Visionet Platform Based FinOps Services
Visionet’s FinOps service helps organisations control, optimise, and govern cloud spend through continuous cost visibility, budgeting, optimisation, and financial accountability. The service is enabled by Ops Studio, which unifies cost, usage, and automation insights to drive proactive cost control, predictable spend, and measurable savings across cloud environments.
Features
- Real-time cloud cost and usage visibility
- Automated cost allocation, tagging, and governance
- Budget creation, alerts, and threshold monitoring
- Rightsizing and waste identification recommendations
- Forecasting and spend trend analysis
- Showback and chargeback reporting
- Reserved instance and savings plan optimisation
- Policy-based cost control automation
- Multi-cloud cost management and reporting
- Platform-enabled FinOps through Ops Studio
Benefits
- Gain real-time visibility into cloud spending
- Control budgets and prevent cost overruns
- Reduce waste through continuous cost optimisation
- Improve forecasting accuracy and financial planning
- Align cloud spend with business priorities
- Enable accountability through showback and chargeback
- Automate cost controls and governance policies
- Accelerate decision-making with actionable cost insights
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 4 9 3 6 8 0 5 2 8 2 3 9 9 0
Contact
VISIONET EMEA LIMITED
Jawad A Khan
Telephone: +447721235694
Email: jawad.a.khan@visionet.com
About your service
- Service categories
-
Systems Infrastructure Software
Cloud Financial Management
- Cloud Financial Management (FinOps)
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service is an extension of enterprise IT operations software platforms, including IT Service Management (ITSM), infrastructure and cloud management, monitoring and observability tools, automation platforms, and security operations (SOC/SIEM) systems.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
The service has no inherent constraints that limit standard usage. Planned maintenance activities, where required, are scheduled in advance and conducted during agreed maintenance windows. The service relies on access to accurate cost, usage, and billing data from supported cloud platforms; limitations may apply where cloud provider data or APIs are restricted. Any environment-specific constraints are identified during onboarding and agreed with the customer.
Planned maintenance activities are scheduled in advance, performed during agreed maintenance windows, and communicated proactively to minimize business impact. - System requirements
-
- Valid cloud platform subscriptions and accounts
- Access to cloud cost and usage APIs
- Enabled resource tagging across cloud environments
- Permissions for read-only cost and usage access
- Secure connectivity to Ops Studio platform
User support
- Email or online ticketing support
- Yes
- Support response times
- All our services are as per agreed SLAs. We provide options like 8x5, 16x5, 24x7 etc.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Yes, we use Microsoft Teams for chat.
- Onsite support
- Yes, at extra cost
- Support levels
- At Visionet, our comprehensive support framework adheres to ITIL standards, delivering 1st, 2nd, and 3rd line support to both public and private sector clients. Our incident management process ensures swift resolution. Each client receives a dedicated Account Manager and Client Partner for personalized attention. We offer a unified support model manned by cloud support engineers, with optional weekend phone support available upon request. Our proactive approach prioritizes short-term issue resolution alongside long-term fixes. An established escalation process guarantees swift resolution, overseen by designated Account Managers who conduct monthly reviews, either remotely or on-site. Performance is monitored through KPIs aligned with SLAs and other critical support metrics. Security clearance is a fundamental aspect of our staff training and policy.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We help users start using the service through a structured onboarding and transition process. This includes service kick-off sessions, environment discovery, and knowledge transfer workshops. We provide role-based onboarding, user guides, standard operating procedures, and runbooks, supported by online documentation. Where required, we deliver remote or onsite training for administrators and support teams, along with walkthroughs of dashboards, workflows, and escalation processes to ensure smooth adoption and operational readiness.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At contract termination, users can extract their data through a structured offboarding process. Visionet supports secure data export from operational tools, dashboards, reports, and ticketing systems in standard, machine-readable formats. Data extraction scope, format, and timelines are agreed during exit planning. All customer data is returned or securely transferred to the customer or their nominated provider, followed by certified data deletion from Visionet-managed systems in line with contractual, security, and compliance requirements.
- End-of-contract process
- At the end of the contract, Visionet executes a structured offboarding and transition process. This includes service handover, knowledge transfer, documentation finalisation, and secure return or transfer of customer data. Standard exit activities—such as transition planning, final reporting, and data export in agreed formats—are included in the contract price. Any additional activities beyond the agreed exit scope, including extended transition support, bespoke data transformations, tooling extensions, or parallel run support, are treated as additional costs and charged on a mutually agreed basis.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The Ops Studio platform provides a responsive web interface and native mobile applications for iOS and Android. Mobile users can submit requests, view tasks, receive notifications, and perform approvals. Desktop access provides the full user interface and administrative capabilities, including configuration, reporting, and advanced workflow management.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service interface is delivered through the web-based platform, providing a single, role-based interface for end users, agents, and administrators. Users access services through configurable service portals with catalog-driven requests, self-service capabilities, and real-time status visibility. Service teams use standardised ITSM and Service Management workspaces for incident, request, change, and case management, supported by dashboards, reporting, and SLA/XLA tracking.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Visionet relies on platform-level accessibility testing, which includes testing with assistive technologies such as screen readers and keyboard-only navigation. During implementation, Visionet configures and validates service portals and workflows using accessibility best practices and guidance, and supports user acceptance testing where buyers choose to include users of assistive technology.
- API
- Yes
- What users can and can't do using the API
- The platform's REST and SOAP APIs can be used to integrate external systems, create and update records (such as incidents, requests, cases, users and assets), automate workflows, and retrieve real-time service data. Initial platform setup, configuration of core Enterprise Service Management processes, security roles, and complex integrations are typically not performed solely through APIs and require administrative access and guided configuration. API usage is subject to ServiceNow platform controls, role-based access, rate limits, and supported data models. Visionet helps users design secure integrations, configure API access, implement automation, and ensure API usage aligns with best practices and governance standards.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can customise the FinOps service by defining cost allocation models, budgets, optimisation rules, reporting views, and governance policies. Customisation is performed during onboarding workshops and through ongoing configuration within Ops Studio, supported by regular service reviews and change requests. Customer-designated finance, IT, and cloud stakeholders can request and approve customisations, which are implemented and governed by Visionet’s FinOps and operations teams in line with agreed controls and accountability models.
Scaling
- Independence of resources
- We ensure users are not impacted by demand from other customers through logical service isolation, capacity planning, and controlled resource allocation. Each customer operates within a dedicated service scope with segregated access, data, and workflows. Capacity is planned and monitored proactively using demand forecasting and threshold-based scaling. Where shared platforms or tools are used, role-based access, workload prioritisation, and SLA-based queue management ensure consistent performance and service levels for each customer.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The FinOps service provides metrics covering cost visibility, optimisation, and financial governance. These include total and allocated cloud spend, budget variance, forecast accuracy, savings identified and realised, rightsizing impact, and commitment utilisation. We also report on tagging compliance, waste reduction, optimisation coverage, and policy adherence. Metrics are delivered through dashboards and periodic reports to support transparency, accountability, and continuous cost optimisation.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users export their data through a controlled data exit process managed by Visionet. Data is extracted from operational systems, ticketing tools, dashboards, and reports using standard export mechanisms and APIs, and provided in commonly used, machine-readable formats (such as CSV, JSON, or PDF, as applicable). The scope, format, and delivery method are agreed during exit planning, and data is securely transferred to the customer or their nominated provider in line with security, privacy, and contractual requirements.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Visionet operates under defined Service Level Agreements (SLAs) covering service availability, incident response, and resolution across infrastructure, end-user, and security operations. Availability targets are agreed per service tower and documented in the contract or Statement of Work. SLAs are measured continuously and reported through regular service reports.
- Approach to resilience
- The FinOps service is designed for resilience through platform redundancy, secure data ingestion, and controlled operational processes. Cost and usage data is collected continuously from cloud providers with automated retries and validation to handle transient failures. Dashboards and reporting operate on resilient backend services with monitored availability. Governance workflows, backups, and audit logging ensure continuity and data integrity, while clear operational procedures and SLAs support consistent service delivery during demand spikes or provider-side disruptions.
- Outage reporting
- Outages are reported through multiple channels to ensure timely and transparent communication. Visionet provides email notifications for confirmed incidents, updates, and resolution milestones to designated customer contacts. Real-time status updates and incident details are available through operational dashboards used for service reporting and reviews. Where required, outage information can also be shared programmatically via APIs or integrated into customer ITSM tools, enabling customers to consume outage data within their own systems and workflows.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through layered identity, access, and governance controls. Role-based access control (RBAC) ensures users and support personnel only have permissions required for their role. Strong authentication mechanisms, including multi-factor authentication, are enforced for privileged access. Administrative access is limited to authorised personnel and logged for audit purposes. Support channels such as service desks and portals are secured through authenticated access, approval workflows, and segregation of customer environments to prevent unauthorised access or data exposure.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
- Compliant with SOC 1 and 2, ISO27001, PCI-DSS, GDPR
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Visionet follows structured configuration and change management processes aligned to ITIL practices. All service components—including infrastructure, applications, endpoints, and security controls—are recorded in a configuration repository and tracked throughout their lifecycle from onboarding to decommissioning. Configuration changes are versioned and auditable.
Changes are assessed through formal change management workflows that evaluate risk, business impact, and security implications. Security impact assessments are embedded into the change process, with mandatory approvals for high-risk changes. Automated checks, logging, and post-change validation are used to ensure changes do not introduce vulnerabilities or compliance gaps. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Visionet operates a structured vulnerability management process across infrastructure, applications, and security controls. Potential threats are assessed through continuous vulnerability scanning, configuration assessments, and risk-based analysis aligned to asset criticality and exposure. Patches are deployed based on severity and impact, with critical vulnerabilities remediated on an expedited basis and others addressed within agreed patch cycles and maintenance windows. Threat intelligence is sourced from cloud providers, software vendors, security advisories, CVE databases, and trusted threat intelligence feeds, and is continuously reviewed to prioritise remediation actions.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Visionet uses continuous protective monitoring to identify potential compromises across infrastructure, endpoints, networks, and cloud environments. Potential compromises are detected through real-time log monitoring, alert correlation, behavioral analysis, and threat intelligence–driven use cases. When a potential compromise is identified, incidents are triaged immediately, containment actions are initiated, and predefined response playbooks are executed, including isolation, remediation, and forensic analysis where required. Response times are governed by SLAs, with critical security incidents acknowledged and acted upon within minutes and managed through to resolution using structured incident response procedures.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Visionet follows a structured, ITIL-aligned incident management approach to restore services quickly and minimise business impact. We maintain predefined incident workflows and runbooks for common events, enabling consistent triage, prioritisation, and resolution. Users can report incidents through multiple channels, including the service desk portal, email, phone, chat, or integrated customer ITSM tools. Incident status and progress are communicated through regular updates, and detailed incident reports—including root cause, impact, actions taken, and preventive measures—are provided after resolution as part of service reporting or post-incident reviews.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 1%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 3%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- GMS INTERCERT SERVICES
- ISO/IEC 27001 accreditation date
- Wednesday 23 June 2021
- What the ISO/IEC 27001 doesn’t cover
- Not Applicable
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- GMS INTERCERT SERVICES
- ISO 9001 accreditation date
- Thursday 13 March 2025
- What the ISO 9001 doesn’t cover
- Not Applicable
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Friday 1 March 2024
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
- Not Applicable
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Sysnet Global Solutions
- PCI DSS accreditation date
- Tuesday 12 December 2023
- What the PCI DSS doesn’t cover
- Not Applicable
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E7f12ebf-757f-4ba2-b918-a2e69c4308b5
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Dea421ad-56e2-44f5-ae1d-8208ca0ca92b
- Other security certifications
- Yes
- Any other security certifications
-
- SOC1 TYPE 2
- SOC2 TYPE 2
- ISO 27001:2022, 27701
- HIPPA Compliant
- GDPR
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-