Backup and Disaster Recovery as a Service
Akita provides managed backup and disaster recovery as a service, offering secure data protection, automated backups, monitored recovery processes and managed retention policies. The service helps buyers protect critical systems, meet compliance requirements and restore operations quickly following data loss, corruption or system failure.
Features
- Automated scheduled backups for servers, applications and cloud workloads
- Encrypted data protection in transit and at rest
- Retention policy management aligned to buyer requirements
- Continuous monitoring of backup health and job success
- Disaster recovery planning and managed failover processes
- Support for rapid restoration of files, systems or full environments
- Immutable storage options to protect against ransomware
- Alerts and reporting for backup status, capacity and recovery readiness
- Optional offsite replication to secondary locations
Benefits
- Reduces data loss risk through consistent and automated protection
- Improves organisational resilience with managed recovery processes
- Accelerates recovery time following incidents or system failure
- Helps buyers meet compliance and audit requirements
- Removes overhead of maintaining backup infrastructure
- Supports secure long term retention of critical data
- Enhances protection against cyber threats such as ransomware
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 8 1 3 6 4 2 4 2 5 5 1 9 6 4
Contact
AKITA SYSTEMS LIMITED
Akita
Telephone: 0330 058 8000
Email: info@akita.co.uk
About the service
- Service categories
-
Systems Infrastructure Software
Storage
Data replication and protection
- Data Protection Software
- Backup and Recovery Reporting Software
- Storage Replication Software
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Backup and disaster recovery integrates with common server and cloud platforms, including Microsoft 365, Azure workloads and on premise virtualised environments. It enhances these services by providing managed protection, replication and recovery without replacing existing systems.
- Cloud deployment model
- Hybrid cloud
- Service constraints
- Backup and recovery performance depends on the buyer’s bandwidth and infrastructure. Large scale restorations may require scheduled maintenance windows. Some advanced recovery features require supported operating systems or virtualisation platforms. Offsite replication and immutable storage may require additional licensing. Onsite recovery tasks may need buyer participation or shutdown planning.
- System requirements
-
- Supported operating systems or virtualisation platform required
- Stable internet connection for backup transfers
- Sufficient storage capacity for local backups
- Administrative access for agent installation
- Valid software licensing where applicable
- Buyer-approved maintenance windows for restorations
- Antivirus exclusions for backup agents
- Supported hardware for bare metal recovery
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is available 24 hours a day, 7 days a week, including weekends and bank holidays, for contracted customers. Standard support hours are Monday to Friday, 8am to 6pm. During standard hours, high priority tickets receive a response within one hour and standard tickets within four working hours. Out-of-hours response times vary based on incident severity and contracted support arrangements.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
E provide first, second and third line support through Akita’s service desk. First line handles incident logging and initial troubleshooting. Second line manages backup job failures, configuration issues and routine recovery tasks. Third line supports complex disaster recovery scenarios and advanced restoration.
Support is priced using our standard rate card, with monthly service packages or pay as you go options depending on the level of cover required. Costs vary by environment size and escalation level.
A named service delivery contact is provided. A technical account manager or cloud support engineer is available on request for buyers who need regular reviews or deeper technical oversight. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide an onboarding session to confirm the environments to be protected, the required backup schedules and retention policies. We install and configure the backup agents, set up reporting and confirm the recovery process with the buyer. Users receive documentation and guidance on how to request restorations and monitor backup status. Online training or walkthroughs can be provided on request.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Users can request a full export of their backup data before the contract ends. Data can be provided through secure download, exported to buyer provided storage or restored to buyer owned systems as required. We remove our access once extraction is complete. No customer data is retained after contract closure.
- End-of-contract process
-
At the end of the contract we schedule an offboarding session to confirm data extraction requirements and the date support will cease. We assist with exporting backup data and removing our access. We also provide confirmation that all stored data has been deleted once extraction is complete.
The contract price includes administrative offboarding, access removal and standard data deletion. Additional costs may apply for large scale data exports, extended retention periods, onsite recovery support or project based assistance requested by the buyer. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Users access a web based management portal to view backup status, monitor job success, check replication activity, review alerts and request restorations. The interface provides reporting dashboards and configuration options based on assigned permissions.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service interface follows standard accessibility practices such as keyboard navigation, structured layouts and clear visual labelling. We have reviewed the portal using screen reader tools and high contrast settings to confirm usability. Further accessibility adjustments can be supported on request where buyers have specific user needs.
- API
- Yes
- What users can and can't do using the API
- The API allows users to automate backup jobs, retrieve backup status information, view logs, generate reports and initiate restoration tasks. Users can set up API access through the portal by creating secure authentication keys. Configuration changes such as adding backup jobs or modifying retention policies can be made through the API where supported by the underlying platform. Some actions, such as advanced recovery workflows or changes affecting protected system configurations, must be performed through the management portal or by Akita’s support team.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Users can customise backup schedules, retention policies, alert settings, protected workloads and recovery preferences. Customisation is done through the management portal or by raising a request with the service desk. Administrators with the correct permissions can create or modify policies, apply configuration changes and adjust backup targets. Standard users can request changes but cannot alter core settings.
Scaling
- Independence of resources
- We allocate backup resources and storage capacity independently for each buyer to prevent performance impact from other environments. Backup jobs run within isolated resource pools, and data is stored in segregated locations with guaranteed bandwidth for transfers. Monitoring ensures that high demand from one buyer does not affect another, and scaling is applied per customer where required.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide metrics on backup job success, failures, storage consumption, retention status, replication activity and recovery performance. Users can view historical trends, daily job summaries and alerts for missed or failed backups. Capacity forecasts and compliance reports are also available.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data by requesting a full backup export through the service desk. Data can be provided as a secure download, transferred to buyer supplied storage or restored to buyer owned systems. Export options depend on the size of the data and the buyer’s preferred method.
- Data export formats
- Other
- Other data export formats
-
- Virtual machine image files
- Encrypted archive backup files
- Data import formats
- Other
- Other data import formats
-
- Virtual machine image files
- Encrypted backup archive files
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We provide availability in line with the underlying cloud platform used for backup storage and recovery. Backup monitoring, job processing and restore requests are operated during contracted support hours. The service aims to maintain high availability for backup operations, and any planned maintenance is scheduled outside peak hours where possible.
If availability falls below the agreed service levels, we review the cause, provide a service credit or adjustment where applicable and agree corrective actions with the buyer. Specific refund arrangements are defined in the support contract and reflect the level of cover purchased. - Approach to resilience
- The service is designed with resilience provided through the underlying cloud platform, which uses redundant storage, distributed infrastructure and automated failover to protect data. Backups are replicated to secure UK based locations, and monitoring ensures failed jobs are reattempted. Recovery processes are validated to support restoration even if a primary location becomes unavailable. More detailed architectural information is available on request.
- Outage reporting
- Service outages are communicated through email alerts to nominated buyer contacts and through updates on the service desk portal. Buyers can request outage information through the API where available. Major incidents are also communicated by the service delivery team with ongoing status updates until resolution.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted through authenticated user accounts with role based permissions. Administrative functions are limited to authorised users, and all actions require secure login with multi factor authentication where enabled. Support channels verify the identity of the requester before making changes or sharing information. Access rights are reviewed, audited and updated when staff roles or buyer requirements change.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We follow information security policies aligned to ISO 27001, covering access control, data handling, incident management, business continuity and supplier management. Policies are owned by senior management and reviewed through our security steering process. Staff receive mandatory security training and must follow defined procedures for handling customer data. Compliance is monitored through internal audits, technical controls, change management and incident reporting. Security issues are escalated to the management team and reviewed for corrective actions.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We track service components through asset registers, version control and documented configuration records. Backup infrastructure, policies and dependencies are recorded and reviewed during onboarding and when changes occur. All changes follow a defined change management process that assesses technical impact, service risk and potential security implications before approval. Security reviews consider access requirements, data flows and any effect on encryption or isolation controls. Approved changes are implemented in controlled windows and monitored for unexpected outcomes. Records are updated after completion to maintain an accurate configuration baseline.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Vulnerability management approach
Describe your vulnerability management process?
Include details of how:
how you assess potential threats to your services
how quickly you deploy patches to your services
where you get your information about potential threats from - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We monitor the service for unusual activity, failed backup patterns, access anomalies and alerts generated by the underlying platform. Potential compromises are identified through automated monitoring tools and review of security events. When an issue is detected, we investigate the cause, restrict access if required and follow our incident response process. Incidents are assessed, prioritised and acted on during support hours, with high priority incidents receiving an immediate response. All incidents are recorded, reviewed and closed with corrective actions where needed.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We use predefined incident procedures for common events such as failed backups, access issues and recovery errors. Users report incidents through the service desk by email, ticket or phone. Each incident is logged, prioritised and managed through our workflow. We provide incident updates through the portal or email, and a full incident report is supplied on request for high priority or security related issues.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- British Assessment Bureau (UKAS accredited)
- ISO/IEC 27001 accreditation date
- Friday 18 January 2019
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001 certification does not cover customer-owned systems or infrastructure not managed by Akita Systems Limited, physical security controls at customer premises, end-user devices not under Akita management, or non-IT business activities outside the defined scope of IT support, cloud services, and hosted and recovery services.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- British Assessment Bureau (UKAS accredited)
- ISO 9001 accreditation date
- Thursday 23 April 2015
- What the ISO 9001 doesn’t cover
- The ISO 9001:2015 certification does not cover activities outside the defined scope of IT service delivery, including non-IT business operations, customer-owned systems or processes not managed by Akita Systems Limited, services delivered entirely by third parties outside Akita’s quality management system, and physical site operations at customer premises where Akita does not have operational control.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 56073cca-376a-486b-a991-0f76b99f23b2
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- Cc55b424-1c83-4f89-8550-44e6b24ec430
- Other security certifications
- No
Social value
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement