Skip to main content

Help us improve the Digital Marketplace - send your feedback

XEROX (UK) LIMITED

Xerox IT Solutions - Arctic Wolf - Aurora Endpoint Security

Aurora Endpoint Defence delivers advanced endpoint protection and detection using AI driven prevention, behavioural analysis, and MITRE ATT&CK framework mapping. It helps organisations block malware and exploits, gain deep visibility into threats, and strengthen security posture to reduce risk across all endpoints.

Features

  • AI & ML Malware Prevention (EPP)
  • Lightweight Agent
  • Device Control
  • Offline Detection
  • Legacy OS Support
  • Endpoint Detection and Response (EDR)
  • Mitre Attack Framework Mapping
  • Threat Hunting

Benefits

  • Zero-day malware protection
  • Real-time protection
  • Automated response
  • Low resource consumption
  • Artificial Intelligence & Machine Learning

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uxb.bidteam@xerox.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 8 5 0 4 4 6 1 2 5 2 6 3 9 1

Contact

XEROX (UK) LIMITED Steve Young
Telephone: 01895251133
Email: uxb.bidteam@xerox.com

About your service

Service categories

Systems Infrastructure Software

Security

  • Endpoint security
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
No
System requirements
  • Windows XP SP3 (32/64-bit) with KB 968730 hotfix or above.
  • Windows Server 2003 SP2 with KB 968730 hotfix or above.
  • Mac OS X 10.9 (Mavericks) and above.
  • RHEL/CentOS 6/7+
  • Supports the SSE2 Instruction Set.
  • 2GB RAM
  • 500MB Disk Space (More if logging is enabled)
  • .NET Framework 3.5 SP1 or later
  • Aurora Focus requires Windows 7 or Above.

User support

Email or online ticketing support
Yes
Support response times
Standard support (included) is 8am - 8pm Mon - Fri ET. Premium support provides 24x7 support at additional cost
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
No
Support levels
We have 2 support options: 1. Standard support - 8am-8pm Mon-Fri ET web based ticketing 2. Premium support 24x7 online and phone with reduced response time.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide remote onboarding services as well as full product documentation on our website.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data is removed 30 days after the end of contract
End-of-contract process
Documentation is available free of charge, all onboarding services come at additional cost.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Essentially 2 separate products due to the OS differences but using the same AI technology. Desktop capability focuses on malware protection and EDR capabilities while mobile focuses on malicious app, sideload protection and smishing protection.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Cloud console where Aurora Endpoint Defence is configured
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Aurora's web-based management console and user interfaces are designed to be perceivable, operable, and understandable for users with diverse abilities. WCAG 2.1 AA compliance covers critical accessibility features such as keyboard navigation, sufficient colour contrast, screen reader compatibility, and support for assistive technologies, making it suitable for most enterprise accessibility requirements.
API
Yes
What users can and can't do using the API
Arctic Wolf provides RESTful APIs for registered organisations to manage their resources. To access the User API resources, the client will need to follow the authentication and authorization flow as defined on the website.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
This is handled by the underlying public cloud our technology platform is architected within. Arctic Wolf is architected to be a multi-tenanted, highly scalable service. More information available on request.

Analytics

Service usage metrics
Yes
Metrics types
License quantity and usage is provided in the console.
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
ARCTIC WOLF NETWORKS UK LTD

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export data directly from the Aurora console using the built-in report export feature, or retrieve data programmatically through RESTful APIs.
Data export formats
  • CSV
  • Other
Other data export formats
RESTful API
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
At this time and as a standard operating practice, we do not include specific availability SLAs in our solutions agreement.
Approach to resilience
Available on request
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Users can only be added and removed to the support portal by an authorised technical point of contact.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Available on request
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and Change Management processes are in place with formal management responsibilities and procedures assigned to ensure appropriate change control. Changes are logged for audit and all relevant information is retained.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability scanning of the support platform is performed using industry leading services. Processes are in place to ensure that patching and remedial actions are taken in a regimented and consistent fashion to limit the business impact of newly discovered vulnerabilities.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective Monitoring Approach conforms with ISO27001 Standards for logging and monitoring our services, and how to identify, handle and respond to incidents quickly.
Incident management type
Supplier-defined controls
Incident management approach
ISO27001 Standards
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We have Aurora Test Drive where customers can test the solution in a virtual sandbox and also a Proof of Concept where they can test the solution in their own environment.
Link to free trial
https://arcticwolf.com/solutions/endpoint-security/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0.01%
Between £250,000 and £500,000
0.01%
Between £500,001 and £1,000,000
0.01%
Between £1,000,001 and £2,500,000
0.01%
Between £2,500,001 and £5,000,000
0.01%
Over £5,000,001
0.01%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Thursday 11 July 2024
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Friday 15 March 2024
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
0eab3d37-9204-413e-9c9c-bd6fd5e69c99
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Ce7299cc-729f-4f32-81fb-f3bc41540d66
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uxb.bidteam@xerox.com. Tell them what format you need. It will help if you say what assistive technology you use.