Cloud Software SaaS
Azure - Dell APEX - Broadcom VMWare - Microsoft Dynamics 365 & Office 365. Druva
Features
- VMware VIrtual Stack - Virtual Services
- Druva - Cloud Data Management Protection
- Microsoft Dynamics
- Microsoft Teams
- Microsoft Office 365
- Microsoft Azure
- BaaS DRaaS CRaaS STaaS PMC APEX Druva
Benefits
- Full VMware Services - Premier Partner
- Cloud Data Management Protection
- Microsoft Dynamics - Hosting & Services
- Microsoft Teams Integration & Deployment
- Microsoft Office 365 - Licence Management & Provision
- Microsoft Azure - Deployment & Management & Security
- Key Approved & Essential Backup - Data Services
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 3 6 8 8 0 3 3 5 9 2 0 5 0 0
Contact
SYNAPSE CONSULTANTS LIMITED
Sales Team
Telephone: 03306600001
Email: sales@synapse360.com
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
Conferencing and virtual event
- Web Conferencing Applications
- Virtual Event Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Our service is an extension to core cloud software platforms and management tools, enhancing existing vendor solutions such as operating systems, virtualisation platforms, security services, and monitoring tools. It integrates with widely used cloud software to provide additional configuration, management, optimisation, and support capabilities rather than replacing the underlying software.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Hosting IOM (Isle of Man) or UK
- System requirements
-
- Flexible and Scalable
- None Specific - subject to SOW
User support
- Email or online ticketing support
- Yes
- Support response times
- SLA's in place. P1 - P5. 24x7. But Standard support is Monday to Friday 9-5. Questions typically within 24 hours or less. Quicker if Business Critical. Please see SLA service guide for details.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
We have undertaken web chat testing with assistive technology users as part of our ongoing commitment to accessibility and inclusive design. Testing has included users who rely on screen readers (such as NVDA and JAWS), keyboard-only navigation, screen magnification, and voice input tools. These tests focused on common web chat journeys including initiating a chat, interacting with automated responses, escalating to a human agent, and ending a session.
Where Salesforce web chat and Salesforce AI Agent capabilities are used, we validate that AI-generated responses are compatible with assistive technologies, use clear and concise language, and avoid unnecessary complexity. We also test focus order, ARIA labelling, contrast, and error handling to ensure the chat interface remains usable throughout the interaction.
Feedback from testing is used to refine conversation flows, improve response clarity, and ensure the AI Agent supports, rather than hinders, accessible customer journeys. Testing is repeated following significant changes or upgrades. - Onsite support
- Yes, at extra cost
- Support levels
- Infrastructure availability aligned to industry-standard SLAs. 24/7 support availability. Incident prioritisation and response based on severity. P1 - P5 subject to Service guide Service credits may apply subject to contractual agreement. Support levels are defined in the Service Guide. Standard levels of support are included in the base price. Enhanced support pricing on request. UK-based service desk and technical engineering support. 24/7 monitoring and fault response. Access to cloud and infrastructure specialists via Synapse360.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- Getting started is simple and supported at every stage: Initial engagement: We work with you to understand requirements, workloads, security needs and outcomes. Design & planning: Our specialists design an appropriate Cloud architecture aligned to your performance, resilience and compliance needs. Onboarding & provisioning: Infrastructure is provisioned quickly using standardised, proven platforms. Migration support: We assist with migrating data and workloads from on premise or other cloud environments. Go live & optimisation: Services are validated, monitored and optimised, with ongoing support available 24/7. Onsite training is available subject to cost. remote and online training available. User documentation available also.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Exit Management and Offboarding summary Customers may exit the service in line with contractual notice periods. Secure return or deletion of data upon termination. Migration support available where required.
- End-of-contract process
- The service includes a clear, structured end-of-contract and exit management process designed to minimise disruption and avoid supplier lock-in. Notice and planning: Upon contract termination or notice, we work with the customer to agree an exit plan, timelines and responsibilities. Data return: Customer data can be securely exported in industry-standard formats to support migration to another provider or on premise environment. Migration support: Optional technical assistance is available to support data and workload migration during the exit period. Secure data deletion: Once data has been successfully transferred and confirmed, all remaining customer data is securely erased in line with recognised data destruction standards. Access removal: Customer access credentials and connectivity are revoked in a controlled manner to maintain security. Documentation and handover: Relevant configuration and service information can be provided to support continuity with a new supplier. This process ensures customers retain full ownership and control of their data throughout the contract lifecycle
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
- Other
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Desktop full details. Mobile basic level.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service interface uses LogicMonitor as a secure, web-based monitoring platform that provides real-time visibility of infrastructure and cloud services. Users access a single dashboard to view performance, availability, alerts, and trends across networks, servers, applications, and cloud resources. LogicMonitor integrates via agents and APIs, presenting data through intuitive graphs, alerts, and reports, enabling proactive monitoring, fault identification, and service performance management
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service interface has been reviewed against accessibility best practices and tested using common assistive technologies, including screen readers and keyboard-only navigation. User journeys were validated to ensure clear labelling, logical navigation order, and readable contrast levels. Feedback from users informed minor improvements to navigation clarity and alert presentation. Ongoing testing is carried out following platform updates to maintain compatibility with assistive technologies and accessibility standards
- API
- Yes
- What users can and can't do using the API
- Subject to request and SOW review
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise the service through configurable dashboards, alerting rules, thresholds, and reporting options to align with their operational and business requirements. Monitoring views can be tailored by service, application, location, or severity, enabling users to prioritise what is most important to them. Alert notifications can be customised by method, escalation path, and time window to support operational workflows.
Users can also define polling intervals, maintenance windows, and access controls, ensuring the service reflects their environment and governance model. Integrations with third-party tools and existing IT service management platforms can be enabled to support incident, change, and reporting processes. All customisation is managed collaboratively and documented within the Statement of Work to ensure clarity, control, and alignment with agreed service outcomes.
Scaling
- Independence of resources
- The service is designed to ensure customer workloads remain independent and protected from the impact of other users, while demand is actively managed to maintain performance and availability. Dedicated resource allocation: Customer environments are logically isolated with allocated compute, storage and network resources to prevent contention. Capacity planning: Infrastructure capacity is proactively monitored and planned to ensure sufficient headroom for growth and peak demand. Scalable architecture: Resources can be increased or decreased as required, supporting fluctuating demand without service degradation. Monitoring and controls: Continuous monitoring identifies utilisation trends and potential bottlenecks before they impact service. Fair usage and governance:
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides real-time and historical metrics covering availability, performance, capacity, and health of infrastructure and cloud services. Metrics include CPU, memory, storage, network utilisation, latency, packet loss, error rates, uptime, and alert response times. Trend analysis and threshold-based metrics support proactive capacity planning and incident management, enabling users to monitor service performance against agreed operational and service objectives
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export their data through secure, role-based access using the service interface or APIs. Data such as performance metrics, alerts, logs, and reports can be exported in standard formats including CSV and PDF, or integrated directly with third-party systems. Scheduled and on-demand exports are supported, ensuring users can retain, analyse, and report on their data outside the platform in line with operational and governance requirements
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Other to be Agreed
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Other to be Agreed and Defined
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- The service is designed to deliver high availability and reliability suitable for public sector workloads. Infrastructure availability: Core IaaS infrastructure is delivered from Tier 3 data centres with resilient power, cooling and network connectivity. Service uptime targets: The service operates to defined availability targets aligned to industry-standard SLAs, ensuring consistent access to hosted infrastructure. Redundancy by design: N+1 redundancy is built into critical components to minimise the risk of service disruption. Monitoring and incident response: Services are monitored 24/7, with incidents managed according to defined response and escalation procedures. Service credits: Where availability targets are not met, service credits may apply in line with contractual terms. Availability commitments and SLA details are clearly defined in the service agreement provided at contract award.
- Approach to resilience
- The service is designed with resilience at its core to ensure continuity of public sector services and minimise the impact of failures or incidents. Resilient data centre design: Infrastructure is hosted in Tier 3 data centres with N+1 redundancy across power, cooling and critical systems. Redundant connectivity: Multiple network paths and carriers are used to reduce the risk of connectivity failure. High availability architecture: Virtualised platforms and clustered infrastructure reduce single points of failure. Proactive monitoring: 24/7 monitoring enables early detection and response to potential issues before they impact service. Disaster recovery options: Optional replication, failover and recovery services provide additional resilience where required. Operational resilience: Documented incident, change and continuity processes support rapid recovery and service stability
- Outage reporting
- Dashboard, API, E-Mail alerts. Support staff
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls and least-privilege principles. Only authorised personnel are granted access based on job role and operational need. Strong authentication methods, including multi-factor authentication where appropriate, are enforced. Access rights are reviewed regularly and promptly revoked when no longer required. Administrative activities are logged and monitored to support security oversight and auditing
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- The service is delivered in accordance with recognised information security standards and best practices to protect customer data and systems. Information Security Policies and Processes The following information security policies and processes are followed as part of service delivery: Information Security Management: An established Information Security Management System (ISMS) aligned to ISO/IEC 27001, covering people, processes and technology. Access control: Role-based access controls, least-privilege principles and multi-factor authentication where appropriate to restrict access to systems and data. Physical security: Secure data centre facilities with controlled access, monitoring, CCTV and security procedures. Network security: Segmented networks, firewalls and intrusion protection to prevent unauthorised access. Vulnerability and patch management: Regular vulnerability assessments and timely patching of underlying infrastructure. Incident management: Documented security incident response procedures, including detection, escalation, investigation and resolution. Change management: Controlled change processes to minimise risk and maintain service stability. Supplier and third-party management: Security controls applied to suppliers and partners involved in service delivery. Data protection: Policies aligned to UK GDPR principles, ensuring confidentiality, integrity and availability of data. Audit and assurance: Regular reviews, audits and compliance checks to ensure ongoing effectiveness of security controls. Security responsibilities operate under a shared responsibility model, defining supplier and customer obligations.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management follow controlled, documented processes designed to maintain service stability and security. All Cloud infrastructure components are managed using standard configurations and version-controlled templates where applicable. Changes are assessed for risk and impact, approved through defined governance, and implemented in a planned manner. Emergency changes follow expedited but controlled procedures. Changes are communicated appropriately, monitored post-implementation, and reviewed to ensure successful outcomes and minimise disruption to customer services.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is delivered through a structured, risk-based approach. The underlying infrastructure is regularly assessed for vulnerabilities using industry-standard tools and threat intelligence. Identified vulnerabilities are prioritised based on severity and potential impact, with remediation actions scheduled accordingly. Security patches and updates are applied in line with defined maintenance processes. Vulnerability management activities are monitored and reviewed to ensure risks are reduced and the security posture is continuously improved.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Proactive monitoring is in place to ensure the availability, performance and security of the service. Infrastructure and core services are monitored 24/7 using automated monitoring tools to detect faults, performance degradation and capacity thresholds. Alerts are generated in real time and handled by experienced engineers following defined incident and escalation procedures. Monitoring trends are reviewed to identify potential issues early and support capacity planning and continuous service improvement
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management follows a structured, ITIL-aligned process to restore service as quickly as possible. Incidents are logged, categorised and prioritised based on impact and urgency. Automated alerts and monitoring enable rapid detection, with incidents escalated to appropriate technical teams. Progress is communicated to customers as required, and incidents are resolved using documented procedures. Post-incident reviews are conducted where appropriate to identify root causes and implement preventative improvements
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- A limited, time-bound free trial is available, providing access to a restricted IaaS environment to evaluate core functionality, performance and management capabilities before committing to a full service.
- Link to free trial
- https://www.synapse360.com/post/can-i-get-a-free-consultation-or-trial-of-your-services
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Tuesday 14 October 2025
- What the ISO/IEC 27001 doesn’t cover
- Any other service as not defined on our certificate.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Tuesday 14 October 2025
- What the ISO 9001 doesn’t cover
- Any other service as not defined on our certificate.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 57ea664b-9813-4177-88ae-2b043e727cb9
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
- ISO 2000-1
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
-