Secure Cloud Storage and Back-Up Services
The total amount of data created by users and applications continues to grow and is forecast to increase over the coming years. Vodafone’s Storage and Backup services are designed to support end-to-end data storage strategy including business specific storage compliance requirements across multiple platforms.
Features
- Pay-as-you-go storage with no hidden costs
- Scalability on demand
- Reduce storage costs
- Secure connectivity options
- Internet connectivity
- Vodafone IP-VPN connectivity
- Direct Connection in select Vodafone data centres
- Quick to implement
Benefits
- Four different services to select based on your business needs
- Flexes up and down with your demand
- Zero capital outlay
- ISO/IEC 27001 certified platform
- Enables you to deploy new applications faster
- Cloud-based solutions save time and money
- Applications can be deployment quickly and data management automated
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 1 1 3 6 1 3 8 0 6 9 7 7 2 2
Contact
VODAFONE LIMITED
Frameworks Team
Telephone: 07775671027
Email: frameworks_team@vodafone.com
About your service
- Service categories
-
Systems Infrastructure Software
Storage
Data replication and protection
- Backup and Recovery Reporting Software
Archiving
- File and Other Archiving Software
Storage infrastructure and device management
- Storage Device Management Software
- Virtualization and Federation Software
- Other Storage Management and Infrastructure Software
Software defined storage controller
- Block-Based Software-Defined Storage Controller Software
- File-Based Software-Defined Storage Controller Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Managed Hosting
- Cloud deployment model
- Private cloud
- Service constraints
- None
- System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
- Please refer service definition for more detail
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
- Vodafone categorizes support into severity levels as follows: Severity 1 resolution within 4 business hours - defined as a total Loss of service affecting entire sites or the core Vodafone network or any elements of the platforms used by the customer, impacting a majority or all of the customer’s end-users. This excludes incidents outside of Vodafone control. Severity 2 resolution within 8 business hours - The loss of some but not all Vodafone services to a single or multiple sites. Severe degradation of a service to such an extent that it is not usable. For example, unable to use speech recognition, but able to make and receive calls. Severity 3 resolution within 48 hours - The degradation of, but not the loss of Vodafone services to a site or a number of sites. For example, poor voice quality while still able to make and receive calls.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- On-boarding guidance is provided as part of the service. When the Cloud Storage service is ready the customer will be provided with the following: I. Order live document – contains account information and guidance II. Quick start guide – this will be populated with the customers network information and covers the most common connectivity scenarios, providing configuration advice where needed (in some cases Vodafone will carry out this work for the customer) III. Connectivity handover (optional) – the Hosting Design team will engage the customer to test connectivity (the customer will have to consult the quick start guide first) IV. Portal user guide – a how to guide for customer administration (not provided for Managed Cloud Storage Applications customers).
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Advise Vodafone help desk that you want to stop using Cloud Storage and we’ll close your account, giving you 30 days before removing any remaining data. Vodafone may also be able to help you minimise the impact of off-boarding through our professional service capability.
- End-of-contract process
- Exit charges may apply.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- All onboarding and offboarding processes are coordinated by our Cloud Management Team who have a range of methods to share documentation depending on the requirements of the customer. This ranges from sharing via email, to sharing with direct access to a shared online portal.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed through the internet and can access a portal. Portal users can either be Account Managers or Account Users. Account Managers have access to create, edit, and remove user accounts. Account Users cannot see the Manage Users screen, however, Account Users can login to the portal and view reports and statistics for the sub-tenancy.
- Accessibility standards
- None or don’t know
- Description of accessibility
- None directly for this service as access is through end user devices
- Accessibility testing
- None directly for this service as access is through end user devices
- API
- Yes
- What users can and can't do using the API
- Vodafone Cloud Storage is available over the network via web service. All data must be accessed through web service calls. Vodafone will provide the API to access web service calls. If the application itself is developed to write to this Cloud Object Storage. Vodafone Cloud Storage uses EMC Atmos® technology, and therefore the API calls are compliant with the API standards developed and maintained by EMC Corporation. Any application which works with EMC Atmos® should work with Vodafone Cloud Storage and any software code created for Vodafone Cloud Storage should work with any EMC Atmos® node. Atmos provides RESTful and SOAP based web services APIs for data access and administration.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- Vodafone centrally monitors the platform performance and utilisation and manages any capacity expansions necessary to prevent service performance bottlenecks
Analytics
- Service usage metrics
- Yes
- Metrics types
- Disk use, and a range of other storage related metrics
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Xxx
- Data export formats
- ODF
- Data import formats
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- Service availability up to 100% can be made available with resilience. within the datacentre and dual site replication. Customers can choose from pre-defined service tiers to control how data is protected. The Gold service replicates your data automatically, providing availability from two Cloud Storage sites. While Gold and Silver tiers both provide self-healing.
- Approach to resilience
- There are multiple protection policies to choose from and the replication policy affects the resiliency of the data and the number of copies of the object. Each customer’s sub tenancy on the storage is setup with a default policy. That default policy will be used unless another policy parameter is passed to the API. Each policy is implemented with erasure coding and checksum in each location, and may include replication to another region if the policy names more than one data centre campus.
- Outage reporting
- Great emphasis is placed by Vodafone on monitoring and proactive identification of incidents; The Vodafone Service Desk will raise a proactive trouble ticket and initiate first line diagnostics. The Service Desk will contact the affected users/site to determine the business impact and identify any potential causes for the faults e.g. local site power issues. Vodafone will work with the customer to identify the most effective contact points for the various levels of escalation needed to resolve the issue.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Access restrictions in management interfaces and support channels
- Portal users - the first user ID and password created when the account is established is the Administrative ID for your storage sub-tenancy, will be used to manage the portal accounts. Additional user ID’s can be created and used to have other roles, privileges. Manage User screen can be found upon selecting Your Account in top right corner. Portal users can either be Account Managers or Account Users. Account Managers have access to create, edit, and remove user accounts. Account Users cannot see the Manage Users screen, however, can login to the portal and view reports, statistics for the sub-tenancy.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- All detailed in the UK and Group policy library and governed by the UK policy framework. Key polies are Information Security, Classification & materials handling, Vulnerability and Patch management, risk management, change management, incident management.
- Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Formal management responsibilities and procedures within Vodafone are in place to ensure satisfactory control of all changes. When changes are made, an audit log containing all relevant information is retained on the Vodafone change management system. Changes to operational systems are only made when there is a valid business reason to do so, such as an increase in the risk to the system.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability scanning is performed by industry standard a vulnerability management platform. Governance is in place to ensure that appropriate patching and/or remedial action is reviewed and implemented according to the severity and business impact of the vulnerability.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Vodafone has logging and monitoring capabilities in place along with appropriate storage of log data. The monitoring capability and events are managed and stored within the SIEM solution. The SIEM solution has been built in line with the Cyber Assessment Framework
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management processes are in line with ITIL best practice, and integrated with event, problem and change management processes.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Friday 16 August 2024
- What the ISO/IEC 27001 doesn’t cover
-
The Information Security Management System covers Vodafone UK mobile, Fixed and UCS Services and the Business Units that enable and support those Services. Locations are identified by the Services and Business Units that they support. All Annex A controls have been deemed applicable in accordance with the Design, Build and Run model & the Statement of Applicability Version 0.1.
The Data Centre locations are covered by the Vodafone Group ISO27001:2022 certificate.
issued by LRQA - 08/07/25.
Information Security Management System of Vodafone Group functions covering:The Provision, Maintenance and Operations for
Cyber Defence, Data Centres, Network, Infrastructure and Application services for Local Markets and Vodafone Business; Office IT
services, Shared Service Centres and relevant Business Processes.Vodafone Business services includes International Network
Connectivity, Unified Communications, Internet of Things, Cloud & Hosting and Customer Service Desks. This is in accordance with
Statement of Applicability version 19.
Therefore all elements of the proposed services are covered by these certifications. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Tuesday 15 September 2026
- What the ISO 9001 doesn’t cover
- Vodafone UK certificate does not cover Vodafone Group, this is covered by a Vodafone Group ISO9001 certification.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- NCC Group Security Services Ltd
- PCI DSS accreditation date
- Monday 7 July 2025
- What the PCI DSS doesn’t cover
- This does not cover UC, AWS or Azure. This are covered by separate certification.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E7b3eb7f-32e7-436f-9d63-b023df698463
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Af87bed1-45db-4396-b5a5-0703ffdc35ce
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-