Cloud Hosting for BI Analytics Data Visualisation, Automation, Reporting & Alerting Service
Differentia Consulting provides UK-onshore Managed Cloud Hosting for AI, BI, IoT platforms. Using AWS and Azure, the service delivers secure environments optimised for AI analytics. It includes full-lifecycle management, #CyberHygiene hardening, and automated scaling. Delivered via #SmarterBI methodology, the service ensures high availability and compliance.
Features
- Ticketing service for reporting infrastructure and connectivity problems.
- Lifecycle management for integration and middleware software licenses.
- Scaling infrastructure to meet changing data and orchestration requirements.
- Monitoring tools to manage infrastructure total cost of ownership.
- Advice on deploying new API and event-streaming features.
- Impact analysis and delivery of infrastructure and gateway upgrades.
- Project management for technical integration and middleware deployment.
- Testing to enhance integration reliability, availability, and performance.
- Infrastructure-level reporting and automated alerting for data pipelines.
- Consulting for API management, messaging middleware, and IoT platforms.
Benefits
- Infrastructure ticket analysis to identify recurring integration bottlenecks.
- UK-based certified team for middleware and orchestration support.
- Expertise across legacy messaging and modern stream processing software.
- Resolution of end-to-end connectivity issues across the integration stack.
- Ad-hoc technical support for API and gateway configuration.
- Planned maintenance for middleware updates to minimize downtime.
- Periodic monitoring of event streams and file transfer health.
- Rapid incident escalation through established integration vendor relationships.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 8 0 4 2 5 2 8 8 9 7 1 8 7 1
Contact
Differentia Consulting
Mari Vartiainen
Telephone: +44 1494 622600
Email: tenders@differentia.consulting
About your service
- Service categories
-
Application Development and Deployment
Integration and orchestration
Business to business middleware
- B2B Gateway Middleware
- B2B Collaboration Networks and B2B Managed Services
- Managed File Transfer
Integration software
- API Management Software
- API Gateway Software
- Integration Platforms
- Connectivity Adapters and Plug-In Software
Event stream processing
- Messaging Middleware
- Stream Processing Software
- Functions Software
- IoT Application Platforms
- Process Mining and Insights Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Qlik, Microsoft, Databricks, Cyferd, customised solutions
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
Service for the hosted solutions are typically supported remotely and during working hours of 9-5. Out of hours by exception.
Maintenance windows typically no more than 5 minutes but sufficient notice will be provided. - System requirements
- Appropriate licences (if not supplied by us)
User support
- Email or online ticketing support
- Yes
- Support response times
- First response within 2 hours during working hours only. No support on Bank Holidays and weekends.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Bronze - on-demand, time and materials based service. Silver - contractual annual software support for customer managed solutions. Gold - contractual annual software support for Differentia Consulting managed solutions. Cost is based on inclusive hours for the contract starting from one hour, including the cost of a technical account manager or cloud support engineer.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Onboarding is led by an Assigned Service Delivery Manager who facilitates an Initial Scope & Requirements Meeting (IS&RM) to align business goals with infrastructure requirements. We then execute a tailored implementation plan, delivering environments remotely or onsite as required.
Training & Documentation
We provide comprehensive knowledge transfer options, including:
Onsite & Remote Training: Tailored sessions for project teams and end-users, covering technical administration and functional use.
User Documentation: Accessible service documentation and technical guides provided in PDF and HTML formats.
Workshops: Specialised sessions for service management and AI orchestration.
Success Management
Post-deployment, we transition users into Success Management, where we monitor initial project aims and provide ongoing consulting to bridge any remaining skills gaps. Our UK-based support desk is then available for continuous technical assistance. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Data is available for export during the life of the service, during business continuity processing, and no specific processes are needed at the end of it other than disposal.
- End-of-contract process
- All services are provided in a T&M basis.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Once completed it is shared in an appropriately formatted PDF.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Scale
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- Platform wide API availability using MCP protocols
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can modify MCP access to meet their own requirements, but not the underlying data set and security protocols.
Scaling
- Independence of resources
- Services are designed to scale horizontally and vertically in line with agreed metrics.
Analytics
- Service usage metrics
- Yes
- Metrics types
- System wide monitoring application is provided for tracking all activity.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- AWS, Azure
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
- Other
- Other data at rest protection approach
- All encryption is handled by the Qlik Cloud security protocols and the use of industry standard tools to encrypt and to protect data at rest
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Users may export data in accordance with the platform and their role-based controls.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- Parquet
- Xlsx
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- Parquet
- Xlsx
- Txt
- Json
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Zero Trust for all public facing services
Availability and resilience
- Guaranteed availability
- 99.9%, no refund.
- Approach to resilience
-
User-managed hosting on AWS and Azure ensures resilience through a "Shared Responsibility Model." While the cloud provider secures the physical infrastructure, the user designs the solution's internal reliability.
Resilience by Design
Modern cloud architectures eliminate single points of failure using three core principles:
Redundancy: Applications are deployed across at least two instances. A Load Balancer (AWS ALB or Azure App Gateway) monitors health and automatically reroutes traffic if an instance fails.
Self-Healing: Using Auto Scaling (AWS ASG or Azure VM Scale Sets), the platform detects server crashes and automatically replaces them with fresh, pre-configured instances.
Decoupled Data: User data and configurations are stored in managed, resilient services like Amazon EFS or Azure Files, which replicate content across multiple locations in real-time.
Datacentre Resilience
Both providers use physically isolated Availability Zones (AZs) within a Region (e.g., London). Each AZ has independent power, cooling, and networking. They are connected by private, high-speed fiber, allowing for near-instantaneous data synchronization. This ensures that even a total facility failure does not result in data loss or extended downtime. - Outage reporting
- Public dashboard
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Via role-based access control
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Description of management access authentication
- Zero Trust
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
Cyber Essentials Plus: We maintain the UK government-backed Cyber Essentials Plus accreditation, ensuring our technical controls (firewalls, secure configuration, user access, malware protection, and patching) are independently audited.
ISO 27001 Alignment: Our Information Security Management System (ISMS) is aligned with ISO/IEC 27001, covering a holistic risk-based approach to people, processes, and technology.
NHS DSPT: We complete the annual Data Security and Protection Toolkit (DSPT) assessment, consistently achieving "Standards Met" (or "Exceeded") to demonstrate compliance with the National Data Guardian’s ten data security standards. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Via service desk and change board
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Differentia Consulting complies with the NCSC 5th Cloud Security Principle through a vulnerability management process audited under Cyber Essentials Plus and aligned with CSA CCM v4.0. Our process includes continuous vulnerability scanning, risk-based prioritization using CVSS, and a mandatory 14-day patching cycle for critical vulnerabilities. This is supported by annual independent CREST-accredited penetration testing and our annual NHS DSPT submission, ensuring robust operational security across our AWS and Azure managed services.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Differentia Consulting utilises an active protective monitoring approach based on our #CyberHygiene framework. We identify compromises through real-time log analysis and automated alerting across AWS/Azure and Qlik/Fabric environments. Responses are managed via a NIST-aligned SIRP, ensuring 1-hour triage for critical incidents and full adherence to NHS 72-hour breach reporting mandates. Our UK-based specialists ensure continuous oversight of infrastructure and application-layer security.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Differentia Consulting follows a robust incident management process governed by our Information Security Policy framework. We utilise pre-defined playbooks for common security and operational events, ensuring consistent responses. Users report incidents via our dedicated ticketing system or email. We provide regular status updates and final incident reports via email, ensuring full transparency and alignment with public sector reporting mandates where applicable.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
- Joint Academic Network (JANET)
- Scottish Wide Area Network (SWAN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Licences are included, services are not included. Trial is between 14 days and 3 months
- Link to free trial
- https://www.qlik.com/us/trial/partner/qlik-cloud-analytics?utm_campaign=trial&utm_medium=partner&utm_source=partnerreferral&utm_team=pmr&utm_content=QCATrial&utm_partner_id=0013z00002hp1TnAAI
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 6%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E32c182c-84a6-467d-8e78-0838a378b523
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 8038aaac-43b3-4c9e-872c-0f482458cf08
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-