GoodMaps
GoodMaps offers an advanced, infrastructure-free positioning and wayfinding platform that enhances accessibility and efficiency in any environment. Available through a browser-based service, dedicated app, or a variety of integrations, GoodMaps enables seamless built environment navigation – empowering users to move confidently while helping organizations create smarter and more inclusive spaces.
Features
- Infrastructure-free indoor positioning using LiDAR and camera.
- Turn-by-turn, audio-first indoor wayfinding for all users.
- Accessible, step-free routing prioritizing mobility and vision needs.
- Self-service venue mapping with Scan & Go smartphone app.
- GoodMaps Web: embedded interactive 3D maps for websites.
- Dot lightweight SDK embeds positioning inside existing venue apps.
- Real-time map management and updates in GoodMaps Studio.
- Supports GoodMaps and IMDF maps for flexible deployments.
- Multi-language, screen-reader-friendly navigation experience.
- QR and link handoff between Web, Dot, and mobile apps.
Benefits
- Reduce wayfinding questions so staff focus on priorities.
- Shorten deployment timelines by mapping venues in weeks.
- Cut mapping costs by removing beacon hardware dependencies.
- Quickly update points of interest as spaces change.
- Improve accessibility compliance with inclusive, step-free navigation.
- Empower visitors to navigate independently without staff escorts.
- Centralize map editing in one digital source of truth.
- Control who can access sensitive facility map data.
- Boost visitor satisfaction with smoother, less stressful journeys.
- Let smaller venues self-scan and iterate layouts anytime.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 9 3 7 5 9 2 6 7 7 9 3 5 0 1
Contact
GoodMaps Inc.
Neil Barnfather
Telephone: 07900908070
Email: neil.barnfather@goodmaps.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- N/A
- System requirements
- None.
User support
- Email or online ticketing support
- Yes
- Support response times
- Weekdays 7am – 10pm, initial response within one hour. Reduced coverage on weekends.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- Initially account management and customer success via email, with escalation to appropriate internal teams when required. On site diagnostics and problem solving if necessary.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
GoodMaps supports new users with both in-app guidance and online resources.
The GoodMaps app includes a built‑in tutorial that walks users through key navigation features the first time they use the service and can be revisited later as needed. In addition, the Connect knowledge hub at https://connect.goodmaps.com provides searchable knowledge base articles, how‑to guides, and supporting documentation so users and venue teams can learn features, troubleshoot issues, and onboard at their own pace. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- N/A/ No end user data is collected.
- End-of-contract process
- Support for computer vision modelling and maps is disabled, and this data is either deleted or retained, subject to the customer’s choice.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- GoodMaps mobile apps provide real-time, turn-by-turn, voice-guided indoor navigation from your live position, including accessible routing, haptics, and screen‑reader support, while the desktop and web experience focuses on browser-based venue exploration, POI search, and route preview, and is typically used for planning or kiosk displays rather than full live navigation, which is handed off to the mobile app.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Via a dedicated app, web map, or integration into third-party apps.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Yes, see: https://goodmaps.com/research/
- API
- Yes
- What users can and can't do using the API
- Buyers can emulate the functionality of our proprietary in-house app.
- API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Our core technology offering is visual positioning, which can be applied to an extensive range of applications – including navigation and wayfinding – but is essentially unrestricted, subject only to environmental suitability.
Scaling
- Independence of resources
- We provide elastic, real-time clustering that automatically scales in response to usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Weekly aggregated usage of the Saas platform on a per-venue basis. To include usage of the platform, route ratings, and top destinations.
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- We have no identifiable user data.
- Data export formats
- Other
- Other data export formats
- N/A for users
- Data import formats
- Other
- Other data import formats
- N/A for users
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.5% uptime SLA
- Approach to resilience
- Available on request.
- Outage reporting
- https://status.goodmaps.com
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- We enforce multi-factor authentication (MFA) for all privileged and support access, and do not allow shared accounts or generic logins.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- GoodMaps follows recognised industry software security best practices and aligns with the UK Software Security Code of Practice principles, alongside widely adopted secure development and cloud security standards.
- Information security policies and processes
- Available on request.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our configuration and change management processes follow industry best practices and are built around automation, review, and traceability. Application and infrastructure configurations are defined as code and stored in version-controlled repositories, with changes implemented through CI/CD pipelines. All non-trivial changes are peer reviewed, tested in pre-production environments, and require approval before deployment to production. We maintain audit trails for configuration and code changes, apply segregation of duties for sensitive updates, and use monitoring and alerting to detect and roll back problematic changes quickly.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Our vulnerability management approach is proactive, automated, and risk-based. We run regular authenticated vulnerability scans across our infrastructure and applications, supplemented by periodic penetration testing. Identified issues are triaged using industry-standard severity ratings (for example CVSS), prioritised based on asset criticality and exploitability, and tracked through to remediation in our ticketing workflow. Patching and configuration fixes are deployed via our standard change management and CI/CD processes, with post-remediation validation scans to confirm closure and reduce the window of exposure.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our protective monitoring approach combines centralised logging, real-time alerting, and regular review. Security‑relevant events from infrastructure, applications, and access controls are collected into a central logging platform, where they are retained for forensic analysis and compliance needs. We apply correlation rules and anomaly detection to generate alerts for suspicious or high‑risk activity, with defined playbooks for triage, incident escalation, and response. Logs and alerts are periodically reviewed to tune detection rules, close visibility gaps, and ensure monitoring remains aligned with evolving threats and best practice.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management approach is structured, responsive, and focused on learning. Incidents arise from monitoring alerts or manual reports and are logged in a central system with clear ownership and priority. We triage based on impact and urgency, follow runbooks for investigation and containment, and escalate to specialists when required. Major incidents trigger a coordinated response with defined communications and regular updates. After resolution, we run post‑incident reviews to identify root causes and improve our controls, monitoring, and processes.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
-