Skip to main content

Help us improve the Digital Marketplace - send your feedback

IDOX SOFTWARE LTD

Idox Exacom

Exacom provides a suite of web-based SaaS solutions for monitoring and managing legal obligations in the Built Environment, including the following modules:
CIL Administrator
S106/S75 Administrator
Project Administrator
Biodiversity Net Gain (BNG)
Building Safety Levy (BSL)
Public Facing Module
Exacom Public Interface (EPI)
Spatial GIS Mapping

Features

  • S106 and CIL reporting and data drill down
  • BNG reporting and data drill down
  • Project milestone tracking and spend reporting
  • Fully customisable
  • Online CIL calculator
  • S106 monitoring, management, allocation and spending
  • Document templates and integrated document management system
  • Integration with other supported systems (ie planning software)
  • Infrastructure Funding Statement via template autofill
  • Public interfaces for S106 and CIL data forms submission

Benefits

  • Ease of submission and paperless working
  • Full lifecycle support and legislative updates
  • Web based and data encrypted at rest and in transit
  • S106 monitoring down to individual covenant level
  • Auto fill template library including demands notices and letters
  • Workflow management and programmable alerts and diary events
  • Unlimited users through corporate desktop log in
  • Granular managed access for individuals and groups
  • Publicly accessible website including access to S106 deed documents
  • Reduces workload on FOI requests

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@idoxgroup.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 8 1 6 0 4 8 1 7 0 8 7 0 3 0

Contact

IDOX SOFTWARE LTD Jen.roberts@idoxgroup.com
Telephone: 0333 011 1200
Email: bidteam@idoxgroup.com

About your service

Service categories

Application Development and Deployment

Data management

Database management systems

  • Relational Database Management Systems
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Local Authority Planning and Finance Systems
Exacom Public Facing Module
Exacom BNG Module
CIL
Building Safety Levy
Cloud deployment model
Private cloud
Service constraints
Planned maintenance occurs outside of normal working hours (usually on Sundays).
System requirements
  • Modern Browser
  • Access via Authority Network using corporate IP(s)

User support

Email or online ticketing support
Yes
Support response times
Within three hours during business hours
The Exacom Standard Helpdesk Service is available Monday to Friday between 9am and 5pm (excluding Bank Holidays).
Our helpful Support staff can be contacted via telephone or e-mail for advice and assistance on technical queries, issues and best practice use of the software.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Full support included with software package.
HIGH PRIORITY: Within 1 working hour of call being logged.
MEDIUM PRIORITY: Within 4 working hours of call being logged.
NORMAL PRIORTY: Within 8 working hours of call being logged.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
An extensive Training Video Library covering all Modules is permanently available om Exacom, which can be used for initial training when you take on an Exacom Module, and also by any new staff who join your team in the future.

In addition, as part of the onboarding package, an in-person training session for each Module purchased is available for staff who have completed the video training. This session will be hosted by one of our in-house specialists and offers the opportunity to ask questions, seek any clarification required and consolidate the video based learning.
Service documentation
Yes
Documentation formats
  • HTML
  • Other
Other documentation formats
Video
End-of-contract data extraction
By arrangement with Exacom. Typical data standard is CSV.
End-of-contract process
Notice given by either party, and arrangements made for secure data transfer, followed by industry standard cleanse of data
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Documentation is provided, however it has not been produced to any specific or formal accessibility standard.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The software is browser based and can be accessed and used via all device types.
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Customers can create custom reports that will allow data extraction via the API for use in external data management systems. Data import from systems such as planning or finance systems can be performed via a REST API. The system provides API endpoints for all external integrations offered as standard.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The solution is highly configurable and can be tailored to fit seamlessly with the user's business processes. There are numerous areas of the system where codes and record types, and the movement of cases and data through the embedded workflow, can be customised to meet local needs. Document templates can also be configured as required.

Scaling

Independence of resources
We ensure that our server specification always far exceeds our clients' requirements, therefore no system limitations will occur due to demand / usage

Analytics

Service usage metrics
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Exacom Systems Ltd

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
CSV, encrypted file transfer.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
99% uptime Monday to Friday Excluding Bank Holidays
Approach to resilience
Available on request.
Outage reporting
Email Alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
IP address limitation via firewall, username and passwords and group membership constraints.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We recognise that information security important in the development and implementation of all systems delivered to our customers, to Idox as a corporate entity, and to our supply chain.

To ensure a consistent and effective approach, we operate an externally audited and certified, organisation wide Information Security Management System (ISMS) which implements and enforces controls on all business functions covering but not limited to information systems, networks, physical environment, incident/threat management, project and contract management and personnel management. 

Our systems and controls are also externally verified and certified annually as part of the ISO 27001 certification process.  Risks raised through internal and external audits are reviewed at management meetings by the Information Security Manager, the appropriate Head of Business and a board representative.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Exacom users have a Test and Live version of the software. Any upgrades are applied to Test for the client to approve, prior to the upgrade being applied to their live system.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Regular penetration test and all servers are protected by industry standard virus and vulnerability software.

Servers are patched on a monthly basis for regular updates.

Any vulnerability patches are applied as they are made available.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Monitoring tools are used to measure server performance metrics as well as storage and network / bandwidth utilisation and unusual server / network / perimeter activity. Alerts from these systems are actively monitored and reviewed and any potential intrusion attempt is raised in line with our security incident reporting procedure for further investigation.
Incident management type
Supplier-defined controls
Incident management approach
Our Support inboxes are monitored during support hours, and incidents are responded to in line with their priority.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation ISO Certification Limited
ISO/IEC 27001 accreditation date
Monday 27 May 2024
What the ISO/IEC 27001 doesn’t cover
Our ISMS is certified and tested to ISO27001 standards annually and covers our entire organisation.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation ISO Certification Limited
ISO 9001 accreditation date
Thursday 11 April 2024
What the ISO 9001 doesn’t cover
Our ISMS is certified and tested to ISO9001standards annually and covers our entire organisation.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
5c6de739-c45d-4eee-916a-013a0c2ce8f7
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
26018f8f-da19-4856-8fd2-b719e0c21047
Other security certifications
Yes
Any other security certifications
ISO 22301

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@idoxgroup.com. Tell them what format you need. It will help if you say what assistive technology you use.