigation and resolution. Root cause analysis is performed and documented for significant incidents. A designated Service Delivery Manager maintains communication with the customer throughout incident lifecycle. Monthly service reports summarise incident activity and resolutions.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
12%
Over £5,000,001
15%

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce

Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

  • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at mark@thumbmunkeys.com. Tell them what format you need. It will help if you say what assistive technology you use.