OPSWAT MetaDefender Cloud Platform
OPSWAT MetaDefender Cloud is a fully managed SaaS platform providing advanced file security, malware prevention, data sanitisation (Deep CDR), sandboxing, reputation services and DLP. It protects cloud, SaaS and hybrid environments from known, unknown and zero-day threats via APIs, ICAP and native integrations.
Features
- Multiscanning
- Deep Content Disarm and Reconstruction (CDR)
- Proactive Data Loss Prevention (DLP)
- Adaptive Sandbox
- File-Based Vulnerability Assessment
- Private Scanning and Processing
- Organisations Feature
Benefits
- Reduces infection risk and strengthens security through malware detection
- Prevents zero-day threats while securely supporting nested archive files
- Prevents unauthorised data transfer, reducing exposure and supporting compliance
- Detonates malware in controlled environments, recording and classifying file behaviour
- Reduces cyberattack risk by preventing exploitation of application vulnerabilities
- Maintains privacy and confidentiality, preventing unauthorised access to files
- Enhances management and security through access control and licensing
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 3 7 9 9 3 4 6 0 3 9 7 4 7 1
Contact
ORYX ALIGN LIMITED
Carl Henriksen
Telephone: 02076057890
Email: hello@oryxalign.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
OPSWAT MetaDefender Cloud is delivered as a fully managed SaaS and has no material service constraints for buyers.
The service requires: Internet connectivity and use of supported integration methods (REST APIs, ICAP-enabled devices, or supported SaaS integrations)
There are no requirements for customer-managed hardware or specialist infrastructure. - System requirements
-
- Internet connectivity
- Use of supported integration methods
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 24 hours
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support levels based on incident severity (15 minutes to 24 hours)
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- We work in conjunction with OPSWAT and our client to help deploy the solution, providing user documentation as well as technical support. Additional onsite and online training can be provided.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- At contract end, users can extract their data using OPSWAT’s standard export tools and documented APIs. Configuration data, logs, reports, and metadata can be exported in non-proprietary formats such as CSV, JSON, or PDF. Customers retain full data ownership and may export data at any time. Following termination, OPSWAT securely deletes remaining customer data in line with its data retention and secure deletion policies.
- End-of-contract process
-
At the end of the contract, the customer’s access to OPSWAT MetaDefender Cloud will be terminated in line with the agreed contract end date.
Customer data is not retained beyond the period required to deliver the service. Files submitted for scanning are processed in-memory or temporarily and are automatically deleted after analysis, unless otherwise configured by the customer.
Any configuration data, access credentials, and service settings associated with the customer account are securely removed in accordance with OPSWAT’s data retention and secure deletion policies.
If requested prior to contract end, OPSWAT will support the customer with off-boarding activities, including providing information to assist with transition to another service.
The end-of-contract process does not require any on-premises activity and does not incur additional mandatory charges beyond the contract term. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- PDF documentation can be provided on request that has security and classification controls applied to it
Using the service
- Web browser interface
- No
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
-
OPSWAT MetaDefender Cloud is built on a scalable, multi-tenant cloud architecture designed to isolate customer workloads and manage demand effectively.
The service uses resource pooling, workload isolation, and automated scaling to ensure that increases in demand from one customer do not adversely affect the performance or availability experienced by other users.
Traffic management, rate limiting, and capacity monitoring are applied to prevent resource contention and maintain consistent service levels across tenants.
OPSWAT continuously monitors service performance and capacity and scales infrastructure as required to meet demand in line with published service levels.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Ticket response
Ticket resolution
Client sentiment - Reporting types
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- OPSWAT
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Users can export their data through the MetaDefender Cloud management interface and APIs.
Available exports include configuration information, scan results, reports, and audit logs, which can be accessed in standard, machine-readable formats such as JSON and CSV, depending on the service and integration used.
Data is accessed and exported using authenticated, role-based access controls to ensure only authorised users can retrieve information.
OPSWAT does not restrict customers from exporting their data during the contract term or prior to contract end. - Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
OPSWAT MetaDefender Cloud is delivered using a highly available, cloud-based architecture with redundancy and automated failover to support continuous service operation.
Availability commitments and service levels are defined in the service agreement and depend on the subscribed service and support tier. The service is designed to meet high availability requirements, with performance and uptime continuously monitored.
If OPSWAT does not meet the agreed service levels, service credits may be applied in accordance with the terms of the contract. Any service credits or remedies are defined contractually and represent the customer’s sole remedy for service level failures.
Details of availability targets, monitoring, and service credit arrangements are provided as part of the contractual documentation. - Approach to resilience
-
OPSWAT MetaDefender Cloud is designed for resilience using a distributed, cloud-native architecture with built-in redundancy and fault tolerance.
The service is hosted in secure, professionally managed cloud datacentres with resilient power, networking, and physical security controls. Infrastructure components are deployed with redundancy to avoid single points of failure, and automated monitoring and recovery mechanisms are used to detect and remediate faults.
Service capacity and performance are continuously monitored, and the platform is designed to scale automatically in response to demand to maintain service availability.
Backup, disaster recovery, and business continuity arrangements are in place and tested in line with OPSWAT policies. Further details of the datacentre architecture, resilience controls, and disaster recovery approach are available on request under appropriate confidentiality arrangements.
This approach supports the UK government’s cloud security principle for asset protection and resilience. - Outage reporting
-
OPSWAT MetaDefender Cloud reports service outages and service-impacting incidents through multiple communication channels.
Public dashboard: Service status information is made available to customers through OPSWAT service communications and the support portal.
API: There is no dedicated public outage status API.
Email alerts: Customers are notified of service-impacting incidents and planned maintenance via email and the support portal.
Outage communications include relevant information about the nature of the issue and progress updates until resolution, in line with OPSWAT incident management processes.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to MetaDefender Cloud management interfaces and support channels is restricted using role-based access controls (RBAC) and strong authentication mechanisms.
Administrative access is limited to authorised users and granted on the principle of least privilege. User roles and permissions can be configured to control access to management functions and sensitive information.
Access to management interfaces is protected using secure authentication and encrypted connections. Support channels, including the customer portal, require authenticated access and are restricted to authorised customer contacts.
Access rights are reviewed periodically and adjusted as required to maintain security and compliance. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
OPSWAT follows a formal information security management framework aligned with internationally recognised standards and best practices.
Information security policies and processes are defined, maintained, and enforced in accordance with ISO/IEC 27001 and SOC 2 Type II requirements. These policies cover areas including access control, data protection, incident management, vulnerability management, business continuity, and supplier security.
Security governance is overseen by senior management, with defined roles and responsibilities for information security, risk management, and compliance. Information security risks and incidents are escalated through established reporting structures to appropriate management and, where required, executive leadership.
Compliance with security policies is ensured through a combination of technical controls, operational procedures, staff training, and regular internal and external audits. Policies are reviewed and updated on a regular basis to reflect changes in risk, technology, and regulatory requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
OPSWAT MetaDefender Cloud follows formal configuration and change management processes designed to maintain service stability, security, and compliance throughout the service lifecycle.
Components, including infrastructure, platform services, and application configurations, are tracked and managed through controlled configuration management systems. Assets are versioned and maintained through their lifecycle to ensure traceability, consistency, and accountability.
Changes to the service are subject to change management process. Proposed changes are assessed for operational and security impact prior to implementation, including consideration of potential risks to confidentiality, integrity, and availability.
Changes are tested in controlled environments before deployment. Deployments are performed using controlled, auditable processes. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
OPSWAT operates a formal vulnerability management process to identify, assess, and remediate potential threats to MetaDefender Cloud. Threats are assessed using a risk-based approach that considers severity, exploitability, and potential impact to confidentiality, integrity, and availability.
Vulnerability information is sourced from multiple channels, including vendor advisories, industry threat intelligence feeds, security researchers, and automated vulnerability scanning tools.
Security patches and mitigations are prioritised based on risk and deployed in line with defined patch management timelines. Critical security patches are applied as soon as practicable, following testing in controlled environments to minimise service disruption. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
OPSWAT operates continuous protective monitoring across MetaDefender Cloud to detect potential security events and compromises. Monitoring includes logging and analysis of system activity, security alerts, and anomalous behaviour across infrastructure and application components.
Potential compromises are identified using automated monitoring tools, alerting mechanisms, and threat intelligence indicators. When a potential compromise is detected, incidents are triaged, investigated, and contained in line with OPSWAT’s incident response procedures.
Security incidents are prioritised based on severity and impact. Response actions are initiated promptly, with critical incidents escalated immediately to appropriate technical and security teams for resolution. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
OPSWAT operates a formal incident management process for MetaDefender Cloud, with pre-defined procedures for common security and service events. These procedures support consistent identification, triage, escalation, and resolution of incidents.
Users can report incidents through the OPSWAT support portal, email, or telephone, depending on the selected support tier. Incidents are prioritised based on severity and impact.
Incident updates and post-incident reports are provided to affected customers as appropriate. Reports may include incident summary, impact, actions taken, and remediation measures, in line with contractual obligations and incident response policies. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Schellman
- ISO/IEC 27001 accreditation date
- Thursday 23 January 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Schellman
- ISO 9001 accreditation date
- Wednesday 5 February 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8f7f3c1b-4253-4cd9-a5c8-ae617e4bd215
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- C94f5175-f45b-49fb-9bbd-855bd667f5b9
- Other security certifications
- Yes
- Any other security certifications
- https://www.opswat.com/legal/compliance-certifications
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-