Hosting, Continuous Integration and Deployment Application Platform (PaaS)
A Platform-as-a-Service (PaaS) tool built for hosting and continuous deployment. Its infrastructure allows you to host web applications on the cloud while making your development and testing workflows more productive. Developers can easily merge their own code into production and deploy across multiple cloud providers without help from DevOps.
Features
- Create and launch projects independently or with teams
- Built in Continuous Integration and Continuous Deployment (CI/CD)
- Instant cloning
- Adaptable workflows
- Automated updates and 24/7 support
- ISO27001 certified hosting in highly secure UK based locations
- Redundant Enterprise architecture with 99.99% uptime guranteed
- Specially tuned for PHP, Drupal, Symfony
- GUI, API and CLI-based service management tools
- Significantly reduce reliance on DevOps team
Benefits
- Automated Continuous Integration (CI) and Continuous Deployment (CD)
- Significantly reduce reliance on DevOps team
- Increase developer productivity
- Faster User Acceptance Testing
- Increase frequency of deployments
- Deploy from anywhere and at anytime
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 0 6 9 5 8 4 2 3 6 4 4 0 2 7
Contact
AXIS12 LTD
Luke Harrop
Telephone: +44 (0) 203 397 8514
Email: tenders@axistwelve.com
About your service
- Service categories
-
PaaS
Application Platforms
- Deployment-centric application platforms
Service scope
- Service constraints
- No known constraints. All OS and hardware configurations supported
- System requirements
-
- Container, Virtual machines and serverless compute available
- Linux or Windows based operating system
- Cloud deployment model
-
- Public cloud
- Private cloud
User support
- Email or online ticketing support
- Yes
- Support response times
- Acknowledgement of questions raised in a support ticket is conducted within 5 minutes. Tickets are triaged and actioned in accordance with our strict SLAs, which range from 60mins through to 5 business days depending on the urgency and severity of the issue.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have tested with various assistive technology users.
- Onsite support
- Yes, at extra cost
- Support levels
- Axis12 provide a range of different support ranging from 24/7 x 365 through to Core hours: Office hours (08:30 – 17:30 Monday to Friday on standard UK business days). Costs vary depending on level of service required and staff type. Every client will have a named account manager experienced in diagnosing and directing requests to the correct resource.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
This first step we take during on-boarding is to create a support project in our back-office support system (Jira). You will need to supply us with a primary contact (through which all change requests will be routed)
plus one or more email addresses for alerts and tickets. Training in how to use Jira for logging tickets will be provided as part of the on-boarding process.
We will confirm your architecture requirements and your servers will then be commissioned and configured.
Provisioning generally takes anywhere from 2-3 hours up to 2-3 days depending on the complexity of your requirements. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- This can be provided by logging a support request with the team.
- End-of-contract process
- Off-boarding involves removing all accounts associated with back-office systems involved in your deployment and securely deleting all data held in line with our ISO 27001 processes. We can provide an archive of all support tickets if requested. Data held on the servers can be packaged and delivered on request although this may incur a small fee. We will also securely delete all tickets in the Jira project we created for you.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Using the web interface
-
For non-production environments "Podium" is Axis12’s proprietary container based hosting platform, with a web interface that allows seamless delivery of code deployment through to realtime infrastructure build.
Built on leading Enterprise class open source technology, it is a ‘no Ops’ solution to building scalable and performant infrastructure on demand and can save development teams countless hours and delays through no longer having to rely on DevOps to build and deploy code to virtual servers.
For production servers "Axis12 Deploy" is the web interface available to client wish to have control over live deployments. - Web interface accessibility standard
- WCAG 2.2 AA
- Web interface accessibility testing
- None, but planned for 2026
- API
- Yes
- What users can and can't do using the API
- There is, but it is only made available on request and subject to certain conditions.
- API automation tools
-
- Ansible
- Chef
- Puppet
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Command line interface
- Yes
- Command line interface compatibility
-
- Linux or Unix
- Windows
- Using the command line interface
-
For non-production servers we provide a command interface that can be accessed through a web interface and so is accessible via any OS and any browser.
For production servers, unless explicitly requested the command line interface is for Axis12 DevOps staff only. However we are able to provide access via VPN if required and subject to certain conditions.
Scaling
- Independence of resources
- We run quality of service metrics on our systems and automatically move / scale resources if demand effects availability
- Usage notifications
- Yes
- Usage reporting
- Optimising consumption
- Yes
- Automatic scaling
- Yes
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Backup and recovery
- What’s backed up
-
- Files
- Database
- Configuration
- Codebase
- Backup controls
- Users can backup at different times and frequency depending on client need
- Datacentre setup
- Multiple datacentres with disaster recovery
- Scheduling backups
- Users contact the support team to schedule backups
- Backup recovery
- Users contact the support team
- Backup and recovery
- Yes
- RPO/RTO
- Yes
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
99.95% uptime as standard. Higher uptime guarantees on request.
Support for Level 1 issues and planned Support Requests (Levels 2-5) where agreed in advance. An out-of-hours telephone number is provided for The Customer to escalate any Level 1 issues. The Supplier will respond to and action any Level 1 issues in accordance with the response targets.
Hosting and infrastructure issues will be actioned within the resolution targets.
Level 1 issues caused by an application or content change made within non-Core hours will be actioned on a best efforts basis. Outages caused by these issues will be exempt from the uptime measurements and Service Level Credit calculations, and the support services may be chargeable. - Approach to resilience
- Resilience is provided across our Priority 1 systems through load-balanced firewalls and switches, multiple reverse proxy servers with automatic failover capability, multiple high-availability webservers and a scale-out NAS file system.
- Outage reporting
-
Our monitoring systems produce email alerts in near real-time.
A ticket is automatically created in our web based ticketing system called Jira. Client is also telephoned immediately. Investigation commences, and any updates to the Jira ticket (at least one every 15 minutes in the case of an outage) triggering update emails to client.
Month end reporting will show full duration and detail of any outages based on monitoring and Jira statistics.
By tracking all support activity through Jira and giving our client full access we provide you with total transparency over the way an issue is being handled and report on our activities against the service level agreement each month.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls, least privilege, and strong authentication. Administrative access is limited to authorised personnel, protected by multi-factor authentication and accessed via hardened bastion hosts. Management interfaces are segregated from customer networks and exposed only through secure, restricted endpoints. Support channels are accessible only to trained staff with defined responsibilities. All access is logged, monitored, and regularly reviewed, with permissions promptly removed when no longer required, ensuring access controls meet OFFICIAL and OFFICIAL-SENSITIVE expectations.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Dedicated device on a government network (for example PSN)
- Dedicated device over multiple services or networks
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
-
ISO 27017
ISO 27018
Cyber essentials plus - Information security policies and processes
-
We operate a comprehensive set of information security policies and processes aligned to ISO/IEC 27001 principles and UK public-sector expectations. These include policies for information security, access control, asset management, data protection, incident management, secure development, supplier assurance, and business continuity. Policies are reviewed at least annually and whenever there is a material change to risk, technology, or regulation.
Overall accountability for information security sits with senior management, with day-to-day responsibility delegated to a nominated Information Security Lead. Security risks, incidents, and compliance status are reported regularly to the senior leadership team, ensuring oversight and timely decision-making.
Policies are embedded through defined operational processes, mandatory staff induction and annual refresher training, role-based access controls, and documented procedures for handling data and incidents. Compliance is reinforced through internal audits, management reviews, vulnerability management, and regular testing of controls. Any non-conformances are recorded, tracked, and remediated.
This structured approach ensures information security is consistently applied across the organisation, understood by staff, actively governed, and continuously improved.
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We operate a defined change control process supported by the Axis12 Change Control system. All service components are recorded and tracked throughout their lifecycle, from initial deployment through change, release, and decommissioning. Each change request is formally documented and assessed by an authorised Change Approver, considering risks, benefits, and potential security impact, including confidentiality, integrity, and availability. Approved changes follow a structured design, testing, and implementation process, with stakeholder review. A final post-implementation assessment confirms success or failure, and changes are closed or reopened as appropriate.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Axis12 are constantly monitoring the various major alert/information channels for threats to our system. Each threat is classified Critical, High, Low with expected implementation times as follow.
- 'Critical’ patches should be deployed within hours.
- 'High’ patches should be deployed within 2 weeks of a patch becoming available.
- ‘Low’ patches deployed within 8 weeks of a patch becoming available. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Axis12 have a range of automated and manual approaches to protective monitoring that are constantly being reviewed as new threats are identified within the industry. We work closely with our hosting partners and other industry experts. The exact process is available on request.
Incident responses are reviewed and classified in our ‘Security Incident (System)’ and assigned to the appropriate Service Level to the incident with the appropriate level of technical resources to resolve the issue. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a formal incident management process aligned to ISO/IEC 27001 and UK public-sector expectations. Pre-defined procedures exist for common incidents, including security events, service disruption, and data breaches, with clear severity levels, response times, and escalation routes. Users report incidents via a dedicated service desk and monitored support channels. All incidents are logged, triaged, investigated, and resolved by authorised personnel. For significant incidents, we provide written incident reports covering impact, root cause, containment actions, recovery, and lessons learned, supporting transparency, assurance, and continuous improvement.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Supplier
- Virtualisation technologies used
- Other
- Other virtualisation technology used
- Kubernetes
- How shared infrastructure is kept separate
- Different organisations are kept apart through layered isolation controls. Each organisation is assigned its own namespace, separating workloads, services, and configurations. Role-Based Access Control (RBAC) ensures users and service accounts can only access their permitted resources. Network Policies restrict pod-to-pod communication, preventing unauthorised traffic between organisations. Resource quotas and limits guarantee fair usage and prevent noisy-neighbour issues. Secrets and ConfigMaps are scoped per namespace to protect sensitive data. Together, these controls provide multi-tenant isolation while efficiently using shared clusters.
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
-
https://cyberfortgroup.com/about/environmental-policy/
In addition to this Cyberfort are also certified to the industry recognised environmental standard ISO14001 which validates this commitment, certificate on request.
We source our power from a company called Bryt which is a zero carbon and 100% renewable electricity supplier.
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Full service, time limited
Discount
- Provide your minimum discount applicable to your baseline prices
- 5%
Formula for calculating price of your services
- Formula for calculating price of your services
-
Which of the core deployment models you intend to offer
Private CloudPrivate Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
- =
- Baseline Pricing
- Baseline pricing is found in G-Cloud Service Lines
- -
- Minimum Discounting
- 5%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- Any add on service such as CDN, WAF or similar service would incur additional costs
- -
- Additional sources of cost reduction
- Typical cost reductions come from bulk buying or size of the total service contract
Mandatory certifications
- Mandatory certifications
-
Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure
Sole Control of the InfrastructureISO 9001 certification
ProvidedISO 14001 certification
ProvidedISO 27001 certification
ProvidedISO 20000-1 certification
ProvidedISO 27017 certification
ProvidedAre you bidding to provide services under Lot 1b or both Lot 1a and Lot 1b?
YesISO 27018 certification
Provided
Cyber Essentials
- Do you have a Cyber Essentials Plus certificate?
- Yes
- Cyber Essentials Plus certificate Number
- C4e2105f-1a22-45f2-a18a-bfb2be57b46e
Non-mandatory Standards and certifications
- ISO 28000:2022 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 27017
- ISO 27018
- ISO 27001
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Plans for positive actions with community groups.
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-