Software-Defined Storage Controller as a Service
Akita provides software-defined storage controller services enabling centralised control of storage capacity, policies and performance. Buyers use a cloud-based management layer to manage storage environments without operating physical infrastructure
Features
- Centralised management of software-defined storage policies and capacity.
- Cloud-based control plane for storage configuration and monitoring.
- Policy-based storage allocation and performance management.
- Integration with supported storage platforms and virtualised environments.
- Monitoring of storage performance, utilisation and health metrics.
- Role-based access control for storage management functions.
- Automated storage provisioning and configuration workflows.
- Secure management interface for controlling storage environments.
Benefits
- Simplifies storage management without operating physical infrastructure.
- Improves visibility of storage performance and capacity usage.
- Reduces operational overhead through centralised storage control.
- Enables consistent storage policies across environments.
- Supports efficient use of storage resources.
- Reduces risk of misconfiguration through policy-based management.
- Improves operational resilience and storage governance.
- Supports scalable storage management as requirements grow.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 9 4 2 9 7 6 5 5 8 2 1 5 3 5
Contact
AKITA SYSTEMS LIMITED
Akita
Telephone: 0330 058 8000
Email: info@akita.co.uk
About the service
- Service categories
-
Systems Infrastructure Software
Storage
Software defined storage controller
- Block-Based Software-Defined Storage Controller Software
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service integrates with existing storage platforms, virtualisation environments and infrastructure management systems, extending buyers’ current storage environments through centralised software-defined control.
- Cloud deployment model
- Hybrid cloud
- Service constraints
- The service requires supported storage platforms and compatible virtualisation or infrastructure environments. Management access depends on network connectivity between storage systems and the service control plane. Planned maintenance is scheduled outside core business hours where possible and notified in advance. The service manages storage control and configuration only and does not include physical hardware supply or installation.
- System requirements
-
- Supported storage platforms compatible with software-defined storage control.
- Supported virtualisation or infrastructure management environments.
- Network connectivity between storage systems and management control plane.
- Appropriate permissions to manage storage configuration and policies.
- Supported web browsers for accessing the management interface.
- Time synchronisation enabled on managed storage systems.
- Firewall rules allowing outbound connectivity to the control plane.
- Compatible operating systems on managed storage controllers.
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is provided via email and an online ticketing system. During UK business hours, initial responses are provided within one business day. Outside business hours and at weekends, responses are provided on the next business day, unless enhanced support arrangements are agreed.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Akita provides standard and enhanced support levels for the service.
Standard support is included in the service price and provides remote email and ticketing support during UK business hours. Incidents are logged, prioritised, and managed through Akita’s service desk, with access to cloud support engineers for investigation and resolution.
Enhanced support is available at additional cost and provides extended support hours, faster response targets, and named escalation contacts. Where required, a dedicated technical account manager can be provided to support service reviews, reporting, and ongoing optimisation. Enhanced support pricing is agreed at call-off stage based on service scope and support requirements.
All support is delivered remotely by Akita cloud support engineers. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Akita supports buyers through a structured onboarding process to help users start using the service. This includes initial service setup, configuration of storage policies, validation of capacity and performance settings, and confirmation of access controls. Users are provided with online documentation covering day-to-day use, policy management, and reporting. Remote knowledge transfer sessions can be provided where required to familiarise users with the service interface and features. Ongoing support is available through Akita’s service desk during early adoption and operational use.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of the contract, buyers can extract configuration data, reports, and usage information through the service interface or via the service API. Data can be exported in commonly used formats to support transition to another service or internal systems. Akita supports buyers during contract exit by confirming data extraction requirements, maintaining access for the agreed exit period, and providing reasonable assistance in line with contract terms.
- End-of-contract process
-
At the end of the contract, Akita works with the buyer to support an orderly service exit. This includes confirmation of contract end dates, continued access to the service for the agreed exit period, and support for exporting configuration data, reports, and usage information through the service interface or API.
Standard contract pricing includes access to the service until contract end and reasonable assistance with data extraction and service close-down. Any activities outside standard exit support, such as extended access periods, bespoke data exports, migration assistance, or additional reporting, are provided at extra cost and agreed with the buyer at call-off stage. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service can be accessed via mobile web browsers to view storage status, alerts, and high-level dashboards. The desktop interface provides full configuration, policy management, and reporting capabilities. Mobile access is intended for monitoring and visibility rather than detailed administrative changes.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, web-based management interface. Users can manage storage policies, capacity, performance settings, and view dashboards and reports. Role-based access controls restrict functions based on user permissions. The interface is browser-based and does not require specialist client software.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The interface is designed using accessible components aligned to WCAG 2.2 AA principles. Testing includes keyboard navigation checks, screen reader compatibility testing, colour contrast validation, and responsive layout testing across supported browsers and devices. Identified accessibility issues are tracked and addressed as part of ongoing service improvements.
- API
- Yes
- What users can and can't do using the API
- The service provides an API to integrate storage management data with existing systems and workflows. Users can use the API to retrieve storage metrics, capacity information, performance data, and status information, and to automate reporting. Limited configuration changes can be made through the API, such as updating monitoring parameters and retrieving policy information. Initial service setup, core storage policy configuration, access controls, and platform-level settings are managed through the web-based service interface. The API does not allow changes that could impact service stability, security, or underlying storage architecture.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Buyers can customise storage policies, capacity allocation rules, performance thresholds, dashboards, and reporting views. Customisation is carried out through the secure web-based management interface and, where appropriate, via the service API. Only authorised buyer users with appropriate role-based permissions can apply or modify customisations. Core platform architecture and underlying storage software are not customisable and remain managed by Akita to maintain service stability, security, and performance.
Scaling
- Independence of resources
- The service is delivered on a scalable cloud platform with logical separation between customer environments. Resource allocation, access controls, and capacity management ensure one customer’s usage does not impact another. Platform performance and capacity are continuously monitored and scaled to maintain consistent service levels for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides metrics including storage capacity usage, performance indicators, policy compliance status, alert volumes, and system health. Metrics support operational oversight, capacity planning, and performance management.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Established third-party software-defined storage platform vendors.
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export configuration data, reports, and usage information through the service interface or via the service API. Data export is available during the contract term and for the agreed exit period in line with contract terms, supporting transition or reuse by the buyer.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Akita targets high availability for the service, delivered on resilient cloud infrastructure with built-in redundancy. Availability targets and service levels are agreed at call-off stage to align with buyer requirements. Service availability is monitored continuously. Where agreed availability targets are not met, service credits may be applied in line with the SLA. Service credits are calculated as a proportion of the affected service charges and applied to future invoices rather than cash refunds.
- Approach to resilience
- The service is designed for resilience using a cloud-based architecture hosted on enterprise-grade third-party datacentre infrastructure. Resilience is achieved through redundancy across compute, storage, and networking components to minimise single points of failure. Data and configuration information are stored on resilient storage services with built-in fault tolerance. The underlying datacentre environment provides resilient power, cooling, and physical security controls. Platform capacity and health are continuously monitored, with scaling and recovery mechanisms in place to maintain service availability. Further technical details on datacentre resilience can be provided on request.
- Outage reporting
- Service outages and service-impacting incidents are communicated through multiple channels. Buyers can view service status and incident updates through the service interface dashboards. Email notifications are issued for significant incidents affecting service availability. Where applicable, outage and incident information can also be accessed via the service API for integration with buyer systems.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through authenticated user accounts and role-based access controls. Permissions are assigned based on least-privilege principles. Administrative access is limited to authorised personnel and reviewed regularly. Support requests require authenticated submission, and access to sensitive actions and information is logged and auditable.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Akita operates a formal information security management framework aligned to ISO 27001. Information security policies cover access control, data protection, incident management, risk management, supplier assurance, and business continuity. Responsibility for information security sits with a named board-level owner, supported by senior management and operational teams. Policies are communicated through onboarding, mandatory training, and regular awareness activities. Compliance is monitored through internal reviews, access controls, incident reporting, and management oversight, with corrective actions tracked to completion.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Service components are tracked through their lifecycle using documented configuration records and version control. Changes are managed through a formal change management process, with assessment of risk, impact, and security implications before approval. Security impact is reviewed as part of change assessment, and changes are tested prior to implementation to minimise risk and service disruption.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Akita assesses vulnerabilities using platform monitoring, vendor advisories, and recognised security alerts. Potential threats are evaluated based on risk and impact to the service. Patches and mitigations are prioritised by severity, with critical updates deployed promptly. Vulnerability information is sourced from software vendors, cloud providers, and recognised security advisory services, with actions tracked through internal security and change management processes.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Akita uses protective monitoring to identify potential security incidents through log review, alerting, and anomaly detection. Suspected compromises are investigated promptly by authorised engineers and escalated where required. Incidents are contained, assessed, and resolved in line with incident management procedures, with response times prioritised based on severity and potential impact.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Akita operates defined incident management processes for common service and security events. Users report incidents through the service desk using email or the online ticketing system. Incidents are logged, prioritised, investigated, and resolved in line with documented procedures. Where required, incident updates and post-incident reports are provided to buyers, outlining impact, actions taken, and resolution.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- British Assessment Bureau (UKAS accredited)
- ISO/IEC 27001 accreditation date
- Friday 18 January 2019
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001 certification does not cover customer-owned systems or infrastructure not managed by Akita Systems Limited, physical security controls at customer premises, end-user devices not under Akita management, or non-IT business activities outside the defined scope of IT support, cloud services, and hosted and recovery services.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- British Assessment Bureau (UKAS accredited)
- ISO 9001 accreditation date
- Thursday 23 April 2015
- What the ISO 9001 doesn’t cover
- The ISO 9001:2015 certification does not cover activities outside the defined scope of IT service delivery, including non-IT business operations, customer-owned systems or processes not managed by Akita Systems Limited, services delivered entirely by third parties outside Akita’s quality management system, and physical site operations at customer premises where Akita does not have operational control.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 56073cca-376a-486b-a991-0f76b99f23b2
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- Cc55b424-1c83-4f89-8550-44e6b24ec430
- Other security certifications
- No
Social value
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement