Skip to main content

Help us improve the Digital Marketplace - send your feedback

APM Technologies SA

SmartOps

SmartOps is a flight-watch software tool for real-time decision- making and provides a visual display of your live schedule in UTC and LT.
Rapid decision is made possible with user-friendly features for the delay, cancellation, diversion, return to gate and reinstatement of flights with a range of reports.

Features

  • Aircraft database
  • Graphical User Interface
  • Airport information
  • Crew Data
  • Intuitive flight control and change wizards
  • IATA Messaging Creation
  • Asset Load Management
  • Delay Management
  • Crew Information
  • Aircraft Standstill Features

Benefits

  • Aircraft Punctuality Assistance
  • Flight Amendment, Change and Cancellation
  • Load Management
  • Graphical Views in LT and UTC
  • On Time Performance Indicators
  • Flight Delay Crew Impact
  • Multi user solution
  • Browser solution
  • Networked solution
  • Editable user rights and displays

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at michael.osullivan@apmtechnologies.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 5 4 3 7 0 8 2 6 9 1 2 1 0 7

Contact

APM Technologies SA Michael OSullivan
Telephone: 00447789637467
Email: michael.osullivan@apmtechnologies.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Defence
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
APM's SmartOps Aircraft Operations software,
APM's CrewLogic Crewing Software
Cloud deployment model
Private cloud
Service constraints
Planned maintenance is necessary for any version updates. This normally requires a downtime of up to 2 hours, which is pre planned with the customer.
System requirements
  • Azure Cloud or MS Operating system compliance
  • Oracle or Firebird databases

User support

Email or online ticketing support
Yes
Support response times
Our SLA criteria is to respond within the hour. Issues are reported as follows,
Monday to Friday 0900 to 1730 Geneva LT,
Weekends and Swiss Bank Holidays Tier 3 Help Desk is closed,
24/7/365 cover for SLA1s
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
We will conduct the vast majority of our support remotely, but should the customer require on site support due to a specific upgrade or security need we will supply it on condition the travel costs are met.
We utilise the JIRA system for recording issues but our ethic is to provide our customers with same day answers and solutions. Not just issue a JIRA ticket.
Initial support requests are covered by our Helpdesk and escalated to Technical Software or IT support as necessary.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We allocate an Account Manager who will use our pre-formatted Onboarding Template to bring a test database for acceptance by the customer. In parallel with this we will train users in the use of the module.
Once the test database is approved by the user will enable same in a production environment
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Data can be extracted via a range of reports and excel/csv extracts.
Additionally if the customer requires we can facilitate at a lower fee a read only extract version of our software.
End-of-contract process
We will delete all data in accordance with GDPR.
We will delete all confidential information as defined in the contract.
We will complete any additional tasks as defined within the contract with the customer.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
It will be made available via Sharepoint or via an FTPS link

Using the service

Web browser interface
Yes
Supported browsers
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The web app presents a clean, structured interface usable with a keyboard. Menus, forms, tables, and dialogs are accessible using tab navigation, arrow keys, and shortcuts, with focus indicators and logical reading order. Features can be reached without a mouse, ensuring efficient and inclusive use. Only a specialized visual component— our Gantt view- requires mouse interaction due to its spatial nature. Yet some keyboard shortcuts are still usable in our Gantt view.
Accessibility standards
None or don’t know
Description of accessibility
Our service is available via a Log On with an authenticated Token Service
Accessibility testing
We use SmartBear technology for both scripted regression tests and manual tests.
We have over 1,200 scripted regression tests.
API
Yes
What users can and can't do using the API
We will install the APM API for them and enable the encrypted Web Service for access.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
We have a Settings module so the following can be customized,
Read or Read Write Access,
Colours of the displays,
Parameters of the displays,
Templates of reports.

Scaling

Independence of resources
We monitor the usage of our Azure Service Cloud and ensure the Cloud resources exceed the MS recommended levels

Analytics

Service usage metrics
Yes
Metrics types
We maintain the logs of the Users
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
All grid reports have can be exported via excel.
Certain printable reports can be exported via PDF.
Data export formats
  • CSV
  • Other
Other data export formats
Xlxs
Data import formats
  • CSV
  • Other
Other data import formats
IATA SSIM and Chapter 7 messages

Data-in-transit protection

Data protection between buyer and supplier networks
Private network or public sector network
Data protection within supplier network
Other
Other protection within supplier network
We use partitioned environments and deploy MS Bastien for Security procedures.

Availability and resilience

Guaranteed availability
SLA 1
The Licensed Software (or a component thereof): (A) is unusable, catastrophically fails or ceases to provide its material, documented, functions; provides erroneous/incorrect output or displays (based upon the accurate input of data) or (B) causes a system, server, workstation, or application to be substantially unusable, catastrophically fail or cease to provide material functions. A viable workaround to restore such operation or functionality is not readily available.

SLA2
The Licensed Software (or a component thereof) is not fully functional (e.g., the Licensed Software has major restrictions on functionality; the Licensed Software performs most, but not all, material documented functions), or causes performance degradation of a system, server, workstation, or application. A viable workaround to restore such operation or functionality is not readily available or such workaround is available but material problems remain. The application usability is to the point that its value to Customer is substantially diminished.

SLA 3
The Licensed Software (or a component thereof) operates with minor, non-material restrictions on certain functions or causes minor performance degradation of systems that are not material to their operation
Refunds due to SLA failure is restricted to SLA1
Approach to resilience
We use an MS Azure Farm in Dublin with a DR site real time cut over in Holland
Outage reporting
An API dashboard with notifications

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
For the management interface
• Role-based access control (RBAC). Users are only granted the minimal privileges needed to use the software. MFA is available. Not exposed to the public internet. Logging mechanism available in the software.
For support channel
• Support through Teams. Identity is verified as only professional email is used during Teams meetings. Support agent does not have a direct access to the system. Only the end user has access to the system and can be guided by the support agent
Access restriction testing frequency
At least every 6 months
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users receive audit information on a regular basis
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • Other
Other security governance standards
Cyber Essentials Plus Certification
Information security policies and processes
We have various policies/processes which cover data protection, device security, backups, cyber security, patch management and employee awareness as listed below.
Data protection – GDPR training, data sanitisation where any documents/databases contain people information.
Device security – Use of standard user logins on devices to prevent unauthorised admin level changes, use of MFA, BitLocker encryption, Bitdefender endpoint security on every device.
Backup Policy – Important data is saved either into applications or to a central location which are then backed up on a weekly basis. Weekly remote backups are made to the cloud.
Cyber Security/patch management – Patch updates are applied weekly to user devices and as required to servers (notified by Icinga alerts). We hold certifications for and maintain security to minimum Cyber essentials and Cyber essential plus level. We also carry out formal security scans on devices monthly .
Employee Training/awareness – Employees have access to security policies (available in ISO system), formal online GDPR and Cyber Security training. Regular communication to employees.
Where possible, policies are implemented at software/hardware level to prevent deviation from formal process.
We have open communication between employees and management via the IT Infrastructure Manager who reports to the Corporate Director.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We release a Version if there is a database change.
We release a Patch if there is no database change.
A version for example would be,
7.41.3.
A patch for this would be
7.41.5 or 7.41.7 etc.
A new vision would be
7.42.3
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We run tenable scans on our environment every month
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
As part of our software release process we monitor security alerts and incorporate the security patches into our code based on the following information,
CVE Datasources:
National Vulnerability Database (NVD) from the U.S. government repository of standards-based vulnerability management data.
Sonatype OSS index based on NVD with additional information and CVE from Sonatype the proprietary of the datasource.
Gitub Advisory and Open source Vulnerability lists.
Incident management type
Undisclosed
Incident management approach
Once informed of an event we will immediately:

1. Establish details and communicate to all staff advising not to connect with the affected customer.

1. Review impact and what actions need to be taken internally by APM.

a. All emails arriving from the customer should be set to be quarantined.

b. Coordinate updates with the customer.

d. For any emergency assistance, the stand-alone laptops should be used via a 4G dongle.

e. No direct connection is permitted to the customer network.

f. Complete ‘Customer Cyber Security Outbreak’ form from the customer.

g. If satisfactory, advise staff they can reestablish connections.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
SOCOTEC
ISO 9001 accreditation date
Wednesday 3 July 2024
What the ISO 9001 doesn’t cover
We have have a process within our ISO in a box system for all our processes
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
5854eb7f-2e0e-4fab-aaed-b3b25ca7a39b
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
498292f0-28aa-4e7b-9e29-538465eba196
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at michael.osullivan@apmtechnologies.com. Tell them what format you need. It will help if you say what assistive technology you use.