Secure Access Service Edge (SASE)
SASE delivers secure, cloud delivered access to applications and data. It combines networking and security controls into a single service, supporting remote users, branch sites and cloud workloads with consistent policy enforcement and simplified management.
Features
- Cloud delivered secure access
- Zero Trust network access
- Secure web gateway
- Firewall as a service
- Centralised policy management
- User and device based controls
- Integrated SD WAN capabilities
- Cloud application security
- Real time threat protection
- Scalable global PoP architecture
Benefits
- Simplifies secure remote working
- Reduces network and security complexity
- Improves visibility and control
- Consistent security everywhere
- Faster application access
- Reduced on premises infrastructure
- Scales with business growth
- Supports hybrid and cloud first models
- Enhances user experience
- Lowers operational overhead
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 4 6 8 4 9 3 5 8 3 0 6 7 8 4
Contact
PURE CLOUD SOLUTIONS LIMITED
Nick Matthews
Telephone: 03331506780
Email: support@purecloudsolutions.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Microsoft Entra ID (formerly Azure AD) for identity based access control
Amazon Web Services hosted applications and workloads
Microsoft Azure hosted applications and virtual networks
Google Cloud Platform hosted services
Existing on premises networks and firewalls
Third party SD WAN and networking services - Cloud deployment model
- Public cloud
- Service constraints
- Barracuda Secure Access Service Edge is a cloud delivered service and depends on reliable internet connectivity for access to applications. Planned maintenance is carried out with advance notice and is designed to minimise service impact. Some features and performance levels depend on the selected licensing tier. Where the service integrates with customer owned networks, devices or third party connectivity providers, those components remain outside supplier control and may limit troubleshooting or service guarantees.
- System requirements
-
- Reliable internet connection required
- Supported modern web browser
- Windows, macOS, Linux supported
- IOS and Android supported
- Lightweight client where required
- User authentication via identity provider
- Compatible with standard networking protocols
- No on premises hardware mandatory
- Administrative access via web portal
- Secure device configuration recommended
User support
- Email or online ticketing support
- Yes
- Support response times
- Our internal SLA requires responses to email tickets within 15 minutes. Cases raised by phone are handled immediately where possible. Response times may vary depending on the nature of the issue and whether third parties, such as ISPs, are involved.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Accessible through a website widget.
- Web chat accessibility testing
- An established product provided by a third party supplier, with all testing and development carried out in-house for their proprietary system.
- Onsite support
- Yes
- Support levels
- Level 1 issues cause major disruption to core functions such as service delivery, traffic, billing, or maintenance. They require immediate corrective action, and customers may report them online or by telephone at any time. Level 2 issues seriously affect more than half of system operations and also need prompt attention, though they may be reported only during office hours. Level 3 issues have a limited impact on system performance and do not significantly affect customer service. These may include minor faults or non-urgent queries and can be reported online or by phone within office hours. Level 4 covers general support requests, including configuration, setup, training, or “how to” guidance, and is chargeable unless covered by the agreed services. Response targets range from two hours for Level 1 to twenty-four hours for Level 4, with corresponding workaround times set for each priority level. Support levels vary according to the size and needs of the organisation. Any extended or out-of-hours support falls outside standard provision and will incur additional charges. Pricing for these enhanced services is available on application, ensuring support arrangements remain aligned with each organisation’s requirements.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- Users are supported through a structured onboarding process that includes guided setup, configuration assistance and policy design. Online documentation and knowledge bases are provided, alongside remote training sessions where required. Optional professional services are available for implementation support, migration and administrator training to ensure the service is adopted effectively.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of the contract, users can extract their data through the management interface and API. Configuration data, logs and reports can be exported in standard, commonly used formats before service termination. Support is provided during offboarding to assist with data extraction and ensure customer data is securely removed in line with contractual and regulatory requirements.
- End-of-contract process
- At the end of the contract, the service transitions into an offboarding phase. Users are given time to export configuration data, logs and reports using the management interface or API. Standard offboarding support and data deletion are included within the contract price. Any additional services, such as extended access periods, bespoke data extraction support or professional services assistance, are provided at an additional cost where requested.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The desktop service provides full policy enforcement, advanced configuration options and broader application access. The mobile service focuses on secure connectivity, Zero Trust access and traffic protection optimised for battery life and mobile networks. Some advanced administrative features and detailed reporting are available only through the desktop web interface, while mobile access prioritises usability and performance.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, web based management portal and user access clients. Administrators use the central dashboard to configure policies, manage users and devices, monitor traffic and review security events. End users connect through a lightweight client or browser based access, with security controls applied transparently in the background.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service interface is tested as part of ongoing usability and accessibility reviews using common assistive technologies, including screen readers and keyboard only navigation. Testing focuses on navigation flow, form interaction, contrast and readability. Feedback from accessibility testing is used to inform interface improvements and ensure continued alignment with recognised accessibility standards.
- API
- Yes
- What users can and can't do using the API
- Barracuda Secure Access Service Edge provides an API that allows authorised administrators to integrate with external systems, automate configuration tasks and retrieve service and security information.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Buyers can customise Barracuda Secure Access Service Edge through configurable security policies, access rules, user and device controls, identity integrations and reporting options. Customisation is managed through the service interface and API, without altering the underlying platform.
Scaling
- Independence of resources
- Barracuda Secure Access Service Edge is delivered using a scalable, multi tenant cloud architecture with logical separation between customers. Capacity is dynamically allocated across global points of presence, and traffic is load balanced to prevent congestion. Usage monitoring and automated scaling ensure individual customer demand does not impact the performance or availability experienced by other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides metrics through the management dashboard and API, including user and device activity, traffic volumes, application access, security events and policy enforcement outcomes. Performance metrics such as latency and availability are available, alongside reporting on threats blocked and access attempts. Metrics support operational monitoring, security analysis and service optimisation.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Barracuda
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users export their data through the secure web based management interface or via the service API. Configuration settings, logs and reports can be downloaded using built in export functions in standard formats. API access allows automated extraction where required. Support is available to assist users during the export process.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON for configuration data via the API
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Barracuda Secure Access Service Edge is delivered with a 99.9% service availability target, measured monthly and excluding planned maintenance notified in advance. Availability covers access to the core service platform and management interface.
- Approach to resilience
- The service is designed using a distributed, cloud native architecture across multiple geographically separated datacentres. Traffic is routed through resilient global points of presence with automatic failover and load balancing. Datacentres provide redundant power, cooling and connectivity, and the platform is continuously monitored to detect and recover from failures. Capacity is scaled dynamically to maintain service continuity during demand spikes or component outages.
- Outage reporting
- Service outages are reported through a combination of channels. Customers are notified via email alerts when incidents occur or are resolved. Service status information is available through a public status page, and updates are provided through the management portal. Where applicable, incident notifications and updates can also be accessed via the service API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted using role based access control, strong authentication and least privilege principles. Administrative access requires authenticated user accounts and can be protected with multi factor authentication. Support channels verify customer identity before engaging and limit access to authorised contacts only. All access and administrative actions are logged and monitored to maintain accountability and security.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We operate formal information security and quality management systems aligned to ISO/IEC 27001 and ISO 9001. These define our information security policies, risk management, access control, incident management, change control and supplier assurance processes. Responsibility for information security sits with senior management, with clear ownership and escalation paths for incidents, risks and non-conformities. Policies are reviewed regularly, approved at management level and communicated to all relevant staff. Compliance is enforced through defined procedures, role-based access controls, monitoring, internal audits and management reviews. Staff receive regular training to ensure policies are understood and followed. Independent external audits are carried out to maintain certification, providing assurance that controls remain effective and continuously improved.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Configuration and change management is controlled through a formal change control process. All configuration changes require a ticket to be raised, ensuring each request is logged, assessed and tracked from initiation to completion. The level of approval required depends on the nature and risk of the change, with higher-impact changes requiring written approval from an authorised manager or director. Changes are implemented in line with documented procedures to minimise risk and disruption. Full change logs are maintained, providing a complete audit trail of requests, approvals, actions and outcomes for compliance and review purposes.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- The service follows a structured vulnerability management process. This includes continuous vulnerability scanning, regular penetration testing, and threat intelligence monitoring. Identified vulnerabilities are risk assessed, prioritised, and remediated through patching or configuration changes. Updates are tested before deployment, with audit logging and change control supporting ongoing security assurance.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Protective monitoring is delivered through continuous security and operational monitoring across the platform. Logs, alerts, and events are collected and analysed to detect suspicious activity, policy violations, and service issues. Automated alerts trigger investigation and response, supported by audit logs, reporting, and escalation procedures to maintain security and service integrity.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Yes. Our ISO/IEC 27001–certified information security management system includes a defined incident management approach. We maintain pre-defined procedures for common security and service incidents, covering identification, response, escalation and resolution. Users can report incidents through our support and ticketing channels, which are monitored and triaged promptly. Incidents are logged, investigated and managed in line with documented processes. Where appropriate, customers are provided with incident updates and post-incident reports outlining impact, root cause and corrective actions taken.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Monday 4 August 2025
- What the ISO/IEC 27001 doesn’t cover
- ISO/IEC 27001 covers all elements of confidentially, integrity and availability of data.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Saturday 5 July 2025
- What the ISO 9001 doesn’t cover
- ISO/IEC 9001 covers all elements of quality, confidentially, integrity and availability of data.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7d6f8ae6-2eb3-4cb0-9985-715a3d6b8297
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 8d342f79-c4a5-4b3f-9794-73d7c063621e
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-