Skip to main content

Help us improve the Digital Marketplace - send your feedback

CRAXEL UK LTD

Black Forest Platform

Craxel’s Black Forest unifies fragmented organisational data into a secure, AI‑ready knowledge graph, delivering real‑time, contextual insight at scale for cyber defence and analytics, enabling faster, better‑informed decisions while using significantly less compute than traditional data platforms.

Features

  • Builds scalable knowledge graphs at line speed
  • Fuses structured and unstructured data seamlessly
  • Delivers real-time semantic context queries
  • Reduces compute costs by up to 90%
  • Provides zero trust searchable encryption
  • Supports hyperscale storage like AWS S3
  • Enables petabyte-scale complex queries instantly
  • Offers flexible cloud, on-prem, edge deployment.
  • Ingests data from any source rapidly
  • Ensures full customer data control

Benefits

  • Accelerate data‑driven decision‑making with timely, contextual insight
  • Unify siloed data for consistent organisational views
  • Automate data preparation, reducing manual integration effort
  • Reduce time‑to‑insight from hours or days
  • Simplify secure data sharing across departments and partners
  • Enable real‑time exploration of live enterprise datasets
  • Cut infrastructure costs through efficient compute and storage
  • Streamline AI initiatives with governed, high‑quality data
  • Improve incident response using instant contextual data access
  • Maintain compliance with fine‑grained, auditable data controls

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gary.connolly@craxel.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 0 7 2 1 1 2 1 0 1 5 9 1 3 4

Contact

CRAXEL UK LTD Gary Connolly
Telephone: 07718133393
Email: gary.connolly@craxel.com

About your service

Service categories

Application Development and Deployment

Data management

Database management systems

  • Graph Database Management Systems
  • Data Lake Management Systems

Database administration and development

  • Data Modelling
  • Database Development and Optimization

Data integration and intelligence

  • Data Ingestion and Transformation Software
  • Data Access Infrastructure Software
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Black Forest runs on standard cloud and commodity hardware but may require sizing for very high‑throughput deployments. Planned maintenance is scheduled, notified in advance, and designed for minimal disruption. Buyer‑specific constraints, such as data residency, security accreditation, and integration approach, should be confirmed during onboarding and architectural design.
System requirements
Standard cloud infrastructure

User support

Email or online ticketing support
Yes
Support response times
Responses depend on level of Service agreement.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support is provided subject to customer requirement and will be on an agreement between the parties.

This includes Technical Account Managers and Cloud Engineers.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
New Black Forest customers receive a structured onboarding experience designed to get them productive quickly and safely. Craxel provides packaged starter engagements, hands‑on implementation support, and full, role‑based documentation to guide every stage of adoption.

For each new deployment, a Craxel engineer is assigned and guarantees successful installation, initial configuration, and basic integration into the customer’s chosen environment. This includes validating connectivity, security settings, performance baselines, and helping align Black Forest with the buyer’s architecture and operating model. Where required, engineers work alongside buyer teams to define initial data sources, ontologies, and access‑control patterns.

Craxel offers 1:1 calls with customer teams to walk through architecture, usage patterns, and best practices, tailored to specific needs and maturity. Comprehensive documentation is available from day one, including step‑by‑step setup guides, API references, example patterns, and operational runbooks.

After go‑live, Craxel continues to provide remote support and guidance, helping teams embed Black Forest into existing workflows, iterate their data models, and scale usage across additional departments and use cases.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Customers receive all their data back should contract end. Black Forest keeps data under customer control throughout, enabling direct extraction using standard interfaces like SQL, SPARQL, and native APIs into customer storage. Craxel provides engineer-assisted egress by agreement to ensure complete, secure data recovery.
End-of-contract process
Customer have the ability to export their data at any time, allowing for migration if required.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Via a webbrowser or pdf

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Black Forest is accessed primarily through secure APIs and standard tools, not a single monolithic UI. Users interact via:

-Web‑based administrative console for configuration, monitoring, and observability.

-Programmatic access using REST APIs and SDKs for applications.

-Standard interfaces (for example SQL, data‑tool connectors) for analysts and engineers
Accessibility standards
None or don’t know
Description of accessibility
The service is accessed by an HTML 5 web browser
Accessibility testing
N/A
API
Yes
What users can and can't do using the API
What users can do
Provision and configure deployments using automation and infrastructure‑as‑code workflows.
Register data sources, define ingest pipelines, and manage schemas or ontologies.
Insert, update, delete, and query encrypted data at high volume.
Configure access controls, roles, and data‑sharing policies.
Retrieve metrics, logs, and health information for monitoring and observability.

How setup works
Authenticate, then call deployment and configuration endpoints to initialise environments.
Use APIs to connect data sources and define pipelines and transformations.
Apply encryption and security settings programmatically as part of setup.

How users make changes
Adjust ingest settings, mappings, and retention through versioned configuration objects.
Update roles and policies centrally without redeploying the platform.
Evolve datasets, indexes, and query templates via machine‑to‑machine interfaces.

Key limitations
Underlying cloud/on‑prem infrastructure must exist; APIs sit above that layer.
Highly destructive or security‑bypassing actions are restricted to tightly controlled channels, not general application APIs
API documentation
Yes
API documentation formats
  • HTML
  • PDF
  • Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
What can be customised?
Data sources, ingest pipelines, schemas, ontologies, and enrichment logic.
Indexing, retention, and performance profiles for different datasets or domains.
​Security labels, access‑control policies, and compartment structures.

How users can customise?
Use APIs and infrastructure‑as‑code templates to configure pipelines, schemas, and environments.
Apply encryption, labelling, and access‑control policies via security configuration interfaces.
Tune performance, scale, and placement (cloud, on‑prem, edge) through deployment settings.

Who can customise?
Platform and data engineers customise pipelines, schemas, and performance settings.
Security and compliance teams configure policies, labels, and governance controls.
Business data owners define ontologies and domain‑specific semantics within agreed guardrails.

Scaling

Independence of resources
Service deploys to customers own On-prem/Cloud Infrastructure, no shared resources between customers

Analytics

Service usage metrics
Yes
Metrics types
Key metrics include:

Query volume, latency

Data ingestion throughput

Storage utilisation

API call counts by endpoint and client

Access patterns and peak usage periods
Reporting types
  • API access
  • Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Methods:

SQL/SPARQL queries for records and graphs.

REST APIs for bulk/programmatic extraction.

Reverse ingest pipelines to buyer storage (S3, Kafka).
Data export formats
  • CSV
  • Other
Other data export formats
  • Json
  • Xml
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • XML
  • PDF
  • HTML
  • RDF

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
Craxel's network is not connected to customer instance.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Point to point encryption.

Availability and resilience

Guaranteed availability
As deployed software is under the management of the customer, SLAs are subject to agreement, based on use case requirements and agreed in writing by way of a contract negotiation.
Approach to resilience
Multi node replication, kubernetes supported infrastructure provisioning.
Outage reporting
Black Forest provides an API to inform of any outages.

Identity and authentication

User authentication needed
Yes
User authentication
Username or password
Access restrictions in management interfaces and support channels
Black Forest allows users to be assigned selected management interfaces through the UI. Admin users can give or rescind access to specific workflows, data, and interfaces to selected users.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials
Information security policies and processes
Craxel UK's Information Security Policy establishes commitment to protecting information assets via Cyber Essentials. It covers all staff, contractors, systems, and locations processing company data.

Core Objectives: Confidentiality (authorised access only), Integrity (prevent unauthorised changes), Availability (timely access for operations).

Key Roles: Board approves policy/resources; Security Lead manages risks/incidents; Managers enforce compliance; Staff report issues.

ISMS Features: Annual risk assessments, asset inventory, incident procedures, continuous improvement.

Compliance: Monitored via audits, vulnerability tests, metrics. Violations trigger disciplinary/criminal action.

Policy reviewed annually or post-incidents/changes.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Software change management is tracked, and any NUCs are communicated to a client before upgrade.

Through mutual agreement between the parties, and agreed via way of contract amendment.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Regular scanning of our software and the management and monitoring of CVEs
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Security Scanning tools e.g. Snyk, this is then managed with the development team and a patch SLA is agreed.
Incident management type
Supplier-defined controls
Incident management approach
Craxel UK operates a formal incident response process with predefined phases: identification, containment, eradication, recovery, and lessons learned, applied to common events such as malware, phishing, data loss, and unauthorised access. Incidents are reported immediately to the Security Lead by email, phone, or in person. All incidents are logged in an Incident Register and a post-incident report is produced, including timeline, impact, root cause, and remedial actions, which is shared with relevant stakeholders and, where required, regulators and affected customers.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
3%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
7%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
4ced6129-cc3c-4c8f-8227-58b405a20fdd
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Plans for positive actions with community groups.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gary.connolly@craxel.com. Tell them what format you need. It will help if you say what assistive technology you use.