Security. Accountability. Trust.
Designed for public-sector accountability
Service Street is being designed around the security, privacy and accountability requirements expected of software used by UK local government.
- Protecting organisational and personal data
- Controlling access appropriately
- Maintaining clear auditability
- Designing around UK public-sector expectations
At the centre
Your data
Council, organisation and user information held within your own environment.
Identity & access
Role-based permissions and controlled access.
Application security
Secure development principles and controlled application behaviour.
Data protection
Responsible handling of council, organisation and user data.
Tenant isolation
Separation of each council's environment and data.
Auditability
Important actions recorded for accountability.
Resilience
Architecture designed with continuity, backup and recovery requirements in mind.
Built on strong security principles
Security designed around how councils work
Data protection
Designed around UK GDPR principles including appropriate access, purpose limitation and responsible handling of information.
Role-based access
Give users access based on their responsibilities, helping ensure people see and manage only the information relevant to them.
Auditability
Important actions can be designed to create clear records of what changed, when it changed and who performed the action.
Tenant separation
Service Street's multi-tenant architecture is designed to keep each council's organisations, users, services and data logically separated.
Resilience
Platform architecture is being designed with backup, recovery and service continuity requirements in mind.
Secure by design
Security should be considered throughout the platform architecture rather than added as an afterthought.
Separated by design
One platform. Separate council environments.
Service Street is designed as a multi-tenant SaaS platform, with each council operating within its own logically isolated environment.
Shared core
Service Street core platform
Council A
Isolated environment
- Organisations
- Users
- Services
- Pricing
- Orders
- Contracts
- Transactions
- Resources
- Data
Council B
Isolated environment
- Organisations
- Users
- Services
- Pricing
- Orders
- Contracts
- Transactions
- Resources
- Data
Council C
Isolated environment
- Organisations
- Users
- Services
- Pricing
- Orders
- Contracts
- Transactions
- Resources
- Data
Council A cannot access Council B's organisations, users or data. Council data should remain isolated even though councils use the same core Service Street platform.
Controlled access
Give the right people the right access
Council traded-services operations involve multiple departments and responsibilities. Service Street is designed around flexible roles and permissions.
Roles & permissions
| Role | Scope | View | Create | Edit | Approve | Export | Administer |
|---|---|---|---|---|---|---|---|
Corporate Administrator Organisation-wide administration | All council services | ||||||
HR Service Manager Manage HR services, customers and contracts | Human Resources | ||||||
Finance Officer Transactions, exports and finance-related information | Finance | ||||||
Service Team Member Operational management | Assigned services | ||||||
School Business Manager Purchase, approve and manage school services | Their organisation |
Corporate Administrator
Scope: All council services · Organisation-wide administration
- View
- Create
- Edit
- Approve
- Export
- Administer
HR Service Manager
Scope: Human Resources · Manage HR services, customers and contracts
- View
- Create
- Edit
- Approve
- Export
- Administer
Finance Officer
Scope: Finance · Transactions, exports and finance-related information
- View
- Create
- Edit
- Approve
- Export
- Administer
Service Team Member
Scope: Assigned services · Operational management
- View
- Create
- Edit
- Approve
- Export
- Administer
School Business Manager
Scope: Their organisation · Purchase, approve and manage school services
- View
- Create
- Edit
- Approve
- Export
- Administer
Clear accountability
Know what changed, when and by whom
Public-sector systems need clear accountability. Service Street is designed so important actions can be recorded and reviewed.
Audit trail
Example day view
- 12:41
Sarah Jones — Changed HR Advisory price from £1,200 to £1,240.
Product · HR Advisory
- 12:47
Sarah Jones — Published HR Advisory.
Service · HR Advisory
- 14:18
Oakwood Primary — Submitted an order.
Order · ORD-2027-0481
- 14:34
Business Manager — Approved order.
Order · ORD-2027-0481
- 14:35
System — Activated HR Advisory contract.
Contract · CON-2027-0312
Responsible data handling
Designed around responsible use of data
These are the data-handling principles guiding how the platform is being built. Formal policies and contractual terms are agreed with each council as part of deployment.
Data minimisation
Collect and retain only information appropriate to operating the platform.
Purpose limitation
Use information for legitimate platform and service-management purposes.
Access control
Restrict access according to user responsibilities.
Data lifecycle
Plan for appropriate retention, deletion and account-management processes.
Transparency
Make clear how information is used and managed.
Council control
Support appropriate administrative control over council users and organisational information.
Security roadmap
Building towards public-sector procurement expectations
As Service Street develops, our security and compliance roadmap is intended to align with the expectations commonly encountered in UK local-government procurement. The items below are objectives, not accreditations currently held.
- In development
UK GDPR
Design and operating practices aligned with UK GDPR requirements.
- Planned
Cyber Essentials
Planned security accreditation. Not currently held.
- Roadmap
Cyber Essentials Plus
Longer-term accreditation objective. Not currently held.
- Roadmap
ISO 27001
Information-security management roadmap. Not currently certified.
- Planned
Penetration testing
Independent technical testing planned as the platform matures.
- Planned
MFA & SSO
Authentication enhancements, including potential Microsoft Entra ID support.
- In development
Backup & disaster recovery
Formalised resilience and recovery procedures.
No empty badges
Clear about where we are
We believe council buyers should be able to distinguish between what a supplier has today and what it is working towards.
Current approach
- Public-sector-focused architecture
- Role-based access principles
- Auditability built into product design
- Multi-tenant data separation
- UK GDPR-aware product design
Roadmap
- Security accreditations
- Independent penetration testing
- Enhanced identity integrations
- Formalised resilience processes
- Procurement framework participation
We will never display a security accreditation or procurement credential that we do not actually hold.
Security without making the product difficult to use
Security should support council operations rather than creating unnecessary friction for everyday users.
Controlled
Users only access what they need.
Traceable
Important actions can be audited.
Separated
Council environments remain logically isolated.
Practical
Permissions reflect real council and school responsibilities.
Security questions
Answers for procurement and IT teams
Security you can discuss openly
Talk to us about your council's security, data protection and procurement requirements and how they can shape your Service Street deployment.