Proxora Kubernetes
A fully managed Kubernetes platform for UK public sector use, providing a secure and resilient control plane with optional high availability. Customers retain control of workloads and data, while the supplier manages platform operations, upgrades, and core monitoring. Designed for scalable, pay-as-you-go cloud delivery.
Features
- CPU optimsised capability
- Memory optimised capability
Benefits
- Soverign capability
- N+2 site availability
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 1 2 5 3 6 3 6 1 2 2 2 0 5 5
Contact
STONESTHRO LTD
Andy Bates
Telephone: 07880783166
Email: andy.bates@stonesthro.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Physical and virtual computing
- Virtual client computing
Operating system environments
- Core Operating Systems
- Client Operating Systems
- Embedded/Industrial Operating Systems
Software defined compute
- Virtual Machine Software
- Container Infrastructure Software
Other computing and storage software
- Container Data and Infrastructure Management Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- The sovereign micro-edge cloud service operates exclusively within approved national jurisdictions and relies on locally deployed infrastructure. Capacity is finite and scaling requires physical hardware expansion rather than on-demand elasticity. Service functionality is limited to a curated set of assured platform components, excluding hyperscaler-native managed services. Connectivity between sites and central management may be restricted or intermittent. Software updates and patches follow controlled change processes, resulting in slower release cycles. Integration with non-sovereign platforms or foreign-hosted services may be constrained. Physical space, power, cooling, and hardware lifecycle dependencies further limit performance, redundancy, and cost efficiency at small scale.
- System requirements
-
- We expect all clients to run AV
- We expect clients to establish back up
- Clients are ultimately responsible for cyber security
User support
- Email or online ticketing support
- Yes
- Support response times
- Best efforts within 4 hours however most of the service is self maintaining and has user support and restart capabilities
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Users can make general enquiries but our portal allows full functionality control
- Web chat accessibility testing
- Our portal provider has an extensive range of users globally and use this feedback to iterate their solution
- Onsite support
- Yes, at extra cost
- Support levels
- We provide personal service with a dedicated technical and acount resource, additional dedicated resource is costed in our SFIA rate card in the attached pricing document
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We will onboard users , provide access to portal and api as well as onboarding documentation
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- By contacting our help desk or self export
- End-of-contract process
- We facilitate users ability to export data directly and do not charge ingress or egress charges
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- We will make this available via web site and under NDA by email during onboarding
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- NA
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- We manage user demand and load share across physical hardware devices and nodes. We also balance load from daytime and nighttime loads and manage using network QOS controls.
Analytics
- Service usage metrics
- Yes
- Metrics types
- CPU/VM utilisation , network usage, storage , ram occupancy
- Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Zadara
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can self export , we do not charge ingress or egress charges, they can ask for additional professional services which are chargeable.
- Data export formats
- Other
- Other data export formats
-
- Block and file units
- Binary file
- Data import formats
-
- CSV
- Other
- Other data import formats
- Binaries
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- We offer 99% availability per site with 99.5% across multiple sites subject to configuration and user application platform integration to cause automated failover
- Approach to resilience
- We offer multiple nodes geographically distributed each site with UPS to reduce power fluctuation issues. Going forward telco diversity is provided across sites avoiding common mode failure scenarios.
- Outage reporting
- We report by public dashboard which can configure email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- We can implement PSN and other private network access at the users request and cost
- Access restrictions in management interfaces and support channels
- We implement separate key pairs and separate management out of band access restricting to IP ranges and other bespoke controls agreed with the client.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Other
- Description of management access authentication
- We provide other in house protection techniques which can be disclosed on request
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- ISO27001 and CE+
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- The provider operates a controlled change and configuration management process designed for distributed sovereign edge environments. All infrastructure and platform configurations are defined as code and maintained in approved, sovereign repositories (Baseline). Proposed changes are risk-assessed, authorised, and tested prior to deployment. Changes are deployed using pull-based automation and GitOps workflows, allowing sites to apply updates only when connectivity and operational conditions permit . Configuration drift is continuously monitored and corrected against approved baselines . Emergency changes follow defined break-glass procedures with retrospective approval and audit . All changes are logged, reviewed, and used to improve standard configurations and resilience
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- The provider operates a continuous vulnerability management process covering infrastructure, Kubernetes platforms, and workloads. Threat intelligence, vendor advisories, and NCSC guidance inform vulnerability identification (Identify). Automated and manual scanning is performed locally where connectivity is constrained, with findings risk-rated by severity, exploitability, and operational impact (Assess). Remediation actions follow controlled change processes, prioritising critical vulnerabilities and using approved patches, configuration hardening, or workload isolation (Treat). Where immediate remediation is not possible, compensating controls are applied and tracked (Mitigate). All vulnerabilities are logged, reviewed, and used to improve baselines, patch cadence, and security architecture
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The sovereign edge cloud provider implements locally enforced protective monitoring at each edge site, aligned with UK protective monitoring and NCSC principles. Security events are collected from infrastructure, Kubernetes control planes, workloads, and networks, with logs and audit data retained on-site by default. Controlled, policy-driven replication to central sovereign monitoring platforms occurs where connectivity permits. Monitoring focuses on user activity, privileged access, configuration changes, workload behaviour, and network flows. Detection and alerting operate independently of our SOC tooling, enabling local incident response, forensic preservation, and evidence integrity under disconnected or degraded operating conditions.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The sovereign micro-edge cloud provider follows an incident management approach aligned to NCSC principles of preparation, detection, response, recovery, and learning. Incidents are detected through local protective monitoring and clearly classified by impact and severity (Detect). Predefined roles, escalation paths, and site-level playbooks enable rapid triage and containment without reliance on external control planes (Respond). Evidence is preserved locally using tamper-evident controls to support forensic investigation and reporting (Respond). Services are restored using tested recovery procedures and configuration baselines (Recover). Post-incident reviews identify root causes, update controls, and improve playbooks across the estate (Learn).
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We will offer upto 10 Vm's for one month however we are happy to run longer proof of concept where it has mutual long term benefit.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 18%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Eda8b040-5636-4501-8dfd-375f408288e3
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- HIPAA via Zadara as primary cloud provider
- ISO27017 of our primary supplier Zadara
- SOC1 via Zadara primary cloud supplier
- SOC2 via Zadara primary cloud supplier
- ISO27018 via Zadara primary cloud supplier
- IRAP via Zadara primary cloud supplier
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-