ULTRA Remote Browser Isolation (RBI)
Garrison ULTRA is a highly performant, full browser isolation cloud service. Garrison ULTRA leverages Garrison’s unique hardware enforced browser isolation technology, trusted by governments around the world, enabling users to safely visit ‘risky’ websites and providing a scalable service that protects from all web-based attacks, including phishing and malware threats.
Features
- Hardware enforced full remote browser isolation
- Near native browsing with hardware-driven video acceleration
- Agentless deployment, accessed via browser web app
- Configurable DLP and credential security controls
- Retain browser history and user profille
- Lightweight integration with proxies and secure web gateways
- Risk-centric reporting and insights
- SIEM and CDR integration via API
- Active directory over SAML user management
- Based on Garrison's NCSC-assessed hardware-security (hardsec) technology
Benefits
- Isolate all malicious webcode, prevent ransomware and malware threats
- Safely visit any website with zero risk of compromise
- Mitigate risk of phishing and other credential harvesting/data theft attacks
- Visit known malicious sites safely for threat research and investigation
- Hardware enforcement removes risk of escape from containers and VMs
- Superior performance and security versus software-based RBI
- Render even the riskiest previously-blocked sites safe for users
- Reduce resource requirements for evaluating access requests and browser alerts
- Real-time cues to indicate potential of masquerading sites
- Secure file downloads via existing CDR or email security pipelines
Pricing
£42.35 a unit
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
1 5 4 9 6 4 4 4 1 3 7 5 8 1 2
Contact
Garrison Technology Ltd
Jason Dowman
Telephone: +44 0207 9600213
Email: salesops@garrison.com
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Not applicable
- System requirements
-
- No additional software is required
- Service accessed via Internet browser
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- We aim to respond to support requests within 1 business day.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 AA or EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Our support hours are 09:00 to 17:00 (UK time), Monday to Friday (excluding UK bank holidays). As part of our service, customers will be assigned a Customer Success Manager.
Enhanced 24/7 support and Professional Services support may be purchased separately. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Each customer is assigned a Customer Success Manager who will support the onboarding and adoption phases.
This includes sharing appropriate deployment documentation, user guides, knowledge base articles and technical on-boarding calls. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- There is no user data to extract when a contract ends. SIEM integration will allow usage data to be extracted into a 3rd party SIEM solution.
- End-of-contract process
-
Before the contract ends, Garrison will share a renewal quote with the customer.
At the end of contract, if the customer does not want to renew, the ULTRA licenses will be revoked and users trying to access the service will not be able to connect.
There are no additional fees or costs involved if the customer doesn't wish to renew.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile use case uses a mobile app to access the service, available via the relevant app stores.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
There are two service interfaces - one for end users and one for administrators.
End users access the ULTRA service through the browser (where ULTRA opens in a separate window) and your administrators configure Garrison ULTRA through a customer Administration Portal accessed via the web. - Accessibility standards
- None or don’t know
- Description of accessibility
-
We provide a number of accessibility features for end users, including colour correction and inversion, high contrast and text magnification.
As the remote side of ULTRA accesses the internet in a normal way and ULTRA then presents a video image of the website in its original form, accessibility features that have been developed in the websites are still accessible and useable to the end user. - Accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
-
The Garrison ULTRA API allows a customer to 'stream' logs to their SIEM solution allowing visibility on their users browsing.
Set up is facilitated within the ULTRA Administration Portal. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Admins can flexibly customise the service at a group or per user level using a series of policies.
Policies cover Data Loss Prevention, Data Residency, Remote Filtering, Remote Logging and Transfers.
Scaling
- Independence of resources
- Garrison provisions adequate hardware capacity within its data centres to maintain the standards set out in our terms of service and SLA.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Includes (not complete list):
- Number of Active users
- Number of Peak active users
- Top websites visited
- Pages securely redirected to ULTRA
- Scripts isolated
- Files downloaded
- Browser insights - Reporting types
- Real-time dashboards
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Using AWS features and application level encryption to protect data at rest in AWS S3 buckets.
- Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- API is available allowing customers to stream end user browsing logs to the customer's SIEM/logging server.
- Data export formats
- Other
- Other data export formats
- Logs are sent in ArcSight Common Event Format
- Data import formats
- Other
- Other data import formats
-
- Data derived from SAML SSO configurations is automatically uploaded
- Manually input e.g., define groups for users
- XML file Customer's Identity Provider Metadata (to configure SAML SSO)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Guaranteed availability of 99.9%. Customer may be eligible for Service Credits as set out in our SLA available on request.
- Approach to resilience
- The service is built with redundancy and resilience in mind by ensuring that all network devices have failovers in place in case any were to go down. Further information available on request.
- Outage reporting
-
Every month we internally report availability. We use network monitoring and logging/SIEM solutions to report outages.
We also run regular, automatic tests to ensure service availability and to raise and report any service outages in line with our SLA.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Administrators are authenticated using SAML 2.0 and 2FA on a customers individual administrative portal
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- 2-factor authentication
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- 29/06/2022
- What the ISO/IEC 27001 doesn’t cover
- Everything in our organisation is included in the scope apart from information security in project management and protection of test data, as Garrison's test data is only public information.
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- Yes
- Any other security certifications
- SOC2 Type II
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- SOC 2 Type II
- Information security policies and processes
- Information Security processes follow ISO 27001 and SOC 2 guidelines, where reporting structure and management aspects are covered.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Change management and configuration processes comply with SOC 2 certification. Further information available on request.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Garrison carry out regular vulnerability scans which are reviewed with the CSO/COO. We have a defined process that dictates how they are addressed. More information is available on request.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Regular scans and monitoring of User access in the management plane, response immediately. Further information can be made available on request.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Information management processes are detailed in our SOC2 certification. More information available on request.
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
We're committed to making sustainability a core part of our culture, ensuring that our success does not come at the cost of our planet. Garrison's Sustainability Committee leads our environmental efforts, aiming for measurable impact reduction across our business.Covid-19 recovery
Garrison adheres to all applicable health and safety regulations, including adhering to official COVID-19 guidance.Tackling economic inequality
We are proud to be a London Living Wage employer, ensuring that all our staff are compensated at rates exceeding the minimum wage. Our policy reserves work experience placements for candidates from disadvantaged or underrepresented backgrounds.Equal opportunity
Garrison is committed to equal opportunities in employment, ensuring all staff and job applicants receive fair treatment in accordance with the Equality Act. Our EDI committee works toward equality, diversity, and inclusion through initiatives such as Unconscious Bias training, CV anonymisation, and cultural celebrations.Wellbeing
At Garrison, we prioritise employee wellbeing and mental health. We offer various resources, including an EAP, trained mental health first aiders, 24/7 virtual GP access, and gym perks, ensuring support both in and out of the workplace.
Pricing
- Price
- £42.35 a unit
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- The free trial provides the full suite of Garrison ULTRA features but is limited in duration and in the number of users that can access the service.
- Link to free trial
- https://www.garrison.com/garrison-ultra-cloud-platform