Pro-Cloud Ambulance
Pro-Cloud Ambulance is a cloud-based operational platform designed to automate and manage critical ambulance service processes. It provides real-time tracking of assets, inventory, and equipment, digitises maintenance and stock workflows, ensures compliance with medical guidelines, and improves readiness, coordination, and resource efficiency for ambulance operations and patient care teams.
Features
- Real-time asset and equipment tracking across ambulance operations.
- Mobile app access for Android and iOS field updates.
- Automated stock replenishment triggers based on minimum levels.
- Maintenance task scheduling with automated service reminders.
- Inventory scanning using RFID, barcode, and QR technology.
- Catalogue management centralises diverse clinical and consumable items.
- Business intelligence reporting with custom dashboards and analytics.
- Audit trail captures movement and status of every asset.
- Make Ready module automates vehicle preparation workflows.
- Expiry and recall alerting for medicines and consumables.
Benefits
- Access asset and stock information instantly from any location.
- Reduce vehicle downtime through automated maintenance reminders.
- Prepare ambulances faster using streamlined Make Ready workflows.
- Maintain clinical compliance with automated audit trails.
- Improve stock accuracy with real-time inventory visibility.
- Reduce waste by tracking expiries and recalls automatically.
- Update records on the move using mobile devices.
- Ensure equipment availability through proactive asset monitoring.
- Simplify inspections by digitising checks and documentation.
- Improve operational efficiency by centralising ambulance workflows.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 3 6 4 2 5 2 8 9 7 1 8 4 6 8
Contact
CSS EUROPE LIMITED
Emma Strain
Telephone: 08448794531
Email: emma.strain@csseurope.co.uk
About your service
- Service categories
-
Applications
Supply chain management
- Supply chain planning
- Warehousing and inventory management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Not applicable.
- System requirements
- Access to the internet.
User support
- Email or online ticketing support
- Yes
- Support response times
- First response within 10 minutes.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We offer three support levels: Basic, Standard, and Premium.
Basic Support is included in the subscription and provides up to 10 incidents per month, one named contact, access to online self-help resources, and helpdesk case submission during Monday–Friday business hours, with an initial response time of 1–3 business days.
Standard Support is available at an additional cost (pricing on request). It includes unlimited incidents, two named contacts, next business day response times, telephone technical setup support, remote assistance, configuration setup support, enterprise setup support, and support for custom web services and third-party integrations during Monday–Friday business hours.
Premium Support pricing is detailed in the pricing documentation. It includes unlimited incidents, six named contacts, extended support hours (7 days, 7am–8pm GMT), a four-hour response time, priority case handling, Power BI report assistance, webinars and telephone consultations, logical and physical platform separation, and technical support for third-party hosted solutions. Premium Support includes a dedicated Technical Account Manager. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We support users in starting to use our service through a structured, phased onboarding and training approach designed to ensure confident adoption and long-term success. From the outset, customers are provided with a comprehensive Project Pack, which outlines the full implementation journey, key milestones, roles, responsibilities, and what to expect at each stage. This is introduced during a formal project handover and kick-off meeting, ensuring alignment and clarity before delivery begins.
Training is delivered during a dedicated Training and User Acceptance Testing phase and is tailored to user roles. We provide both digital and, where required, onsite training sessions. Designated “Champions” or super users receive in-depth training first, enabling them to support and train wider teams internally. This approach helps embed best practices and builds internal capability across the organisation.
Users also gain access to a “Learn” environment, allowing them to practice real-world scenarios in a safe test system before go-live. Comprehensive user documentation, including user guides and workflow instructions, is provided to support day-to-day use and reinforce learning.
Following go-live, users benefit from ongoing support, including access to a dedicated helpdesk and a structured handover to business-as-usual support, ensuring continued confidence, stability, and effective use of the service. - Service documentation
- Yes
- Documentation formats
- Other
- Other documentation formats
- Online
- End-of-contract data extraction
-
At the end of the contract, users are supported through a structured and controlled data extraction process to ensure continuity and data ownership. Upon request, we work with the customer to agree the scope, format, and timing of the data extract. This typically includes all relevant system data such as asset records, stock information, user data, audit history, and reports.
Data is exported in commonly used, open formats (such as CSV or Excel) to ensure it can be easily accessed, reviewed, and imported into alternative systems if required. Where appropriate, supporting documentation is provided to explain data structures and field definitions, helping users interpret the extracted data accurately.
The extraction process is carried out in line with data protection and security requirements to ensure confidentiality and integrity throughout. Once the data has been successfully transferred and confirmed by the customer, system access is decommissioned in line with contractual and data retention policies.
If required, professional services support can be provided to assist with more complex data extraction requirements or transition planning, ensuring a smooth and controlled exit from the service. - End-of-contract process
-
At the end of the contract, the service is formally closed in a structured and controlled manner to ensure continuity, transparency, and data ownership. Users may request a data extract of their system information, including assets, stock, audit history, and related records. Where data is extracted using the standard system templates and in the same format in which it was originally imported, this extraction is included within the contract at no additional cost.
If users require data to be extracted in a different format, mapped to bespoke structures, or tailored for migration into another system, this is considered a custom data extract. Custom extraction requests may involve additional data transformation, validation, or consultancy effort and are therefore chargeable.
Once data extraction has been completed and confirmed, system access is decommissioned in line with contractual terms and data protection requirements. Any retained data is handled according to agreed retention and deletion policies.
The contract price includes standard system access for the agreed term, user documentation, and the ability to export data via standard templates. Additional costs only apply where users request non-standard, customised data outputs or enhanced transition support beyond the standard offboarding process. - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No difference.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AAA
- API
- Yes
- What users can and can't do using the API
- Multiple API options.
- API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Pro-Cloud Bluelight has multiple flags within the contract settings allowing users to customize the software to their contract.
Scaling
- Independence of resources
- We guarantee independence of resources through a fully scalable architecture designed to ensure consistent performance for all users, regardless of overall demand. The systems are built to scale both vertically and horizontally, allowing capacity to be increased as usage grows or during peak periods. Continuous monitoring tools track key resource metrics such as CPU, memory, and storage, with automated alerts to CSS IT and hosting provider teams when thresholds are approached. This enables proactive capacity management and timely scaling, ensuring that increased demand from one user does not negatively impact the performance or experience of other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide service metrics through our online ticketing system and regular service reporting. All support requests are logged, tracked, and managed within the ticketing system, allowing us to monitor volumes, priorities, response times, resolution times, and escalation activity. These metrics are used to measure performance against agreed service levels and identify trends or recurring issues. Monthly account reports are automatically sent to customers, providing visibility of support activity, service performance, and any key observations or improvement actions. This approach ensures transparency, accountability, and continuous improvement in the delivery of our support services.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data using built-in reporting and business intelligence (BI) tools within the service. These tools allow users to generate reports across key data areas, apply filters, and tailor outputs to their operational needs. Reports can be exported in commonly used formats such as CSV or Excel, enabling easy analysis, sharing, or archiving of data outside the system. This self-service capability ensures users retain access to their information throughout the contract, supports data ownership.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee a high level of service availability for our online services, underpinned by a formal Service Level Agreement (SLA). We commit to 99.9% availability for our core services, including Pro-Cloud™, TCES Community™, TCES Connections™, TCES Configurator™, and Pro-Cloud Bluelight™ solutions. In addition, we guarantee 99.9% availability for Power BI Embedded, enabling users to reliably execute API calls and access embedded reports.
Availability is measured on a monthly basis using a clearly defined uptime calculation, excluding planned and scheduled maintenance. Downtime is recorded only where a service is unavailable for fifteen consecutive minutes or more.
If we fail to meet the guaranteed availability levels in any applicable monthly period, customers may be eligible for service credits. Where monthly uptime falls below 99.9%, a 10% credit of the applicable monthly service fees may be applied. If availability falls below 99%, the service credit increases to 25%. Service credits are applied to future invoices following validation of a claim submitted within the defined timescales.
Service credits are the sole remedy for availability failures and are capped at the value of the affected monthly service fees. This SLA provides transparency, accountability, and assurance that service availability is actively monitored and managed. - Approach to resilience
- Available on request.
- Outage reporting
-
Our service reports outages through a combination of public visibility and direct customer communication. We provide a publicly accessible status page and dashboard, available via a dedicated URL, which displays current service availability and historical uptime information. This allows customers and stakeholders to independently check service status at any time.
In the event of a service outage or service degradation, customers are proactively informed through in-application notifications and email alerts. These updates provide clear information on the nature of the issue, its impact, and progress towards resolution. Once service is restored, follow-up communications are issued to confirm resolution and provide reassurance
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- SSO.
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is strictly controlled to protect our services. Full administrative and management interfaces are restricted to authorised CSS staff only and protected using role-based access control, least-privilege principles, and multi-factor authentication. Access is approved, logged, and reviewed regularly.
CSS staff and customers access services through limited interfaces that provide only the functionality required for their role. These interfaces prevent access to underlying management systems and sensitive configurations. Support channels, including the ticketing system, are restricted to authorised users, with role-based permissions and audit logging in place to monitor access and detect unauthorised activity. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- SSO
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
We operate a formal Information Security Management System (ISMS aligned with ISO/IEC 27001 and Cyber Essentials Plus, ensuring the confidentiality, integrity, and availability of information.
Our policies include an overarching Information Security Policy supported by policies for risk management, access control, acceptable use, asset management, incident management, supplier security, business continuity, and data protection. All policies are approved by senior management, reviewed at least annually, and updated to reflect changes in risk, technology, or regulation.
Key processes include regular risk assessments and treatment, role-based access control with least-privilege principles, multi-factor authentication, vulnerability management, patching, and security monitoring. We maintain defined incident response procedures covering detection, reporting, investigation, escalation, and lessons learned. Third-party suppliers are assessed for security risks and managed through contractual controls.
Overall accountability for information security rests with senior management. Day-to-day responsibility for implementing and maintaining the ISMS is assigned to a designated Information Security Lead, who reports regularly on risks, incidents, audit findings, and compliance.
Compliance with policies is ensured through mandatory staff training, ongoing security awareness, technical controls, internal audits, and management reviews. Non-compliance is addressed through corrective actions, supporting continual improvement of our security posture. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
We maintain formal configuration and change management processes aligned with ISO/IEC 27001.
All service components, including infrastructure, applications, and endpoints, are recorded in a controlled asset and configuration register. Each component has an assigned owner and is tracked throughout its lifecycle from deployment to secure decommissioning. Secure configuration baselines are defined and maintained.
All changes are managed through a documented change process. Proposed changes are logged, assessed&approved by the Information Security Panel before implementation. Each change includes an assessment of potential security impact, including access controls, data protection, availability, and compliance. Post implementation reviews confirm effectiveness and update configuration records. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We operate a formal vulnerability management process to protect the confidentiality, integrity, and availability of our services. Potential threats are assessed through regular risk reviews, vendor security advisories, and scheduled vulnerability scanning using Nessus credentialled patch audits conducted every two weeks. Results are reviewed by the CSS IT team and tracked to remediation.
Security patches are deployed based on risk classification.Critical and High within 14 days, Medium within 21 days, and Low within 28 days. Patches are tested prior to deployment, Microsoft patches applied to development before production. Threat intelligence is obtained from vendors, security bulletins, and vulnerability scan outputs. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
We operate a structured protective monitoring process to identify and respond to security threats promptly. System, application, and security logs are collected centrally and monitored 24/7 by a dedicated Security Operations Centre using SIEM technology and threat intelligence feeds. Monitoring identifies potential compromises such as suspicious logins, privilege escalation, malware activity, and anomalous network traffic.
If a potential compromise is detected, alerts are immediately raised to the CSS for investigation and containment. Incidents are triaged, escalated where required, and managed in line with our incident response procedures. Security incidents are reviewed without delay, with response initiated immediately upon detection. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We operate a formal incident management process with pre-defined procedures for common events, as outlined in our SLA documentation. These procedures cover incident identification, classification, escalation, communication, and resolution.
Users report incidents through our dedicated ticketing system or via a dedicated support telephone line. All incidents are logged, prioritised, and tracked through to resolution by CSS.
We maintain structured internal and external reporting processes. For infrastructure outages or major incidents, incident reports and status updates are communicated to affected parties by email. Post-incident reviews are conducted where appropriate to capture lessons learned and support continual service improvement. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 1%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 1%
- Over £5,000,001
- 1%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Monday 30 September 2024
- What the ISO/IEC 27001 doesn’t cover
- NA
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Saturday 30 August 2025
- What the ISO 9001 doesn’t cover
- NA
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 91395cee-140c-4683-a295-e14eaff9a00a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 66a8320e-6186-48fb-899e-313d273798ec
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-