Integration Platform as a Service (iPaaS)
iPaaS is a suite of cloud services enabling development,execution and governance of integration flows connecting any combination of on premises and cloud based processes, services, applications & data within individual or across multiple organisations. AIM (Agilyx Integration Machine) is an Agilyx owned and developed iPaaS system.
Features
- Receive immediate ‘web hook’ events when the source system errors
- Polling file directories (SharePoint, DropBox, SFTP etc)
- Regular schedule (minutes, hours, days, weeks etc)
- Receiving an email, tweet or SMS
- Receiving an API call
- Receiving an EDI document
Benefits
- Streamline business operations
- Improve the efficiency of data management
- Improve customer experience and interactions
- Connect your organisation’s disparate software applications
- Reduce costs
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 5 6 8 9 8 5 3 0 7 1 4 1 5 9
Contact
AGILYX EMEA LTD
Julie Taylor
Telephone: 01628 637266
Email: julie.taylor@agilyxgroup.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Any solution that needs to communicate with another solution. these can be external or third party solutions.
- Cloud deployment model
- Public cloud
- Service constraints
- Solutions requiring integration must have the ability to produce an output.
- System requirements
- Fully Managed Cloud Service
User support
- Email or online ticketing support
- Yes
- Support response times
- We operate a follow the sun support model and typically respond within 2 hours.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide one support level
You will be associated with a Customer Relationship Manager - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- The service is deplyed by our in house development team and created for the number of endpoints required by the customer. Offsite training and documentation is supplied.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Data is not stored by the service per se, data passes through the services for transformation, mapping and routing purposes. Users can extract their audit data and any stored data via query when desired.
- End-of-contract process
- The contract includes base costs, hosting and data storage. The number of endpoints required make the contract variable and the implementation of the product is a separate cost.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Via a link
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- The service is built on the basis of integrations, therefore, the service can be accessed through API where data is moved from one solution through the AIM to another solution.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The service in itself is based on development, it can be accessed to move data from any one system to any other system, there is development work required.
Scaling
- Independence of resources
- Our services uses the latest Microsoft Azure technology meaning every interaction is independent of the next, we user commercially reasonable efforts to make AIM available 99.5% of the time.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Number of transactions passed/failed and success/failure metrics.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- This is not usually required, however, users can extract logs via code work if required.
- Data export formats
-
- CSV
- Other
- Data import formats
-
- CSV
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- Agilyx operate an information security program designed to protect Customer Data processed through the Hosting Environment using industry standard policies and technologies.
- Data protection within supplier network
- Other
- Other protection within supplier network
- Agilyx operate an information security program designed to protect Customer Data processed through the Hosting Environment using industry standard policies and technologies.
Availability and resilience
- Guaranteed availability
-
Agilyx will use commercially reasonable efforts to make AIM available 99.5% of the time excluding any of the following periods:
(a) planned downtime; and
(b) unscheduled downtime caused by: (i) circumstances beyond Agilyx’s reasonable control (including, but not limited to: acts of God, acts of government, flood, fire, earthquake, civil unrest, acts of terror, strike or other labour problem, hosting provider failure or delay, issues related to Third Party Integrated Applications, or denial of service attacks); (ii) circumstances entitling Agilyx to suspend access to AIM under the terms of this Agreement; and (iii) the Customer’s or a User’s failure to use AIM in accordance with Agilyx documentation. - Approach to resilience
- Working with MS Azure our data follows all MS Azure resilience protocols. Further information is available on request.
- Outage reporting
- E mail alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is limited to authorised users only.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- The Agilyx global Information Security Policy can be provided upon request. Agilyx is accredited to ISO 27001 Information Security Management.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- AIM Cloud relies on the expert services of Azure, who provided the underlying platform, network connectivity and System software. The Azure platform offers High Availability, Fault Tolerance, and redundancy at all levels, and components are automatically replaced at the end of their lifetimes or when failed - all contributing to the AIM system availability SLA of 99.5% . deployments within Azure allow everyone to benefitfrom their experience of running highly secure and compliant online services
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Deployments within Microsoft Azure allow everyone to benefit from their experience of running highly secure and compliant online services around the globe (such as Microsoft Cyber Defense Operations Centre, a 24x7x365 state-of-the-art cybersecurity and defence facility). AIM Cloud has implemented industry leading anti virus, intrusion prevention system and intrusion detection solutions (IPS IDS). AIM Cloud works with R&D teams to identify, mitigate and share information about known risks. Agilyx uses log monitoring and analyses to identify usage anomalies and exceptions. Software patches are applied during the maintenance window, but security patches are applied immediately.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- AIM Cloud’s end to end service includes hardware and system software, monitoring, management and maintenance of the Agilyx software and environment in Azure. A continuous 24x7x365 monitoring program is in place to detect and resolve infrastructure and application issues in order to meet the Agilyx application availability targets. The monitoring covers solution health, availability and response times. Prioirity 1 alerts generated are handled by Agilyx staff 24/7/365. see also response concerning Incident Management Approach.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Agilyx will take prompt action to respond to any Security Incident and to prevent the further unauthorized use or disclosure of Customer Data, and/or to correct the issues within AIM (to the extent that AIM gave rise to such Security Incident).
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 15 January 2025
- What the ISO/IEC 27001 doesn’t cover
- The scope of this approval is applicable to: The design, development, provision and support of Unit4 software products and associated consultancy, technical and managed IT services. Statement of Applicability v2. The scope covers all UK activities, and also include Global activities, hosting, SaaS etc
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- QAS International
- ISO 9001 accreditation date
- Monday 10 November 2025
- What the ISO 9001 doesn’t cover
- We are exempt from M08 monitoring and Measuring equipment
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- SyberNet Self Assessed Certification
- PCI DSS accreditation date
- Saturday 14 January 2017
- What the PCI DSS doesn’t cover
- The service is deployed as a hosted service, via our partner SyberNet, who are required to run and maintain it in a PCI compliant environment. Sybernet are currently a Level 2 service provider with less than 300,000 transactions annually and so they complete an SAQ, a Quarterly scan by an ASV (they use Qualys as their Approved Scanning Vendor) and provide an attestation of compliance (AOC).
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 29a5e660-848c-4905-bd25-51c0df414642
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 270017
- SOC 1 (type 1 and 2)
- SOC 2
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-