Craft CMS website cloud hosting, support and maintenance
Studio 24 is an award-winning, accessibility-focussed agency that manages enterprise Craft CMS solutions for clients such as W3C and RNIB.
We offer managed hosting with comprehensive support and maintenance. We customise Craft CMS to deliver unique business and user requirements ensuring accessibility, security and data privacy compliance.
Features
- Fully managed cloud hosting for Craft CMS
- Comprehensive support, advice and training, including 24/7 support options
- Proactive maintenance, CMS updates, and monitoring
- CDN for performance and security, DDoS protection, and bot mitigation
- Sustainable web design and green hosting
- Craft CMS installation and configuration
- Headless and multisite website solutions
- Multilingual solutions, including support for Welsh-language websites
- Accessibility, security and data privacy compliance
- Solutions that follow GOV.UK Design Principles and Service Standards
Benefits
- 6 years of Craft expertise with small to large websites
- Craft Partner
- Experience of managing large web estates with multiple websites
- Strategic thinking to meet your business and user needs
- Experience of working in a complex stakeholder environment
- Supports your team to efficiently manage your website
- Fast, secure, and reliable website
- Experience with reliable and secure Craft CMS plugins
- Customised Craft CMS admin to help editors manage content
- Truly accessible solutions, WCAG 2.2 AA-level compliant
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 8 4 3 0 8 4 3 9 6 6 4 5 2
Contact
STUDIO 24 LIMITED
Emma Lane
Telephone: 01223 328017
Email: hello@studio24.net
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Enterprise Content Management Applications
Persuasive content management
- Website Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Craft CMS
- Cloud deployment model
- Public cloud
- Service constraints
- Support, maintenance and continuous improvement is for Craft CMS websites only
- System requirements
- Modern website browser
User support
- Email or online ticketing support
- Yes
- Support response times
- We have the following response SLAs for our support service: Critical 1 hour, High 2 hours, Medium 1 working day, Low 2 working days.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
We offer standard and out-of-hours support levels.
Our standard technical support & maintenance service covers CMS and plugin updates and security patches, uptime monitoring, hosting support with guaranteed response times.
We offer as standard in-office hours support, Monday to Friday 8am to 6pm, for an annual or monthly fee.
An out-of-hours 24/7 support service is also available and has a fixed additional monthly fee and a usage fee per incident.
All clients have an account manager who oversees your account, will meet with you regularly, and can address any concerns you may have. We supply monthly reports summarising account activity.
For any critical incidents we create a critical incident report which covers details of the issue, the root cause, and preventative action to minimise the risk of the issue recurring in the future. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
At the start of the service we will arrange an onboarding call to discuss how we work and agree ‘ways of working’.
This will cover roles and responsibilities, communication plan, frequency of status meetings, discussion of risks and mitigations, and importantly ensure we have an agreed understanding of the scope of work for the service.
We provide training on Craft for your team (in person or online), and supply supporting documentation where required. We also provide instructions on how to use and access our support system (Zendesk), so clients can report and access any issues that need addressing. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- We will supply a copy of the website codebase, data, and uploaded assets. All files are sent securely using encrypted email via Proton Mail (Swiss hosted secure email service). We can supply data and content multiple times.
- End-of-contract process
-
We have an open and supportive approach with our clients and support them when a contract ends with migrating to a new supplier. At the end of a service contract we will advise clients on the offboarding process and what work is required to migrate to a new supplier.
We: Backup and archive website files; Send copy of website files to client securely; Archive git repo; Archive services; Client offboarding survey.
Where possible, we can migrate the Git code repository to the new supplier. This contains the full audit history of changes to your website code.
We also ensure a handover meeting takes place so we can transfer as much knowledge as possible. Any documentation is also shared. We are happy to liaise with the new supplier to ensure this process is smooth. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The Craft CMS control panel works on mobile, though some features are easier to use on larger screens.
All Craft websites are designed to be mobile-friendly and work just as well on smaller mobile screens as on larger desktop screens. We design websites to be mobile-first, adjusting content/layouts/navigations where required. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- Via a web browser Craft admins can access the CMS to add, amend or delete content for their website.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Craft continually improves the accessibility of the CMS. For more details, including accessibility conformance reports, see https://craftcms.com/accessibility
We build robust, accessible websites using progressive enhancement, as recommended by the GOVUK Service Manual.
We have created our own HTML/CSS starter kit Amplify to help embed best practices in our work. It’s accessible, has been tested on the W3C redesign project, and is open source (sharing our learnings with the community). - API
- Yes
- What users can and can't do using the API
-
The primary service interface for Craft is the GraphQL API, which allows applications to interact with Craft websites. The Craft CMS API allows full access to managing content, users and media. API user permissions can be customised depending on requirements. More details are available at https://craftcms.com/docs/5.x/development/graphql.html
We have over 25 years experience integrating with external web services and building APIs to enhance existing, or introduce new functionality. We can integrate Craft plugins with external APIs or build custom web applications to integrate with APIs where the requirements are more complex. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- All of our work centres around business and user needs. Based on your requirements we can customise applications or websites in a number of ways including design, content management, workflows and editing processes, plugins, front and backend functionality, third party integrations, hosting, security and accessibility.
Scaling
- Independence of resources
- Our hosting service is isolated to individual clients so you do not share resources with other clients. You will be supplied with your own cloud server and associated services (e.g. database service, Elastic Cloud search service, etc). We do not offer shared hosting services.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide a number of metrics to our clients and can customise these according to client needs.
We recommend Matomo for privacy-aware analytics or Google Analytics 4.
At a minimum all clients are provided with web analytics via Matomo or Google. This includes website visitors, page views. We can set up custom events and reporting as required.
We also report on bandwidth usage (network traffic) and storage used. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
-
You can export Craft content in CSV, JSON or XML format from the Craft admin area.
We can supply a full export of the Craft database in SQL or CSV format.
Craft has a lot of flexibility on importing data into the CMS using the Feed Me plugin. For more information see https://docs.craftcms.com/feed-me/v6/ - Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- XML
- Database export (SQL, CSV)
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- ATOM
- RSS
- XML
- Database export (SQL, CSV)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We can offer 99.9% or 99.99% SLA for your website. 99.99% SLA requires redundant hosting in multiple data centres, to ensure we have a disaster recovery environment we can switch over to quickly.
We offer a guaranteed uptime SLA for your website, the maximum total credit for a monthly billing period shall not exceed 100% of the monthly service fee for the directly affected services.
If we fail to meet the guaranteed uptime SLA for your website we will pay a 5% credit of the monthly fee for that service and a further 5% for each additional 30 minutes the server is not available.
Scheduled maintenance is excluded from this SLA and covers any maintenance explicitly agreed with the customer. Downtime is recorded from the point at which a critical issue is raised or the monitoring system detects the website is down for more than 5 consecutive minutes. - Approach to resilience
-
Our hosting service is designed to be resilient and capable of handing high levels of traffic. All services are isolated and not shared with other clients. We use CDN services to efficiently serve static content, cache web pages and mitigate against DDoS attacks. We continuously monitor services so we can take action if there are any issues.
Our High Availability hosting service also includes redundancy and auto scaling. We set up high availability hosting in 2 geographically separate data centres. We set up auto scaling which can scale services in response to traffic and automatically scales down once traffic has reduced. - Outage reporting
-
Our support team will reach out to the client's emergency contacts to notify them of any site downtime by email and telephone. A support ticket will be created in our online support portal (Zendesk) to ensure the client is kept up to date.
We will also share an incident report with the client following resolution.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to our support system (Zendesk) is restricted by username and password. Studio 24 staff must also use two-factor authentication.
Access to hosting platforms by Studio 24 staff is restricted by username, password and two-factor authentication.
Access to cloud hosting services is locked down by secure VPN and SSH keys. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We take security seriously at Studio 24 and this is led at a board level by Managing Director Simon Jones. We maintain public documentation detailing our approach to security at https://github.com/studio24/security-principles/ which is based on National Cyber Security Centre (NCSC) cloud security principles. We regularly run staff training and review our standards in response to published guidance and current industry best practice.
- Information security policies and processes
-
We have a published data breach policy at https://github.com/studio24/security-principles/blob/main/data-breaches.md
If we have evidence of a data breach this must be reported to the Managing Director, or another Senior Director if he is on leave, who will assist in reviewing information and client liason. We will report any incidents to clients immediately and within the same working day.
Security and Data Protection training is undertaken on an annual basis with the entire team.
The board reviews information security on an annual basis. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We use open source tools Ansible and Terraform to manage and track changes to our hosting services. We store configuration as code, which is tracked in a git repository. We can share access to this with clients, if required.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- For Craft websites we use GitHub Dependabot to track security vulnerabilities in PHP packages. This can be configured to automatically patch security vulnerabilities in code via Pull Requests.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We regularly review website traffic via CDN monitoring and web access logs. Our CDN service includes DDoS protection and bot mitigation. Where issues are identified we raise a support ticket and investigate in more depth. We may work with other senior staff and liaise with our hosting and CDN suppliers to understand root cause and plan our mitigation.
If we find a potential compromise we treat this as a critical issue and respond within 1 hour. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We have a robust incident management process. Incidents are logged in our support system (Zendesk) and can be created by automated alerts from our monitoring system or by client-submitted support requests. Clients can send urgent support tickets via email. Clients with out-of-hours support can also call a dedicated support number which automatically creates a critical support ticket and pages support staff to respond.
After any critical support incident we create an incident report within 5 working days, which details the incident, the root cause, and any preventative action we will take to reduce the risk of reoccurance. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ddcbfcd8-ffc6-4ed7-a788-ac27e7deabe5
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 7236b381-e563-41ee-a078-109101c5c6e7
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-