Bramble Hub - eXate Data Security Platform
eXate is a distributed software platform that enforces data privacy, data protection and fine grained access controls for data in motion and data at rest. The service applies attribute based and purpose based access controls to automatically enforce data policies and the principle of least privilege.
Features
- AI driven data classification across structured/semi/unstructured data
- Policy enforcement with attribute and purpose based access control
- Encryption based data protection software including post quantum cryptography
- Sovereignty aware data protection software enforcing jurisdictional compliance
- Chain testing: masking/synthetic data with ETL data replication services
- Data protection software securing AI and application data access
- API level data protection software without modifying underlying systems
- Dynamic masking and tokenization data protection software at query time
- Governance audit and reporting data protection software
- Security and control layer for cloud and cross platform migration
Benefits
- Rapid automated classification enables scalable enterprise data protection
- Real time policy control over API and data access
- Stronger cryptographic protection reduces risk of data compromise
- Assured regulatory compliance through enforced data sovereignty controls
- Reduced insider and misuse risk through fine grained access enforcement
- Secure AI and application access without exposing sensitive data
- Protects data via APIs without disrupting existing systems
- Minimizes sensitive exposure through dynamic masking and tokenization
- Faster audits through centralized governance evidence and reporting
- Secure cloud migration with continuous policy enforcement and control
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 5 2 3 8 5 4 8 4 6 6 3 6 9 8
Contact
BRAMBLE HUB LIMITED
Geoff Couling
Telephone: +44 (0) 2077350030
Email: contact@bramblehub.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Cloud native application protection platform
- Security analytics
- Governance, risk and compliance
Identity and access management
- Access
- Privilege
Network security
- Trusted network access and protection
- Active application security
Data security
- Information protection
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- EXate integrates with existing data platforms and applications to enforce data security and access policies. It operates as a sidecar service for APIs using REST or gRPC, integrates with JDBC drivers for databases, and supports bulk data protection for analytics platforms such as Apache Spark.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- EXate is delivered as a cloud native service and does not require buyer managed hardware. For customers with higher assurance requirements, eXate can be deployed using confidential computing capabilities provided by supported cloud platforms. This is recommended but not mandatory. Planned maintenance and upgrades are communicated in advance, and support is provided for non current versions for up to two years from release. Integration requires standard interfaces such as REST, gRPC or JDBC, subject to agreed service levels.
- System requirements
-
- Kubernetes 1.16 or later, or Red Hat OpenShift
- Minimum cluster capacity of 12 vCPU and 36GB RAM
- Microsoft SQL Server 2017 or later for metadata storage
- Optional Elasticsearch for audit log aggregation and search
- SSL or TLS certificates for HTTPS access to APIs
- Helm and kubectl tools for deployment and cluster management
- Supported key management services for encryption keys and secrets
- Optional confidential computing support from cloud platforms
- Cluster access with appropriate role based permissions
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Email and online ticketing support is provided. Bronze support is included on a best efforts basis. Silver, Gold and Platinum support packages offer defined response times, including 24/7 coverage for critical incidents under Platinum.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
EXate provides four structured support levels to meet varying operational requirements: Bronze, Silver, Gold and Platinum.
Bronze support is included by default and provides assistance on a best efforts basis during standard business hours. This level is suitable for non business critical use cases and provides access to email and ticketing support without guaranteed response times.
Silver support is available at additional cost and provides defined service levels Monday to Friday from 09:00 to 16:00 GMT or BST, with agreed response and resolution targets based on incident severity.
Gold support is available at additional cost and provides enhanced service levels Monday to Friday from 08:00 to 17:00 GMT or BST, including 24 by 5 coverage for critical Type 1 incidents and faster response commitments.
Platinum support is available at additional cost and provides full 24 by 7 coverage for critical incidents, including weekends and public holidays, with the fastest response times.
Optional technical account management and senior engineering support can be purchased to supplement any support tier where required. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- EXate supports onboarding through comprehensive user documentation covering deployment, configuration and operation of the service. Online training sessions are available at additional cost to support setup and usage. Onsite training can also be provided at additional cost where required. Technical support is available via email and online ticketing in line with the selected support level.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Customers can extract service metadata using documented APIs and Postman collections. Where applicable, customers can also retrieve configuration and audit metadata through supported export mechanisms. eXate does not prevent customers from accessing or extracting their data at contract end.
- End-of-contract process
- Upon contract termination or expiry, eXate ceases active policy enforcement and processing. The service no longer applies data transformations, masking or access controls. Customer data continues to reside in the customer’s source systems. Where eXate has applied encryption, customers may use supported JDBC drivers to decrypt the data and restore it to clear text within their own systems. Service access is withdrawn in line with contractual offboarding procedures. The contract price includes access to the eXate service, standard documentation, and Bronze level support on a best efforts basis. Data extraction using standard APIs is included. Any additional offboarding assistance, bespoke data export support, extended support, or professional services are available at additional cost if required.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
EXate provides APIs for runtime execution and policy enforcement within the data plane. Users can integrate the service with applications and data platforms, enforce access controls, apply data protection policies, and retrieve execution and audit metadata. Role based access controls restrict API actions by user or service role.
Design time and control plane functionality, including metadata management and service configuration, is available through the platform and is being extended to API access. At present, some administrative and configuration actions may require platform access rather than API calls. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- EXate can be customised through configuration and policy definition rather than code changes. Buyers can define custom privacy and data protection techniques, such as bespoke masking and transformation rules, to meet specific regulatory or business requirements. Customisation is performed using the platform configuration interfaces and design time APIs. Access to customisation features is restricted through role based access controls and is typically limited to authorised administrators or technical users designated by the buyer.
Scaling
- Independence of resources
- EXate enforces tenant isolation using an internal reverse proxy that applies per client quotas and rate limits. Where required, individual tenants can be provisioned with dedicated execution services and APIs to provide workload isolation. The service supports horizontal autoscaling to manage changes in demand and maintain consistent performance. These controls ensure that customer workloads are isolated and operated in line with public sector availability and assurance requirements.
Analytics
- Service usage metrics
- Yes
- Metrics types
- EXate provides service usage and data access metrics, including policy enforcement activity, data access volumes, and API usage associated with protected data. Service usage and data access metrics are available via APIs for authorised users.
- Reporting types
-
- API access
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- EXate provides tooling to enforce field level data protection for data at rest, including encryption, tokenization, pseudonymisation and masking depending on environment and policy. Protections are applied through fine grained access controls and policy enforcement at the data layer. Physical security of underlying storage is managed by the third party cloud or customer infrastructure provider.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export service metadata using documented APIs, including Postman collections. Exports are initiated by authorised users and retrieved through standard API responses.
- Data export formats
- Other
- Other data export formats
- JSON via REST APIs using Postman collections
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- CSV
- JSON
- XML
- Parquet
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- EXate does not provide a fixed availability guarantee that applies to all deployments. Availability depends on the buyer’s chosen deployment model, hosting environment and resilience configuration. Where the service is deployed on customer managed or third party infrastructure, availability is determined by that infrastructure and associated platform service levels. Any availability commitments or service levels are agreed contractually on a case by case basis where applicable.
- Approach to resilience
- EXate is designed using cloud native architecture principles, including stateless services, horizontal scaling and fault isolation. The service supports deployment across redundant infrastructure and availability zones where provided by the underlying cloud platform. Individual tenants may be deployed with dedicated execution services to further isolate workloads. Resilience of physical datacentres, power, networking and hardware is provided by the third-party cloud infrastructure provider hosting the service. Detailed datacentre resilience information is available on request.
- Outage reporting
- EXate provides application level health information through documented health and status APIs. Customers are responsible for configuring their own monitoring and alerting mechanisms using these APIs. For the hosted SaaS offering, service incidents are communicated through email notifications and the support ticketing system. For customer managed deployments, including on premises or private cloud, infrastructure level outages and alerting are managed by the buyer, with eXate providing application level support in line with the selected support level.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to eXate management interfaces is restricted using role based access control enforced through management APIs. Permissions are assigned based on user role and the principle of least privilege, ensuring users can only access functions required for their responsibilities.
Access to support channels is controlled through authenticated access to the support management platform. All support agents and internal users must authenticate, with permissions granted strictly based on role. Agents are limited to specific service projects and queues required for their job function, while administrative access is restricted to designated administrators. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- ISO 27701 and Cyber Essentials
- Information security policies and processes
- EXate operates a formal information security management system aligned with ISO/IEC 27001:2022 and ISO/IEC 27701. Security governance is risk based and includes defined ownership, regular risk assessments, policy review, and continuous improvement of security controls.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
EXate operates formal configuration and change management processes aligned with ISO IEC 27001 controls including A.8.9 Configuration Management and A.8.32 Change Management.
All service components are version controlled and tracked throughout their lifecycle using centralised repositories that maintain full history traceability and rollback capability. Access to source code infrastructure and configuration items is restricted through role based access controls.
All changes are managed through a formal change process. Each change is documented, reviewed and assessed for potential security impact on confidentiality integrity and availability before approval. Approved changes are tested, authorised, implemented and audited before deployment. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
EXate operates a vulnerability management process aligned with ISO IEC 27001 controls and OWASP guidance. All assets are recorded within a centralised inventory and reviewed through joiner mover and leaver processes. Potential threats are assessed through risk assessments, vulnerability scanning, and security testing of platform components.
Threat intelligence is obtained from supplier advisories, CVE disclosures, OWASP publications, and security tooling. Security patches are prioritized based on risk and severity. High and critical issues are remediated before production release. Patches are tested in non production environments before deployment. All vulnerabilities and remediation actions are tracked through governance processes for improvement activities. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
EXate operates protective monitoring controls aligned with ISO IEC 27001 requirements. Potential compromises are identified through centralised logging continuous monitoring and automated security tooling across platform services infrastructure and corporate endpoints. Application activity access events and security alerts are monitored across development test and production environments.
When a potential compromise is detected it is logged, assessed and investigated by authorised personnel to determine scope impact and cause. Containment and remediation actions include access revocation configuration changes, patch application and malware removal. Initial investigation begins promptly following detection. Response is prioritised by severity with critical incidents escalated under incident management procedures. - Incident management type
- Supplier-defined controls
- Incident management approach
-
EXate operates a formal incident management approach aligned with ISO IEC 27001 2022 controls A.5.24 and 6.13.1.1. Predefined processes exist for common events including platform downtime data breaches and business continuity incidents. All staff are trained to identify and report incidents promptly.
Users report incidents through defined channels including email to the Data Protection Officer for data breaches or the Chief Operating Officer for service incidents. All incidents are logged and managed through a centralised incident tracker. Incident status resolution actions and lessons learned are documented and reported to stakeholders. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS
- ISO/IEC 27001 accreditation date
- Tuesday 31 December 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- UKAS
- ISO 9001 accreditation date
- Tuesday 31 December 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 94c671e6-823b-4c1b-9e66-be61b04e765c
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 3b271556-6f71-40cd-bd60-169f03c35f6e
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-