Skip to main content

Help us improve the Digital Marketplace - send your feedback

AURAQ LIMITED

Mendix Low Code Development

AuraQ has extensive experience delivering low-code solutions at speed and scale. Providing tailored applications to solve complex business challenges, our development team has an in-depth knowledge of the low-code development environment and we specialise in the delivery of agile solutions to support a range of functions.

Features

  • Integrate with other external or internal systems and services
  • Git-based version control
  • Tools to gather and process end-user feedback
  • Built-in tools for Agile project management methodologies
  • Deploy to any cloud, on-premise environment, or edge device
  • Supports native iOS and Android applications
  • Build reusable components with Java and Javascript
  • Leverage open AI/ML models with the Mendix Machine Learning Kit
  • Build reusable components and microservices
  • Visualize data with charting capabilities

Benefits

  • Rapidly build and deploy custom web and mobile apps
  • Out-of-the-box templates, widgets and plug-ins
  • Supports the entire application development lifecycle
  • Manage your applications in the cloud of your choice
  • Extend the capabilities of legacy systems
  • Quickly deliver customer-facing mobile apps
  • Reduce development time by up to 90%
  • One-click deployment
  • Rapid, iterative, and collaborative design
  • Accelerated app delivery

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at mike.clarke@auraq.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 1 7 8 8 8 3 6 0 2 9 9 6 4 5

Contact

AURAQ LIMITED Mike Clarke
Telephone: 07879 080375
Email: mike.clarke@auraq.com

About your service

Service categories

Application Development and Deployment

Application development

  • Development languages, environments and tools
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
No.
System requirements
None.

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Depends on the customer's requirements.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Depending on the platform edition of choice customers will get Gold or Platinum Support. Support fees are included in the platform fee. Mendix also offers Premier support for mission critical systems with dedicated support engineers. AuraQ can also provide application level support tailored to your requirements.

Cost is dependent on number of users and response times required.

An account manager is provided.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Access to the Mendix development environment is free of charge. We provide training for developers to work through rapid certification, intermediate and then to advanced level. Mendix provides a full on-boarding program with our Digital Execution Program to get clients up and running extremely quickly. Mendix offers free online training for all platform users. Our Introduction Course will quickly get your team up to speed so you can build robust and adaptable Mendix applications in days. To explore more advanced features and topics there is free access to online documentation and a very active forum and community. To further build your expertise Mendix provides Expert Webinars that are given by community Experts around platform. In addition to online training Mendix provides (on site) Classroom Training and Certification and Consulting services as detailed in the SFIA document.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Mendix protects your investment in model-driven development, with a fully documented formal meta model. Mendix provides a Model API & SDK for exporting models including meta data, export to other RAD Platforms, 3GL programming languages (Java, .Net, Python, etc..) and Export to your target architecture (Spring, Hibernate, etc..) Models can be exported at any time and reimported for later use; even after contract end, Mendix models will still run in the Mendix Free Edition.
End-of-contract process
The Mendix contract covers the Mendix platform and runtime services. Any model or application developed and deployed on the platform remains the IP of the customer and as such can be migrated as mentioned above should the contract end. Even after this, the model could be imported and used on the Mendix free edition albeit with limitations on users and uptime.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Via the browser.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mendix native mobile apps are truly native mobile apps based on React Native. Native mobile apps differ from hybrid apps in that they do not render inside a web view. Instead, they use native UI elements, which results in faster performance, smooth animations, natural interaction patterns (like swipe gestures), and improved access to all native device capabilities
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The Mendix Platform provides unified access to a developer portal for developers to define application projects, assign team members, manage scope and progress. Cloud Portal for DevOps engineers and administrators to manage application deployment and operations.
Accessibility standards
None or don’t know
Description of accessibility
Via the browser.
Accessibility testing
Mendix is committed to testing with assistive technology users, for example those with colour blindness or other eyesight impairments. This testing is typically delivered as part of the testing of applications developed on the platform and is therefore customer deployment specific.
API
Yes
What users can and can't do using the API
Mendix provides Platform APIs for all relevant steps in the application lifecycle. Mendix also provides a Model SDK to access application models from outside.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Based on the principles of model-driven development, Mendix provides a single IDE. From creating data models to integrations, developers can build apps with confidence and take on complex tasks with ease. All applications developed with Mendix are cloud-native, containerised, and portable by default. Developers have the freedom and flexibility to deploy and scale anywhere - public, private, hybrid clouds, or on-premises.

Scaling

Independence of resources
Each application on the Mendix Cloud runs in an application environment on one or more containers and has dedicated resources allocated to the application environment. The use of containers. Containers support a true microservices approach to development. Applications or parts of applications can be scaled individually, as required, and without needlessly scaling others simultaneously.

Analytics

Service usage metrics
Yes
Metrics types
Infrastructure or application metrics Metrics types • CPU • Disk • HTTP request and response status • Memory • Network • Number of active instances.
Reporting types
  • API access
  • Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Siemens / Mendix

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Data export can be achieved in a number of ways . End users of the application can be provided with the option to export selections of data to a CSV or Excel format. Any data stored in the system can be exported via Odata (Open Data Protocol) which can be used by most industry standard reporting software or even an Excel spreadsheet. Finally, for more advanced data exporting requirements data can exported by a REST service which also allows the data to be transformed or manipulated if needed.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • JSON
  • XLSX
  • XML
  • Odata
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • Odata
  • XLSX
  • JSON
  • XML

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
99.95% uptime guarantee applies for applications with fallback and horizontal scaling configured in Mendix Cloud V4.
Without fallback and horizontal scaling configured the uptime guarantee is 99.5%.
Approach to resilience
Mendix Cloud Runs on AWS globally, and we make use of AWS multi-AZ options for resilience. In addition, for applications that are scaled horizontally, where the Mendix Runtime Engine runs on multiple containers within an application environment, applications will continue to run if one of the containers would go down. Lastly, for all applications running on the Mendix Cloud, the health manager is checking application availability and will try to auto restart if an application environment would go down.
Outage reporting
Mendix uses https://status.mendix.com which has an API and generates mail alerts. Mendix has service monitoring per application which is a dashboard for project members and can receive email alerts on outages or issues specifically to your application.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
IP Filters MFA Public key authentication for SSH Username + password Integration with SSO (Azure ID) with MFA User access review every quarter.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ISO/IEC 27017 Certification ISO/IEC 27018 Certification ISAE 3000 Type II Assurance Report ISAE 3402 Type II Assurance Report SOC 1 Type II Assurance Report SOC 2 Type II Assurance Report SOC 3 Type II Assurance Report PCI DSS Level 1 Service Provider Attestation of Compliance Cyber Essentials (UK)
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Any components used by customers in our cloud follows the change management process. Every change at least has: - Manager approval - Is tested - Peer reviewed - Has acceptance criteria from management - Scanned using Veracode, Snyk and SonarQube.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Weekly vulnerability assessments, 13 penetration tests per year, HackerOne managed responsible disclosure and HackerOne managed bug bounty. Times are aligned with NIST 800-53. Multiple sources are used, US-CERT, Snyk, VeraCode, Tenable.IO, HackerOne.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Mendix uses AWS as service provider which has identification capabilities for potential compromises, Mendix deployed Wazuh on cloud nodes to identify potential compromises. Mendix follows it's security incident management policy which is based on NIST 800-61. Within 36 hours we report towards the customer about such incidents.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Mendix has multiple pre-defined processes in place for incident management which are part of our ISAE 3402 report. Using our support portal. Informing the technical contact of a Mendix Application.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Wednesday 14 November 2018
What the ISO/IEC 27001 doesn’t cover
None.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Wednesday 22 January 2014
What the ISO 9001 doesn’t cover
None.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at mike.clarke@auraq.com. Tell them what format you need. It will help if you say what assistive technology you use.