Skip to main content

Help us improve the Digital Marketplace - send your feedback

STONESTHRO LTD

Proxora Kubernetes

A fully managed Kubernetes platform for UK public sector use, providing a secure and resilient control plane with optional high availability. Customers retain control of workloads and data, while the supplier manages platform operations, upgrades, and core monitoring. Designed for scalable, pay-as-you-go cloud delivery.

Features

  • CPU optimsised capability
  • Memory optimised capability

Benefits

  • Soverign capability
  • N+2 site availability

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andy.bates@stonesthro.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 1 2 5 3 6 3 6 1 2 2 2 0 5 5

Contact

STONESTHRO LTD Andy Bates
Telephone: 07880783166
Email: andy.bates@stonesthro.co.uk

About your service

Service categories

Systems Infrastructure Software

Physical and virtual computing

  • Virtual client computing

Operating system environments

  • Core Operating Systems
  • Client Operating Systems
  • Embedded/Industrial Operating Systems

Software defined compute

  • Virtual Machine Software
  • Container Infrastructure Software

Other computing and storage software

  • Container Data and Infrastructure Management Software
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
The sovereign micro-edge cloud service operates exclusively within approved national jurisdictions and relies on locally deployed infrastructure. Capacity is finite and scaling requires physical hardware expansion rather than on-demand elasticity. Service functionality is limited to a curated set of assured platform components, excluding hyperscaler-native managed services. Connectivity between sites and central management may be restricted or intermittent. Software updates and patches follow controlled change processes, resulting in slower release cycles. Integration with non-sovereign platforms or foreign-hosted services may be constrained. Physical space, power, cooling, and hardware lifecycle dependencies further limit performance, redundancy, and cost efficiency at small scale.
System requirements
  • We expect all clients to run AV
  • We expect clients to establish back up
  • Clients are ultimately responsible for cyber security

User support

Email or online ticketing support
Yes
Support response times
Best efforts within 4 hours however most of the service is self maintaining and has user support and restart capabilities
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes, at an extra cost
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Users can make general enquiries but our portal allows full functionality control
Web chat accessibility testing
Our portal provider has an extensive range of users globally and use this feedback to iterate their solution
Onsite support
Yes, at extra cost
Support levels
We provide personal service with a dedicated technical and acount resource, additional dedicated resource is costed in our SFIA rate card in the attached pricing document
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We will onboard users , provide access to portal and api as well as onboarding documentation
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
By contacting our help desk or self export
End-of-contract process
We facilitate users ability to export data directly and do not charge ingress or egress charges
Documentation accessibility standard
None or don’t know
How the documentation is accessible
We will make this available via web site and under NDA by email during onboarding

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
NA
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
No

Scaling

Independence of resources
We manage user demand and load share across physical hardware devices and nodes. We also balance load from daytime and nighttime loads and manage using network QOS controls.

Analytics

Service usage metrics
Yes
Metrics types
CPU/VM utilisation , network usage, storage , ram occupancy
Reporting types
  • API access
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Zadara

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can self export , we do not charge ingress or egress charges, they can ask for additional professional services which are chargeable.
Data export formats
Other
Other data export formats
  • Block and file units
  • Binary file
Data import formats
  • CSV
  • Other
Other data import formats
Binaries

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)

Availability and resilience

Guaranteed availability
We offer 99% availability per site with 99.5% across multiple sites subject to configuration and user application platform integration to cause automated failover
Approach to resilience
We offer multiple nodes geographically distributed each site with UPS to reduce power fluctuation issues. Going forward telco diversity is provided across sites avoiding common mode failure scenarios.
Outage reporting
We report by public dashboard which can configure email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
We can implement PSN and other private network access at the users request and cost
Access restrictions in management interfaces and support channels
We implement separate key pairs and separate management out of band access restricting to IP ranges and other bespoke controls agreed with the client.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Other
Description of management access authentication
We provide other in house protection techniques which can be disclosed on request

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ISO27001 and CE+
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
The provider operates a controlled change and configuration management process designed for distributed sovereign edge environments. All infrastructure and platform configurations are defined as code and maintained in approved, sovereign repositories (Baseline). Proposed changes are risk-assessed, authorised, and tested prior to deployment. Changes are deployed using pull-based automation and GitOps workflows, allowing sites to apply updates only when connectivity and operational conditions permit . Configuration drift is continuously monitored and corrected against approved baselines . Emergency changes follow defined break-glass procedures with retrospective approval and audit . All changes are logged, reviewed, and used to improve standard configurations and resilience
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
The provider operates a continuous vulnerability management process covering infrastructure, Kubernetes platforms, and workloads. Threat intelligence, vendor advisories, and NCSC guidance inform vulnerability identification (Identify). Automated and manual scanning is performed locally where connectivity is constrained, with findings risk-rated by severity, exploitability, and operational impact (Assess). Remediation actions follow controlled change processes, prioritising critical vulnerabilities and using approved patches, configuration hardening, or workload isolation (Treat). Where immediate remediation is not possible, compensating controls are applied and tracked (Mitigate). All vulnerabilities are logged, reviewed, and used to improve baselines, patch cadence, and security architecture
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
The sovereign edge cloud provider implements locally enforced protective monitoring at each edge site, aligned with UK protective monitoring and NCSC principles. Security events are collected from infrastructure, Kubernetes control planes, workloads, and networks, with logs and audit data retained on-site by default. Controlled, policy-driven replication to central sovereign monitoring platforms occurs where connectivity permits. Monitoring focuses on user activity, privileged access, configuration changes, workload behaviour, and network flows. Detection and alerting operate independently of our SOC tooling, enabling local incident response, forensic preservation, and evidence integrity under disconnected or degraded operating conditions.
Incident management type
Supplier-defined controls
Incident management approach
The sovereign micro-edge cloud provider follows an incident management approach aligned to NCSC principles of preparation, detection, response, recovery, and learning. Incidents are detected through local protective monitoring and clearly classified by impact and severity (Detect). Predefined roles, escalation paths, and site-level playbooks enable rapid triage and containment without reliance on external control planes (Respond). Evidence is preserved locally using tamper-evident controls to support forensic investigation and reporting (Respond). Services are restored using tested recovery procedures and configuration baselines (Recover). Post-incident reviews identify root causes, update controls, and improve playbooks across the estate (Learn).
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We will offer upto 10 Vm's for one month however we are happy to run longer proof of concept where it has mutual long term benefit.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7.5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
18%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Eda8b040-5636-4501-8dfd-375f408288e3
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • HIPAA via Zadara as primary cloud provider
  • ISO27017 of our primary supplier Zadara
  • SOC1 via Zadara primary cloud supplier
  • SOC2 via Zadara primary cloud supplier
  • ISO27018 via Zadara primary cloud supplier
  • IRAP via Zadara primary cloud supplier

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andy.bates@stonesthro.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.