Skip to main content

Help us improve the Digital Marketplace - send your feedback

AXIS12 LTD

Hosting, Continuous Integration and Deployment Application Platform (PaaS)

A Platform-as-a-Service (PaaS) tool built for hosting and continuous deployment. Its infrastructure allows you to host web applications on the cloud while making your development and testing workflows more productive. Developers can easily merge their own code into production and deploy across multiple cloud providers without help from DevOps.

Features

  • Create and launch projects independently or with teams
  • Built in Continuous Integration and Continuous Deployment (CI/CD)
  • Instant cloning
  • Adaptable workflows
  • Automated updates and 24/7 support
  • ISO27001 certified hosting in highly secure UK based locations
  • Redundant Enterprise architecture with 99.99% uptime guranteed
  • Specially tuned for PHP, Drupal, Symfony
  • GUI, API and CLI-based service management tools
  • Significantly reduce reliance on DevOps team

Benefits

  • Automated Continuous Integration (CI) and Continuous Deployment (CD)
  • Significantly reduce reliance on DevOps team
  • Increase developer productivity
  • Faster User Acceptance Testing
  • Increase frequency of deployments
  • Deploy from anywhere and at anytime

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@axistwelve.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 0 6 9 5 8 4 2 3 6 4 4 0 2 7

Contact

AXIS12 LTD Luke Harrop
Telephone: +44 (0) 203 397 8514
Email: tenders@axistwelve.com

About your service

Service categories

PaaS

Application Platforms

  • Deployment-centric application platforms

Service scope

Service constraints
No known constraints. All OS and hardware configurations supported
System requirements
  • Container, Virtual machines and serverless compute available
  • Linux or Windows based operating system
Cloud deployment model
  • Public cloud
  • Private cloud

User support

Email or online ticketing support
Yes
Support response times
Acknowledgement of questions raised in a support ticket is conducted within 5 minutes. Tickets are triaged and actioned in accordance with our strict SLAs, which range from 60mins through to 5 business days depending on the urgency and severity of the issue.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We have tested with various assistive technology users.
Onsite support
Yes, at extra cost
Support levels
Axis12 provide a range of different support ranging from 24/7 x 365 through to Core hours: Office hours (08:30 – 17:30 Monday to Friday on standard UK business days). Costs vary depending on level of service required and staff type. Every client will have a named account manager experienced in diagnosing and directing requests to the correct resource.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
This first step we take during on-boarding is to create a support project in our back-office support system (Jira). You will need to supply us with a primary contact (through which all change requests will be routed)
plus one or more email addresses for alerts and tickets. Training in how to use Jira for logging tickets will be provided as part of the on-boarding process.
We will confirm your architecture requirements and your servers will then be commissioned and configured.
Provisioning generally takes anywhere from 2-3 hours up to 2-3 days depending on the complexity of your requirements.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
This can be provided by logging a support request with the team.
End-of-contract process
Off-boarding involves removing all accounts associated with back-office systems involved in your deployment and securely deleting all data held in line with our ISO 27001 processes. We can provide an archive of all support tickets if requested. Data held on the servers can be packaged and delivered on request although this may incur a small fee. We will also securely delete all tickets in the Jira project we created for you.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Using the web interface
For non-production environments "Podium" is Axis12’s proprietary container based hosting platform, with a web interface that allows seamless delivery of code deployment through to realtime infrastructure build.

Built on leading Enterprise class open source technology, it is a ‘no Ops’ solution to building scalable and performant infrastructure on demand and can save development teams countless hours and delays through no longer having to rely on DevOps to build and deploy code to virtual servers.

For production servers "Axis12 Deploy" is the web interface available to client wish to have control over live deployments.
Web interface accessibility standard
WCAG 2.2 AA
Web interface accessibility testing
None, but planned for 2026
API
Yes
What users can and can't do using the API
There is, but it is only made available on request and subject to certain conditions.
API automation tools
  • Ansible
  • Chef
  • Puppet
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
Command line interface
Yes
Command line interface compatibility
  • Linux or Unix
  • Windows
Using the command line interface
For non-production servers we provide a command interface that can be accessed through a web interface and so is accessible via any OS and any browser.

For production servers, unless explicitly requested the command line interface is for Axis12 DevOps staff only. However we are able to provide access via VPN if required and subject to certain conditions.

Scaling

Independence of resources
We run quality of service metrics on our systems and automatically move / scale resources if demand effects availability
Usage notifications
Yes
Usage reporting
Email
Optimising consumption
Yes
Automatic scaling
Yes

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • CPU
  • Disk
  • HTTP request and response status
  • Memory
  • Network
  • Number of active instances
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Backup and recovery

What’s backed up
  • Files
  • Database
  • Configuration
  • Codebase
Backup controls
Users can backup at different times and frequency depending on client need
Datacentre setup
Multiple datacentres with disaster recovery
Scheduling backups
Users contact the support team to schedule backups
Backup recovery
Users contact the support team
Backup and recovery
Yes
RPO/RTO
Yes

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
99.95% uptime as standard. Higher uptime guarantees on request.
Support for Level 1 issues and planned Support Requests (Levels 2-5) where agreed in advance. An out-of-hours telephone number is provided for The Customer to escalate any Level 1 issues. The Supplier will respond to and action any Level 1 issues in accordance with the response targets.
Hosting and infrastructure issues will be actioned within the resolution targets.
Level 1 issues caused by an application or content change made within non-Core hours will be actioned on a best efforts basis. Outages caused by these issues will be exempt from the uptime measurements and Service Level Credit calculations, and the support services may be chargeable.
Approach to resilience
Resilience is provided across our Priority 1 systems through load-balanced firewalls and switches, multiple reverse proxy servers with automatic failover capability, multiple high-availability webservers and a scale-out NAS file system.
Outage reporting
Our monitoring systems produce email alerts in near real-time.
A ticket is automatically created in our web based ticketing system called Jira. Client is also telephoned immediately. Investigation commences, and any updates to the Jira ticket (at least one every 15 minutes in the case of an outage) triggering update emails to client.

Month end reporting will show full duration and detail of any outages based on monitoring and Jira statistics.

By tracking all support activity through Jira and giving our client full access we provide you with total transparency over the way an issue is being handled and report on our activities against the service level agreement each month.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access controls, least privilege, and strong authentication. Administrative access is limited to authorised personnel, protected by multi-factor authentication and accessed via hardened bastion hosts. Management interfaces are segregated from customer networks and exposed only through secure, restricted endpoints. Support channels are accessible only to trained staff with defined responsibilities. All access is logged, monitored, and regularly reviewed, with permissions promptly removed when no longer required, ensuring access controls meet OFFICIAL and OFFICIAL-SENSITIVE expectations.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Devices users manage the service through
  • Dedicated device on a segregated network (providers own provision)
  • Dedicated device on a government network (for example PSN)
  • Dedicated device over multiple services or networks
  • Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
ISO 27017
ISO 27018
Cyber essentials plus
Information security policies and processes
We operate a comprehensive set of information security policies and processes aligned to ISO/IEC 27001 principles and UK public-sector expectations. These include policies for information security, access control, asset management, data protection, incident management, secure development, supplier assurance, and business continuity. Policies are reviewed at least annually and whenever there is a material change to risk, technology, or regulation.

Overall accountability for information security sits with senior management, with day-to-day responsibility delegated to a nominated Information Security Lead. Security risks, incidents, and compliance status are reported regularly to the senior leadership team, ensuring oversight and timely decision-making.

Policies are embedded through defined operational processes, mandatory staff induction and annual refresher training, role-based access controls, and documented procedures for handling data and incidents. Compliance is reinforced through internal audits, management reviews, vulnerability management, and regular testing of controls. Any non-conformances are recorded, tracked, and remediated.

This structured approach ensures information security is consistently applied across the organisation, understood by staff, actively governed, and continuously improved.

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We operate a defined change control process supported by the Axis12 Change Control system. All service components are recorded and tracked throughout their lifecycle, from initial deployment through change, release, and decommissioning. Each change request is formally documented and assessed by an authorised Change Approver, considering risks, benefits, and potential security impact, including confidentiality, integrity, and availability. Approved changes follow a structured design, testing, and implementation process, with stakeholder review. A final post-implementation assessment confirms success or failure, and changes are closed or reopened as appropriate.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Axis12 are constantly monitoring the various major alert/information channels for threats to our system. Each threat is classified Critical, High, Low with expected implementation times as follow.
- 'Critical’ patches should be deployed within hours.
- 'High’ patches should be deployed within 2 weeks of a patch becoming available.
- ‘Low’ patches deployed within 8 weeks of a patch becoming available.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Axis12 have a range of automated and manual approaches to protective monitoring that are constantly being reviewed as new threats are identified within the industry. We work closely with our hosting partners and other industry experts. The exact process is available on request.
Incident responses are reviewed and classified in our ‘Security Incident (System)’ and assigned to the appropriate Service Level to the incident with the appropriate level of technical resources to resolve the issue.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We operate a formal incident management process aligned to ISO/IEC 27001 and UK public-sector expectations. Pre-defined procedures exist for common incidents, including security events, service disruption, and data breaches, with clear severity levels, response times, and escalation routes. Users report incidents via a dedicated service desk and monitored support channels. All incidents are logged, triaged, investigated, and resolved by authorised personnel. For significant incidents, we provide written incident reports covering impact, root cause, containment actions, recovery, and lessons learned, supporting transparency, assurance, and continuous improvement.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Supplier
Virtualisation technologies used
Other
Other virtualisation technology used
Kubernetes
How shared infrastructure is kept separate
Different organisations are kept apart through layered isolation controls. Each organisation is assigned its own namespace, separating workloads, services, and configurations. Role-Based Access Control (RBAC) ensures users and service accounts can only access their permitted resources. Network Policies restrict pod-to-pod communication, preventing unauthorised traffic between organisations. Resource quotas and limits guarantee fair usage and prevent noisy-neighbour issues. Secrets and ConfigMaps are scoped per namespace to protect sensitive data. Together, these controls provide multi-tenant isolation while efficiently using shared clusters.

Energy efficiency

Energy-efficient datacentres
Yes
Description of energy efficient datacentres
https://cyberfortgroup.com/about/environmental-policy/

In addition to this Cyberfort are also certified to the industry recognised environmental standard ISO14001 which validates this commitment, certificate on request.

We source our power from a company called Bryt which is a zero carbon and 100% renewable electricity supplier.

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Full service, time limited

Discount

Provide your minimum discount applicable to your baseline prices
5%

Formula for calculating price of your services

Formula for calculating price of your services

Which of the core deployment models you intend to offer

Private Cloud

Private Cloud - Formula for calculating price of your services


Total Cost
The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
=
Baseline Pricing
Baseline pricing is found in G-Cloud Service Lines
-
Minimum Discounting
5%
+
Onboarding Activity
Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
+
Additional sources of cost
Any add on service such as CDN, WAF or similar service would incur additional costs
-
Additional sources of cost reduction
Typical cost reductions come from bulk buying or size of the total service contract

Mandatory certifications

Mandatory certifications

Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure

Sole Control of the Infrastructure

ISO 9001 certification

Provided

ISO 14001 certification

Provided

ISO 27001 certification

Provided

ISO 20000-1 certification

Provided

ISO 27017 certification

Provided

Are you bidding to provide services under Lot 1b or both Lot 1a and Lot 1b?

Yes

ISO 27018 certification

Provided

Cyber Essentials

Do you have a Cyber Essentials Plus certificate?
Yes
Cyber Essentials Plus certificate Number
C4e2105f-1a22-45f2-a18a-bfb2be57b46e

Non-mandatory Standards and certifications

ISO 28000:2022 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Other security certifications
Yes
Any other security certifications
  • ISO 27017
  • ISO 27018
  • ISO 27001

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Plans for positive actions with community groups.
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@axistwelve.com. Tell them what format you need. It will help if you say what assistive technology you use.