Skip to main content

Help us improve the Digital Marketplace - send your feedback

OPUZ LTD

Opuz

Opuz is here to support and control facilities management, compliance management/risk control, asset management, workforce and contractor management.
It's a comprehensive CaFM Integrated Workplace Management System built from real-world experience. It provides a single, reliable platform to unify your operations, enhance efficiency, increase productivity and ensure you are always audit-ready.

Features

  • Mobile Workforce Solution
  • Reactive Helpdesk
  • Planned preventative maintenance
  • Estate & asset lifecycle management
  • Compliance and Risk Control
  • Customisable Dashboard and Analysis
  • AI and Smart Building Integration (IOT) Ready
  • CapEx Projects
  • Generate Survey & Reports Documents
  • Compliance Document Control

Benefits

  • Ensures peace of mind
  • Simplifies compliance management
  • Assists inter-departmental organisation
  • Enhances operational efficiency
  • Auto population of risk assessment data
  • Simplifies hazard management
  • Time saving
  • Maintains audit trail
  • Multi site/building accounts
  • Data is yours, can be exported anytime

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at dan@opuzsoftware.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 7 4 6 8 8 7 6 4 0 8 7 9 0 3

Contact

OPUZ LTD Dan Kimber
Telephone: 07584235804
Email: dan@opuzsoftware.com

About your service

Service categories

Applications

Enterprise resource management

  • Asset life-cycle management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No
System requirements
Modern up to date web browsers eg Chromium based browsers

User support

Email or online ticketing support
Yes
Support response times
Response times to questions in our user support team are within a maximum of 24 hours in normal working days 09:00-17:00 Monday to Friday.

Response times to questions in our user support team outside working hours or on weekends/bank holidays will be on the next working day.

Users will have access to our Opuz support team via jira support ticketing system,email and phone which can be used depending on the priority.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 A
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Opuz offers support on site which includes system training, mobilisation, asset identification, tagging and loading, maintenance programme loading. Opuz offers system audits/system health checks to help ensure it is being used efficiently for your organisation and that it is providing expected time savings, cost savings, expected compliance and risk management and increased efficiencies.

Cost for Opuz on site support is costed at £990 per day.

Support regarding the health checks and audits as detailed above can be carried out remotely alternatively which can be provided at £79 per hour.

This work will be delivered by experienced members/users of Opuz.

General Opuz support is free which is provided via the Opuz support team via emails, phone or video calls. This includes everything to do with guidance, help and trouble shooting the system.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Opuz will provide either online or on site training for use of the main Opuz system accessed via browser and training on the mobile application. Opuz will provide regular drop in sessions for and agreed duration of an agreed period of time between client and Opuz. For example this could be for the first 12 weeks, Opuz provide a dedicated hour each week to assist new users. We can go over previously trained areas/refresh or to answer any questions that may be present. Further to this, Opuz can help mobilise by assisting in migration/integration of current data into the Opuz system. Opuz can work with clients to setup and customise the system to their needs/wants. There are also "How to" and help guides on the Opuz support pages which include screenshots and videos for help on system use.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
All data entered into or generated by Opuz remains the property of the customer. When a contract ends, Opuz provides a structured and supported process to enable customers to securely extract their data.

Data extraction process

Export on request
Customers can request a data export as part of contract termination or service exit. Exports are coordinated with the customer to ensure the required scope and format are agreed.

Standard data formats
Data is provided in commonly used, non-proprietary formats such as:
CSV for structured records (e.g. assets, tasks, schedules, risk data, and reports)
JSON where appropriate for structured or hierarchical datasets
File exports (e.g. images and documents) provided in their original formats

Exported data is made available via secure transfer mechanisms, such as time-limited secure download links or customer-approved secure storage locations.

Exports can include, where applicable:
Asset and site data
Planned and reactive maintenance records
Risk assessments and compliance data
Task history and audit information
User-generated documents and images
End-of-contract process
The standard contract price includes a defined end-of-contract process to support an orderly and secure service exit. This includes coordination of contract termination, confirmation of service end dates, and secure logical deletion of customer data from the live service in accordance with contractual terms and data protection requirements. Customers may request a standard data export at contract end, with data provided in commonly used, non-proprietary formats (such as CSV for structured data and original formats for documents and images). Reasonable support is provided to explain the contents and structure of the exported data.

Additional costs may apply where customers require services beyond the standard exit process. These may include bespoke or repeated data exports, data transformation or reformatting to meet specific third-party system requirements, extended access to the service beyond the contract end date, accelerated exit timelines, or additional consultancy support to assist with migration to another system. Any such costs are agreed in advance and charged transparently.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The Opuz mobile app is a native app. Used usually by in house maintenance teams, site operational staff or contractors to complete the work digitally which is then synced back to the Opuz system. Tasks are assigned to the mobile app users through the main Opuz system accessed via browsers.

The browser is independent of the app. You can use Opuz browser without the mobile app. this can be accessed through modern chromium browsers from any device such as desktops, tablets and phones.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
Opuz is delivered as a secure, cloud-based web application with an accompanying mobile application for field-based users. The service interface is designed to be intuitive, role-based, and accessible via standard web browsers and mobile devices without the need for specialist hardware or local installations.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Opuz has not yet undergone formal, third-party accessibility testing with specialist assistive technology users. However, accessibility considerations are incorporated into design, development, and testing activities as part of our ongoing product development lifecycle.
API
Yes
What users can and can't do using the API
The Opuz platform provides secure, role-controlled APIs that allow authorised customers and integration partners to exchange data with Opuz and integrate it with other systems. The APIs are designed to support interoperability while maintaining strong data protection, tenant isolation, and operational integrity.

What users can do using the API

Authorised API users can, subject to permissions and configuration:

Integrate with third-party systems
Exchange data with other Facilities Management, reporting, or corporate systems to avoid duplicate data entry and support joined-up workflows.

Retrieve operational data such as:

Assets, sites, and locations
Planned maintenance schedules
Reactive tasks and job status
Risk assessment and compliance records
Performance and status information for reporting purposes

Submit and update operational data including:

Work orders and tasks
Status updates from mobile or external systems
Measurement or inspection data (for example, IoT or monitoring inputs)
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Buyers can configure and customise Opuz to suit their operational processes without modifying the underlying software code. Customisation is provided through built-in configuration options and role-based controls.
Configure task workflows, status options, mandatory steps, and approval requirements to align with internal processes.Where additional configuration or integration is required beyond standard options, Opuz can support bespoke configuration or extensions through agreed professional services, without impacting the shared core platform.

Scaling

Independence of resources
Opuz is delivered as a multi-tenant, cloud-based SaaS platform designed to ensure that usage by one customer does not negatively impact the performance.

Each customer operates within a logically isolated tenant.
Data access is strictly segregated by tenant, with enforced boundaries at the application and database levels.
Opuz is hosted on a scalable cloud infrastructure that dynamically allocates resources based on demand.
Application services and databases are provisioned to support concurrent usage across tenants without reliance on fixed-capacity hardware.
The platform is designed to scale horizontally to absorb increases in load

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Through the Opuz system directly users can select and export their data.Users can customise grid/table layouts for specific data extraction if needed. In Opuz users can export out in many different types. Some examples of data being exported are in CSV and Excel eg grid/table layouts. Other data records can be exported as PDFs for example job sheets, documents, plans. In Opuz customisable widgets can be exported for visuals as PNG or SVG files and the background data of these widgets is also exportable.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Low Impact Changes (e.g. data amendment, configurations, data uploads/downloads, general support):
Resolution: Completed within 5 working days of acceptance.
Low Priority (Minor Bugs):
Resolution: Addressed and resolved in the next feature release.
Medium Priority (Bug Fix):
Resolution: Addressed and resolved within 5 working days.
High Priority (Incidents resulting in an interruption to business performance, but not causing major disruption):
Response Time: Within 8 hours of receiving the incident report.
Recovery Time: Within 24 hours of receiving the incident report.
Critical Priority (Core System Critical: Downtime affecting all users):
Response Time: Within 2 hours of receiving the incident report (during normal working hours).
Recovery Time: Within 4 working hours of receiving the incident report (during normal working hours).
Approach to resilience
At the application level, Opuz is designed to tolerate component failure without loss of data integrity. Services are stateless where possible, enabling them to be restarted or scaled without impacting customer data. Routine backups are performed to protect against data loss, and monitoring is in place to detect service degradation or failures so that remedial action can be taken promptly.

The datacentre setup benefits from Azure’s resilient design, including redundant power, networking, and storage, and the use of geographically resilient facilities within the chosen region. Azure manages physical security, hardware lifecycle, and infrastructure resilience in line with recognised standards and UK public sector expectations. Platform services used by Opuz are designed for high availability and fault tolerance, reducing the impact of hardware or component failure.
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
Opuz restricts access to management interfaces and support channels using role-based access control and least-privilege principles. Access to administrative and management functions is limited to authorised personnel only and is granted based on job role and operational need. User accounts are individually assigned and protected using secure authentication mechanisms, with multi-factor authentication available for privileged access.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
Opuz follows defined information security policies and processes designed to protect customer data, maintain service integrity, and meet UK public sector security expectations. These policies cover areas including access control, data protection, secure software development, incident management, change control, and business continuity, and are aligned with recognised best practice and the shared responsibility model used when hosting services on Microsoft Azure.

Overall responsibility for information security sits with senior management, with day-to-day oversight provided by technical leads responsible for implementation and compliance. Security risks, incidents, and material changes are escalated through an internal reporting structure to ensure visibility, accountability, and timely decision-making.

Information security policies are embedded into operational processes across the organisation. These include role-based access control using least-privilege principles, segregation of development, staging, and production environments, secure configuration and credential management, controlled code review and release processes, and continuous logging and monitoring to support detection and investigation of security events.

Adherence to policies is maintained through regular internal reviews, peer review of changes, and the use of automated vulnerability scanning and static analysis tools. Security is reviewed as part of ongoing development and operational improvement.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All application components are version-controlled using source code management. Infrastructure and application configuration is managed centrally within the cloud environment. Environments for development, staging, and production are segregated.
Proposed changes are assessed for functional, operational, and security impact before implementation. This includes reviewing access control implications, data handling changes, dependency updates, and potential effects on availability or integrity. Code changes are subject to peer review and automated checks, including vulnerability scanning and static analysis, prior to deployment. Changes are tested in a staging environment before release to production, with rollback procedures in place.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Information about potential vulnerabilities is obtained from multiple sources, including vendor security advisories, dependency and package repositories, automated vulnerability scanning and static analysis tools.

When vulnerabilities are identified, they are risk-assessed based on severity, exploitability, and potential impact. Critical or high-risk vulnerabilities are prioritised and patched as soon as practicable, typically through expedited releases or configuration changes. Lower-risk issues are addressed as part of planned maintenance cycles. Patches and fixes are tested in a staging environment before deployment to production, with monitoring in place to identify any post-release issues.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Opuz uses protective monitoring to identify potential security compromises through continuous review of application and platform logs, alerts, and unusual activity patterns, supported by monitoring capabilities provided by Microsoft Azure. When a potential compromise is detected, authorised personnel investigate, contain risk, preserve evidence, and apply remedial actions as required. Incidents are escalated appropriately and customers are notified where necessary. High-severity incidents are responded to immediately, with lower-risk issues addressed through planned remediation.
Incident management type
Supplier-defined controls
Incident management approach
Opuz operates defined incident management processes for common events such as service outages, security incidents, and data issues. These processes include investigation, escalation, containment, and communication steps based on incident severity. Users can report incidents via agreed support channels, including email or the designated service contact. Incidents are logged, assessed, and prioritised by authorised personnel. Where appropriate, customers receive incident updates and post-incident reports detailing impact, resolution, and preventative actions.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Free trial of the Opuz software can be provided. Opuz can liaise with potential buyers to provide them temporary access for system use. This will come with support and system demo. The system features will be accessible and useable for the trial period. Period between 1 and 3 months.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
28fd39ed-8cd3-43a7-85c6-3efec4417577
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
6e110fed-a3dd-4dd9-b34b-0f16afa2a90c
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at dan@opuzsoftware.com. Tell them what format you need. It will help if you say what assistive technology you use.