Landlord Accreditation Scheme Web Platform
Rocktime's landlord accreditation software allows councils to provide an effective online platform to manage landlord accreditation through the delivery of E-learning for ongoing CPD accreditation and the management of instructor led training courses. Rocktime's systems can be integrated with legacy CRM/EDRMS systems as well as postcode and online payment systems
Features
- E-learning
- User Dashboards
- CPD Points management
- Event Management For External Training
- Fully Customisable Course Modules
- Automatic Documentation And Certificate Production
- Integration with CRM, EDRMS and legacy software
- Full Reporting Function
- Built in help system for Users and Citizens
- On screen help system for applicants
Benefits
- Landlord Training To Improve Housing Standards
- Full automation of the accreditation process
- E-Learning Delivery & Accreditation Management
- Browser based Delivery
- Dashboard Access for Officers / Instructors For User Management
- Compliant with CESG Architectural Pattern No. 10
- Prosecutions Database For Rogue Landlord Filtering.
- Address validation via UPRN to prevent incorrect scheme applications
- Fully configurable branding and style
- Browser based front end and control panel for mobile access
Pricing
£40,000 an instance a year
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
9 6 9 9 7 1 6 5 5 7 4 9 4 5 7
Contact
    ROCKTIME LIMITED
    
    Alex McCreath
    
    
    Telephone: 01202 678777
    
    
    Email: rtsales@rocktime.co.uk
    
  
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- 
      - Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
 
- Service constraints
- On request.
- System requirements
- 
      - Managed Service supplied by Rocktime
- Dedicated Tailored Web Server Environment
- Software Licence on a per instance
- Latest .NET Technology
 
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Response Times Our response times for each support issue raised during normal working hours are as follows: • Priority Level 1: Within 36 hours • Priority Level 2: Within 50 hours • Priority Level 3: Within 1 Week • Priority Level 4: Updates applied every 6 months (unless critical)
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- The support types are prioritised according to potential business impact and are identified as follows: Priority Level 1 • Critical bug fixes (errors that prevent the site from functioning) • Ecommerce (errors that prevent the site from functioning) • Payment platform (errors that prevent the site from functioning) • Server Diagnosis (if on Rocktime Hosting) Priority Level 2 • Minor Bug fixes • Validation issues • JavaScript issues Priority Level 3 • Simple text changes (for static content) • Graphical amendments (for static content) • Minor usability changes • Simple programming changes • Browser compatibility issues (for static content) for past and / or future browsers • Minor layup alterations (for static content) Priority Level 4 • Core updates • Module updates (core and control panel) • Security updates Each support issue will have a ‘ticket’ raised and the appropriate resolution/work will be scheduled within our standard work schedule and communicated to the client. Our response times for support issues raised during normal working hours are as follows: • Priority Level 1: Within 36 hours • Priority Level 2: Within 50 hours • Priority Level 3: Within 1 Week • Priority Level 4: Updates applied every 6 months (unless critical)
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Stakeholder engagement from the outset. Full scoping exercise with the involvement of all parties. Clear deliverables with milestone objectives. Agreed account and project management meetings with appropriate forms of communication through the entire delivery process. Tailored training programme with identified system users delivered virtually; one to one and one to many with option for train the trainer.
- Service documentation
- Yes
- Documentation formats
- 
      - HTML
 
- End-of-contract data extraction
- All data is held in a SQL database or if integrated, within the users systems. All data will be extracted by Rocktime and sent to the user in their preferred format at the end of the contract as a chargeable service.
- End-of-contract process
- Rocktime has a documented process for onboarding and offboarding clients using Verso. this includes extracting client data from Verso and ensuring all API links are closed. Any developer time required for this process will be quoted for depending on the client system configuration.
Using the service
- Web browser interface
- Yes
- Supported browsers
- 
      - Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
 
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Verso uses a fluid design, all content will be displayed on mobile, tablet and desktop variants using a responsive framework.
- Service interface
- Yes
- User support accessibility
- WCAG 2.1 AAA
- Description of service interface
- Full officer dashboard functions to manage all aspects of the software and the licensing process
- Accessibility standards
- WCAG 2.1 AAA
- Accessibility testing
- Fully tested against a range of desktop, mobile and tablet based devices using Windows, IOS and Android operating systems
- API
- Yes
- What users can and can't do using the API
- Rocktime provides access to an API with instructions on how to connect to all held data and/ or the ability to push data into verso where appropriate. There are no limitations other than those set by the data types themselves.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- 
      During the initial configuration process the software will be customised for: Branding Questioning process; Workflow & Business logic; Application workload management; User groups & Access (User Admin Editable).
 Further customisation can be undertaken as part of a Continuous Improvement Program.
Scaling
- Independence of resources
- Cloud hosted solution accounts for user level activity to maintain performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Dashboard and reporting
- Reporting types
- 
      - API access
- Real-time dashboards
- Regular reports
- Reports on request
 
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a Tigerscheme qualified provider or a CREST-approved service provider
- Protecting data at rest
- 
      - Physical access control, complying with another standard
- Encryption of all physical media
 
- Data sanitisation process
- Yes
- Data sanitisation type
- 
      - Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
 
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Data can be exported via API or .CSV
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- 
      - Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
 
- Data protection within supplier network
- 
      - TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
 
Availability and resilience
- Guaranteed availability
- Updates will be carried out on request by the client according to the following summary of services: Option 1: Telephone and email support service during standard working hours and evenings Email support service during evenings Site Monitoring Response Times Priority Level 1 Within 24 hours Priority Level 2 Within 50 hours Option 2: Telephone and email support service during standard working hours Email support service during evenings Site Monitoring (tests every 5 mins) Response Times Priority Level 1 Within 18 hours Priority Level 2 Within 50 hours Option 3: Telephone and email support service during standard working hours Email support service during evenings and weekends Site Monitoring Response Times Priority Level 1 Within 12 hours 24/7 Priority Level 2 Within 40 hours Option 4 - Critical: Telephone and email support service during standard working hours Email support service during evenings and weekends Site Monitoring Response Times Priority Level 1 Within 4 hours 24/7 Priority Level 2 Within 24 hours Note: These are response times for incident notification; they are not times for incident resolution.
- Approach to resilience
- Information available on request
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
- 
      - 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
 
- Access restrictions in management interfaces and support channels
- 2-factor authentication Public key authentication (including by TLS client certificate)
- Access restriction testing frequency
- At least once a year
- Management access authentication
- 
      - 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
 
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- 01/02/2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Self Assessment - SAQ-D
- PCI DSS accreditation date
- 25/04/2024
- What the PCI DSS doesn’t cover
- N/A
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
- CESG Architectural Pattern No. 10
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Rocktime follows security policies and procedures according to ISO 27001
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Verso has has a release cycle for upgrades and changes, the implementation of which is managed under ISO 9001:2015 & ISO 27001:2017
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- In accordance with ISO 27001:2017 Rocktime's approach for managing vulnerabilities is as follows: Timely identification of vulnerabilities - The sooner we discover a vulnerability, the more time we will have to correct it, or at least to warn the clients about the situation, decreasing the opportunity window a potential attacker may have. Assessment of Rocktime's exposure to a vulnerability. - Rocktime will risk assess to identify and prioritise those vulnerabilities that are more critical to our own or our clients assets and business. Proper measures considering the associated risks - plan actions and allocate resources to deal with risks accordingly.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Rocktime conforms to ISO 27001:2017 requirements for logging and monitoring. This includes Event Logging, Protection of log information, Administrator and operator logs and clock synchronization.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Rocktime conforms to ISO 27001:2017 incident management clauses that include: 5.1 — Leadership and commitment 7.2 — Competency 5.3 — Organizational roles, responsibilities and authorities A.16.1.1 — Responsibilities and procedures A.16.1.4 — Assessment of and decision on information security events A.16.1.5 — Response to information security incidents A.16.1.6 — Learning from information security incidents
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Public Services Network (PSN)
Social Value
- Social Value
- 
      Social Value - Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
 Fighting climate change Rocktime Limited aims to achieve excellence in all areas of our company with the commitment to minimising the environmental impacts of our business operations. Our commitment sets out to: • Reduce our consumption of resources and improve the efficient use of those resources. • Continuously improve our environmental performance and integrate recognised environmental management best practice into our business operations. • Measure and take action to reduce the carbon footprint of our business activities to meet objectives and targets. • Manage waste generated from our business operations according to the principles of reduction, re-use and recycling. • Manage our business operations to prevent pollution. • Give due consideration to environmental issues and energy performance in the use of our office buildings. • Ensure environmental, including climate change, criteria are taken into account in the procurement of goods and services. • Comply as a minimum with all relevant environmental legislation as well as other environmental requirements. To meet our commitments, we will: • Set and monitor key objectives and targets for managing our environmental performance at least annually. • Communicate internally and externally our environmental policy and performance on a regular basis and encourage feedback. • Communicate the importance of environmental issues to our people. • Work together with our people/employees, service partners, suppliers, landlords and their agents to promote improved environmental performance. • Promote appropriate consideration of sustainability and environmental issues in the services we provide to our clients. • Review our environmental policy regularly.Covid-19 recovery Covid-19 recovery As a cloud technology company, Rocktime has been successful in implementing changes to processes and procedures to adapt to the new norm that features greater flexibility in the manner in which it conducts its business both with its staff as well as with clients. The company has actively promoted excellence through the use of technology that helps local businesses to connect and work more effectively, benefitting from collaborative working arrangements to foster positive business relationships in the local community and recovery as we exit Covid-19 and accept the current economic landscape. The company engages with local diverse market businesses to advise on the use of technology in the same manner as it does with its public sector clients with the aim to open up supply chain opportunities.Tackling economic inequality The company’s values a diverse workforce and the contribution each individual makes. We are committed to promoting inclusivity, equality and diversity in our policies, practices and procedures. This policy applies to the company's dealings with all its people as well as others engaged by or who work with the firm including, for example, clients, job applicants and other third parties. The company believes in treating everyone equally and with the same attention, courtesy and respect regardless of their age, disability, gender reassignment, marriage/civil partnership, pregnancy/maternity, race, religion or belief, sex and sexual orientation which is referred to within its Equality, Diversity and Inclusion Policy as the "protected characteristics".Equal opportunity The company has always believed in promoting diversity within the workplace and this forms part of its recruitment practices. Using the 5 foundational principles of quality work set out in the Good Work Plan (e.g. fair, pay, participation and progression, voice and autonomy). Career advice with local schools offers opportunity to instil insights and confidence in potential career paths for young people whilst also providing the opportunity for a work placement. Additionally, consideration is made for recruiting trainees and training them to perform roles whilst offering them a career path within the business or as a means to seek one elsewhere.Wellbeing The company recognises the pressures that have arisen in recent times with Covid-19 and the effects of social distancing, remote working and travel enforcements. Through constant dialogue with its team the company has sort to provide flexible working conditions whilst maintaining regular and personal engagement to reduce the impact of loneliness and isolation. Believing in the positive nature of ‘culture’ within a company, initiatives are in place to maintain and reinforce a team mentality that aims to support individuals and foster wellbeing.
Pricing
- Price
- £40,000 an instance a year
- Discount for educational organisations
- No
- Free trial available
- No