Cloud Storage-as-a-Service
Akita provides cloud-based storage-as-a-service offering secure, scalable capacity for backup data, archives and retention vaults. We manage availability, performance and lifecycle policies so buyers can store, protect and access data reliably without managing physical infrastructure.
Features
- Secure cloud storage for business data
- Scalable capacity based on buyer requirements
- Managed performance and availability monitoring
- Configurable retention and lifecycle policies
- Secure cloud storage for business data
- Managed access controls and permission changes on request
- Service desk support for storage related requests
- Regular reporting on capacity usage and trends
Benefits
- Store and protect critical data without running physical storage hardware
- Scale storage up or down as needs change
- Reduce operational effort by using managed storage services
- Improve resilience and recovery options through protected storage
- Support compliance needs with defined retention policies
- Gain visibility of storage usage and capacity trends
- Free internal teams to focus on higher value work
- Use a single contact point for support and changes
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 0 8 8 1 1 9 8 6 1 9 2 6 4 0
Contact
AKITA SYSTEMS LIMITED
Akita
Telephone: 0330 058 8000
Email: info@akita.co.uk
About the service
- Service categories
-
Systems Infrastructure Software
Storage
Data replication and protection
- Data Protection Software
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- This service can extend backup and recovery services, monitoring services, data protection platforms, and archival or retention services by providing secure, scalable storage capacity and managed lifecycle controls as part of a wider cloud service stack.
- Cloud deployment model
- Public cloud
- Service constraints
- This service is delivered as a managed public cloud service and does not provide buyer access to underlying storage infrastructure. Storage capacity, retention, performance, and availability are agreed at call-off. The service does not include on-premise deployment or physical hardware support. Planned maintenance may be required and will be communicated in advance where applicable. Service availability and recovery objectives depend on the agreed service configuration and buyer requirements.
- System requirements
-
- Internet connectivity to access cloud storage services
- Compatible systems supporting secure storage protocols
- Secure credentials for authorised service access
- Modern web browser for reporting and management access
- Supported operating systems for integration where required
- Network firewall rules allowing secure outbound connections
- Time synchronisation enabled on connected systems
- Antivirus or endpoint protection on buyer-managed systems
User support
- Email or online ticketing support
- Yes
- Support response times
- .Support is available 24 hours a day, 7 days a week for contracted customers. Standard support is provided during UK business hours, Monday to Friday, 9am to 5pm. Requests raised outside standard hours are triaged and responded to in line with incident severity and contracted support arrangements.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Akita provides support for Storage-as-a-Service through a consultancy-led managed service model. Support is delivered by cloud and storage specialists via email or online ticketing during UK business hours.
A named service contact is provided for the duration of the engagement to coordinate support, changes, and service queries. A dedicated technical account manager or cloud support engineer is not assigned as standard, as the service is managed centrally. Specialist engineering support is provided as required within the agreed service scope.
Support costs are included within the agreed service pricing for standard operational support. Additional activities such as capacity changes, configuration adjustments, retention policy updates, or service enhancements may be charged using published SFIA-aligned rates, agreed in advance at call-off.
This approach provides predictable support access while maintaining clear scope control and cost transparency. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Akita supports buyers through a structured onboarding process to help them start using the service. This includes initial service setup, configuration aligned to buyer requirements, and secure access provisioning.
Buyers are provided with guidance documentation covering service usage, access, and support processes. Online knowledge sharing sessions may be provided where required to explain service features, reporting, and request procedures. Onsite training is not provided, as the service is delivered and managed remotely.
Ongoing support is available through the service desk to assist with questions, configuration changes, and service optimisation following onboarding. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, buyers can request extraction of their data from the service. Akita supports data export using standard, commonly used formats appropriate to the stored data and agreed at call-off. Data can be securely transferred to buyer-nominated locations using encrypted transfer methods.
Extraction requests are managed through the service desk and coordinated to ensure data integrity and security. Once data extraction has been completed and confirmed by the buyer, remaining data held within the service is securely deleted in line with agreed retention periods and data handling policies. Confirmation of data deletion can be provided on request.
This approach ensures buyers retain control of their data and can transition to alternative services without vendor lock-in. - End-of-contract process
-
At the end of the contract, Akita works with the buyer to support an orderly service exit. This includes confirming contract end dates, agreeing data extraction requirements, and planning secure data transfer or deletion. Standard contract pricing includes coordination of the contract close, support for data extraction requests, and secure deletion of remaining data in line with agreed policies.
Additional activities, such as extended data retention beyond contract end, bespoke export formats, accelerated exit timescales, or additional support to migrate data to third-party services, may be charged separately using published SFIA-aligned rates and agreed in advance.
This approach provides a controlled and transparent exit process while allowing flexibility based on buyer requirements. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is accessed through a web-based interface that adapts to desktop and mobile devices. On mobile devices, functionality focuses on monitoring, status viewing, and reporting. Configuration and administrative tasks are typically performed on desktop devices where larger screens support more detailed management activities.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, web-based management interface. Buyers can view storage usage, capacity trends, service status, and reports, and submit requests for changes or support. The interface provides role-based access and is designed to be clear and easy to navigate for operational and administrative users.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service interface is based on widely used web platforms designed to meet WCAG 2.2 AA accessibility standards. Accessibility is supported through platform-level features such as keyboard navigation, screen reader compatibility, and appropriate colour contrast. Usability and accessibility considerations are reviewed as part of ongoing service improvement and platform updates, with issues addressed through standard change and release processes.
- API
- Yes
- What users can and can't do using the API
-
The service provides APIs that allow authorised users to integrate storage services with other systems and automation workflows. Through the API, users can retrieve service status information, usage metrics, and capacity data, and submit requests related to configuration or lifecycle actions where supported.
Initial service setup and core configuration are managed by Akita to ensure security and service integrity. Users cannot use the API to access or modify underlying storage infrastructure or bypass agreed controls. Certain changes, such as capacity adjustments or retention policy updates, may require approval and are actioned through managed processes. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise the service through agreed configuration options defined at call-off. Customisable elements include storage capacity, retention and lifecycle policies, access controls, reporting, and alerting preferences.
Customisation requests are submitted through the service desk or agreed change processes. Changes are implemented by Akita to ensure security, stability, and compliance with the agreed service scope. Authorised buyer representatives and approved third parties can request customisations in line with their access permissions.
Customisation does not allow buyers to directly manage underlying storage infrastructure or bypass security controls. All changes are subject to approval and are recorded as part of standard service management and governance processes.
Scaling
- Independence of resources
- The service is delivered using logically separated storage environments with controls to manage capacity, performance, and access per buyer. Resource allocation and monitoring are used to prevent one buyer’s usage from adversely affecting others. Capacity thresholds and alerts support proactive management, and service performance is monitored to maintain stability across all tenants.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Describe the service metrics you provide
The service provides metrics including storage capacity usage, growth trends, utilisation levels, service availability, and basic performance indicators. Metrics support capacity planning, monitoring, and operational oversight and help buyers understand how storage resources are being used over time. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Buyers can export their data by submitting a request through the service desk. Data is extracted by Akita using secure, standard export methods and provided in commonly used formats appropriate to the data type. Exports are transferred securely to buyer-nominated locations using encrypted transfer mechanisms.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- ZIP archives containing original file formats
- TAR archives for bulk data exports
- Native file formats as originally stored by the buyer
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- ZIP archives containing original file formats
- TAR archives for bulk data exports
- Native file formats as originally stored by the buyer
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is delivered as a managed public cloud service and availability is designed to align with the resilience and availability characteristics of the underlying cloud platform. Akita does not offer a fixed percentage uptime guarantee as standard for this service.
Availability targets, service levels, and any associated remedies are agreed at call-off based on buyer requirements and service configuration. Where service availability does not meet agreed levels, remediation is handled through service management processes, including investigation, corrective actions, and service credits or refunds where contractually agreed.
This approach allows availability commitments to be tailored to buyer needs while maintaining transparency and flexibility within the service agreement. - Approach to resilience
-
The service is designed using resilient public cloud infrastructure with built-in redundancy and fault tolerance. Data is stored across multiple components within the cloud platform to reduce the impact of individual hardware or service failures. Monitoring and alerting are used to identify issues early and support proactive management.
Datacentre resilience, including power, cooling, and physical security, is provided by the underlying cloud provider using geographically resilient facilities. Detailed information about datacentre design and resilience controls is available on request where required.
Service resilience configurations, including replication and retention options, are agreed at call-off to align with buyer requirements and risk profiles. - Outage reporting
-
Service outages are monitored and managed by Akita using service monitoring and alerting tools. Where an outage affects service availability, buyers are informed through email notifications and service desk communications. Status updates and progress information are provided during incident resolution.
Service status information may also be made available through dashboards or reports where applicable. Outage information can be shared through reporting or on request, depending on the nature and scope of the incident
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls and authenticated user accounts. Only authorised users can access service management, reporting, or request changes. Permissions are assigned based on user roles and responsibilities. Support requests are accepted only from approved contacts and verified through authentication checks. Access is reviewed periodically and updated when roles change or access is no longer required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Akita follows a defined set of information security policies and processes aligned to ISO/IEC 27001. These cover areas including access control, data protection, incident management, risk management, supplier assurance, and business continuity.
Information security governance is overseen by senior management with board-level accountability. Day-to-day responsibility for policy implementation and compliance sits with designated security and operational leads. Policies are reviewed regularly to ensure they remain effective and aligned with regulatory and contractual requirements.
Compliance with information security policies is supported through staff training, role-based access controls, change management processes, and monitoring of systems and activities. Security incidents and risks are reported through defined escalation and reporting procedures, with corrective actions tracked and reviewed to ensure continuous improvement. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management are managed through defined internal processes. Service components are recorded and tracked throughout their lifecycle, including configuration, updates, and retirement. Changes are assessed for impact on security, availability, and service integrity before implementation. Security considerations form part of change approval, and changes are implemented in a controlled manner with appropriate testing and documentation.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Akita operates a defined vulnerability management process. Potential threats are identified through monitoring, supplier notifications, security advisories, and vulnerability scanning. Risks are assessed based on severity and potential impact to the service. Patches and mitigations are prioritised and deployed in a timely manner in line with risk and change management processes. Threat intelligence is informed by vendor security bulletins, industry alerts, and public vulnerability disclosures.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Akita uses monitoring and alerting to identify potential security incidents, service anomalies, and unauthorised activity. Alerts are reviewed by operational teams to assess potential compromise. Where an incident is identified, response actions are initiated in line with incident management processes, including investigation, containment, and remediation. Incidents are prioritised based on severity and potential impact, with timely response and escalation to appropriate stakeholders where required.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Incident management approach
Describe your incident management processes.
Include:
whether you have pre-defined processes for common events
how users report incidents
how you provide incident reports - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- British Assessment Bureau (UKAS accredited)
- ISO/IEC 27001 accreditation date
- Friday 18 January 2019
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001 certification does not cover customer-owned systems or infrastructure not managed by Akita Systems Limited, physical security controls at customer premises, end-user devices not under Akita management, or non-IT business activities outside the defined scope of IT support, cloud services, and hosted and recovery services.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- British Assessment Bureau (UKAS accredited)
- ISO 9001 accreditation date
- Thursday 23 April 2015
- What the ISO 9001 doesn’t cover
- The ISO 9001:2015 certification does not cover activities outside the defined scope of IT service delivery, including non-IT business operations, customer-owned systems or processes not managed by Akita Systems Limited, services delivered entirely by third parties outside Akita’s quality management system, and physical site operations at customer premises where Akita does not have operational control.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 56073cca-376a-486b-a991-0f76b99f23b2
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- Cc55b424-1c83-4f89-8550-44e6b24ec430
- Other security certifications
- No
Social value
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement