Managed Object & S3 Storage
Wasabi Cloud Storage is a cloud storage solution for storing, protecting, and retrieving files, backups, video, and large datasets. It uses fast tier, S3 compatible access, and built-in security controls to simplify cloud storage for organisations of any size. Fully managed by Qnetix.
Features
- Single-tier hot cloud storage for all data types
- S3 and IAM API compatible object storage
- Encryption in transit and at rest
- Object Lock with compliance and governance modes
- Covert Copy virtual air-gapped immutable copy
- Multi-user authentication for sensitive access
- Global storage regions with replication support
- Account Control Manager for multi-account governance
- Data Transfer Appliance for large data ingest
- AI metadata tagging for media discovery
Benefits
- Simplifies storage operations by removing tier decisions
- Keeps data readily accessible for fast recovery
- Strengthens ransomware resilience with immutable backups
- Protects sensitive data against insider and external threats
- Supports compliance and evidential integrity requirements
- Extends existing backup tools without workflow changes
- Scales video retention without new on-prem hardware
- Enables faster media discovery through AI tagging
- Improves governance across departments and customers
- Supports hybrid deployments with secure private connectivity
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 8 0 1 3 2 4 7 1 8 8 5 9 4 5
Contact
Qnetix Ltd
Qnetix - Your Trusted Technology Solutions Partner
Telephone: +443333355673
Email: sales@qnetix.io
About your service
- Service categories
-
Systems Infrastructure Software
Storage
Data replication and protection
- Data Protection Software
- Backup and Recovery Reporting Software
Archiving
- File and Other Archiving Software
Storage infrastructure and device management
- Storage Access and Path Management Software
- Other Storage Management and Infrastructure Software
Software defined storage controller
- Object-Based Software-Defined Storage Controller Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
- Response times are based on priority levels: P1 (Critical) within 4 hours, P2 (High) within 8 hours, P3 (Medium) within 2 business days, and P4 (Low/Requests) within 3 business days. This structured approach ensures urgent matters are addressed promptly while maintaining consistent service for all enquiries.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support includes business-hours assistance and optional 24/7/365 support across all priority levels. Each customer is assigned a dedicated Technical Account Manager as the primary point of contact for service oversight, escalations, service reviews, reporting, and strategic roadmap alignment, alongside a dedicated Principal Engineer providing deep technical expertise, architectural guidance, troubleshooting, and direct incident resolution and optimisation support.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Our services are designed to be easy to consume and simple to use. New customers provide a list of authorised contacts and access levels. We engage directly with those contacts, provide documentation, and offer training where required. Standard onboarding and offboarding are included at no cost; additional onboarding support is available at a pre-agreed rate.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- We do not charge for standard off-boarding, allowing organisations to exit the service without penalty. If extensive project management or large-scale support is required, charges may apply, subject to prior agreement with the customer before termination.
- End-of-contract process
- We will work with you to agree a plan for closing your account and assist with exporting and downloading your data. Users can also download their data directly.
- Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Fully mobile compliant with similar functionality as available on the browser.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AAA
- API
- Yes
- What users can and can't do using the API
- Standard API services available across the full lifecycle.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- All customer resources are logically segmented and, where required, fully isolated to prevent contention between users. Capacity is monitored continuously using performance and utilisation metrics, allowing proactive scaling and rebalancing before service degradation occurs. Controls are in place to prevent noisy-neighbour impact. For customers with higher assurance requirements, services can be deployed as isolated, dedicated tenants with reserved capacity to guarantee consistent performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Service availability, deduplication rates, successful backups, restores, active users, license allocation, growth rates.
Not limited to the above and many more available. - Reporting types
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- We will work with you to create a technical plan and provide assistance.
- Data export formats
-
- CSV
- ODF
- Other
- Data import formats
-
- CSV
- ODF
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- 99.5% uptime
- Approach to resilience
- The service is designed for high resilience using a multi-datacentre architecture. Customer systems are replicated across separate data centres or cloud locations to remove single points of failure. This enables automatic failover, data redundancy, and continued service availability in the event of hardware, network, or site-level incidents. Further architectural and datacentre resilience details are available on request.
- Outage reporting
- Outages of the system availability or the storage component are communicated to all assigned administrators within a cloud instance via email as well as via the Support Portal.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Access restrictions in management interfaces and support channels
- Only authorised contacts are granted access rights / access.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Annual audits
- Information security policies and processes
-
Dedicated Security team that is responsible for security governance. This team includes dedicated personnel that oversee security operations, certifications, and internal audit. The CISO reports to the company MD.
Documented policies include:
Access Control Policy,
Audit and Accountability Policy,
Configuration Management Policy,
Contingency Planning Policy,
Identification and Authentication Policy,
Information Security Policy,
Information Technology Policy,
Personnel Security Policy,
Physical & Environmental Security Policy,
Risk Assessment Policy,
System & Information Integrity Policy,
Vendor Management Policy,
Business Continuity Plan - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Use of industry tools to help manage and deploy, using our own change management policies and methods. Any changes are controlled under project management and done with validated testing to ensure changes are stable.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Own policies and maintaining high level awareness of industry approaches and fixes to defined issues and ensuring adoption of these fixes as soon as is possible.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Operations team monitoring the services 24x7x365. Systems are monitored for performance, access, security and intrusions. All activity is logged to our central logging and monitoring platform.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Documented Incident Response Plan that includes steps to respond to security incidents including identification, investigation, response, mitigation, customer notification, and root cause analysis.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Free trials are available. Resource limits and timeframe are agreed on a case basis.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 1.5%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 2.5%
- Over £5,000,001
- 3%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-