SmartOps
SmartOps is a flight-watch software tool for real-time decision- making and provides a visual display of your live schedule in UTC and LT.
Rapid decision is made possible with user-friendly features for the delay, cancellation, diversion, return to gate and reinstatement of flights with a range of reports.
Features
- Aircraft database
- Graphical User Interface
- Airport information
- Crew Data
- Intuitive flight control and change wizards
- IATA Messaging Creation
- Asset Load Management
- Delay Management
- Crew Information
- Aircraft Standstill Features
Benefits
- Aircraft Punctuality Assistance
- Flight Amendment, Change and Cancellation
- Load Management
- Graphical Views in LT and UTC
- On Time Performance Indicators
- Flight Delay Crew Impact
- Multi user solution
- Browser solution
- Networked solution
- Editable user rights and displays
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 5 4 3 7 0 8 2 6 9 1 2 1 0 7
Contact
APM Technologies SA
Michael OSullivan
Telephone: 00447789637467
Email: michael.osullivan@apmtechnologies.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Defence
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
APM's SmartOps Aircraft Operations software,
APM's CrewLogic Crewing Software - Cloud deployment model
- Private cloud
- Service constraints
- Planned maintenance is necessary for any version updates. This normally requires a downtime of up to 2 hours, which is pre planned with the customer.
- System requirements
-
- Azure Cloud or MS Operating system compliance
- Oracle or Firebird databases
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our SLA criteria is to respond within the hour. Issues are reported as follows,
Monday to Friday 0900 to 1730 Geneva LT,
Weekends and Swiss Bank Holidays Tier 3 Help Desk is closed,
24/7/365 cover for SLA1s - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
We will conduct the vast majority of our support remotely, but should the customer require on site support due to a specific upgrade or security need we will supply it on condition the travel costs are met.
We utilise the JIRA system for recording issues but our ethic is to provide our customers with same day answers and solutions. Not just issue a JIRA ticket.
Initial support requests are covered by our Helpdesk and escalated to Technical Software or IT support as necessary. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We allocate an Account Manager who will use our pre-formatted Onboarding Template to bring a test database for acceptance by the customer. In parallel with this we will train users in the use of the module.
Once the test database is approved by the user will enable same in a production environment - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Data can be extracted via a range of reports and excel/csv extracts.
Additionally if the customer requires we can facilitate at a lower fee a read only extract version of our software. - End-of-contract process
-
We will delete all data in accordance with GDPR.
We will delete all confidential information as defined in the contract.
We will complete any additional tasks as defined within the contract with the customer. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- It will be made available via Sharepoint or via an FTPS link
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The web app presents a clean, structured interface usable with a keyboard. Menus, forms, tables, and dialogs are accessible using tab navigation, arrow keys, and shortcuts, with focus indicators and logical reading order. Features can be reached without a mouse, ensuring efficient and inclusive use. Only a specialized visual component— our Gantt view- requires mouse interaction due to its spatial nature. Yet some keyboard shortcuts are still usable in our Gantt view.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Our service is available via a Log On with an authenticated Token Service
- Accessibility testing
-
We use SmartBear technology for both scripted regression tests and manual tests.
We have over 1,200 scripted regression tests. - API
- Yes
- What users can and can't do using the API
- We will install the APM API for them and enable the encrypted Web Service for access.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
We have a Settings module so the following can be customized,
Read or Read Write Access,
Colours of the displays,
Parameters of the displays,
Templates of reports.
Scaling
- Independence of resources
- We monitor the usage of our Azure Service Cloud and ensure the Cloud resources exceed the MS recommended levels
Analytics
- Service usage metrics
- Yes
- Metrics types
- We maintain the logs of the Users
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
-
All grid reports have can be exported via excel.
Certain printable reports can be exported via PDF. - Data export formats
-
- CSV
- Other
- Other data export formats
- Xlxs
- Data import formats
-
- CSV
- Other
- Other data import formats
- IATA SSIM and Chapter 7 messages
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- Other
- Other protection within supplier network
- We use partitioned environments and deploy MS Bastien for Security procedures.
Availability and resilience
- Guaranteed availability
-
SLA 1
The Licensed Software (or a component thereof): (A) is unusable, catastrophically fails or ceases to provide its material, documented, functions; provides erroneous/incorrect output or displays (based upon the accurate input of data) or (B) causes a system, server, workstation, or application to be substantially unusable, catastrophically fail or cease to provide material functions. A viable workaround to restore such operation or functionality is not readily available.
SLA2
The Licensed Software (or a component thereof) is not fully functional (e.g., the Licensed Software has major restrictions on functionality; the Licensed Software performs most, but not all, material documented functions), or causes performance degradation of a system, server, workstation, or application. A viable workaround to restore such operation or functionality is not readily available or such workaround is available but material problems remain. The application usability is to the point that its value to Customer is substantially diminished.
SLA 3
The Licensed Software (or a component thereof) operates with minor, non-material restrictions on certain functions or causes minor performance degradation of systems that are not material to their operation
Refunds due to SLA failure is restricted to SLA1 - Approach to resilience
- We use an MS Azure Farm in Dublin with a DR site real time cut over in Holland
- Outage reporting
- An API dashboard with notifications
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
For the management interface
• Role-based access control (RBAC). Users are only granted the minimal privileges needed to use the software. MFA is available. Not exposed to the public internet. Logging mechanism available in the software.
For support channel
• Support through Teams. Identity is verified as only professional email is used during Teams meetings. Support agent does not have a direct access to the system. Only the end user has access to the system and can be guided by the support agent - Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- Other
- Other security governance standards
- Cyber Essentials Plus Certification
- Information security policies and processes
-
We have various policies/processes which cover data protection, device security, backups, cyber security, patch management and employee awareness as listed below.
Data protection – GDPR training, data sanitisation where any documents/databases contain people information.
Device security – Use of standard user logins on devices to prevent unauthorised admin level changes, use of MFA, BitLocker encryption, Bitdefender endpoint security on every device.
Backup Policy – Important data is saved either into applications or to a central location which are then backed up on a weekly basis. Weekly remote backups are made to the cloud.
Cyber Security/patch management – Patch updates are applied weekly to user devices and as required to servers (notified by Icinga alerts). We hold certifications for and maintain security to minimum Cyber essentials and Cyber essential plus level. We also carry out formal security scans on devices monthly .
Employee Training/awareness – Employees have access to security policies (available in ISO system), formal online GDPR and Cyber Security training. Regular communication to employees.
Where possible, policies are implemented at software/hardware level to prevent deviation from formal process.
We have open communication between employees and management via the IT Infrastructure Manager who reports to the Corporate Director. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We release a Version if there is a database change.
We release a Patch if there is no database change.
A version for example would be,
7.41.3.
A patch for this would be
7.41.5 or 7.41.7 etc.
A new vision would be
7.42.3 - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We run tenable scans on our environment every month
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
As part of our software release process we monitor security alerts and incorporate the security patches into our code based on the following information,
CVE Datasources:
National Vulnerability Database (NVD) from the U.S. government repository of standards-based vulnerability management data.
Sonatype OSS index based on NVD with additional information and CVE from Sonatype the proprietary of the datasource.
Gitub Advisory and Open source Vulnerability lists. - Incident management type
- Undisclosed
- Incident management approach
-
Once informed of an event we will immediately:
1. Establish details and communicate to all staff advising not to connect with the affected customer.
1. Review impact and what actions need to be taken internally by APM.
a. All emails arriving from the customer should be set to be quarantined.
b. Coordinate updates with the customer.
d. For any emergency assistance, the stand-alone laptops should be used via a 4G dongle.
e. No direct connection is permitted to the customer network.
f. Complete ‘Customer Cyber Security Outbreak’ form from the customer.
g. If satisfactory, advise staff they can reestablish connections. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- SOCOTEC
- ISO 9001 accreditation date
- Wednesday 3 July 2024
- What the ISO 9001 doesn’t cover
- We have have a process within our ISO in a box system for all our processes
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5854eb7f-2e0e-4fab-aaed-b3b25ca7a39b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 498292f0-28aa-4e7b-9e29-538465eba196
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
-