Skip to main content

Help us improve the Digital Marketplace - send your feedback

HEXIOSEC LIMITED

Hexiosec Transfer

Hexiosec Transfer is a secure file transfer solution with true end-to-end encryption, designed for organisations that need control and confidentiality when sharing sensitive data. It supports secure file transfer, forms, email and spaces, ensuring only intended recipients can ever access data.

Features

  • Secure file transfer
  • Secure forms
  • Secure email
  • Secure spaces
  • True end-to-end encryption
  • Built, maintained and hosted in the UK
  • Outlook add-in

Benefits

  • Send files securely
  • Request form data securely
  • Send emails securely
  • Collaborate with others securely
  • No one else can access your data, not even us
  • Maintain control of your data sovereignty
  • Send files as easily as attachments from Outlook

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at frameworks@hexiosec.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 8 3 2 3 7 9 6 4 2 0 9 0 3 5

Contact

HEXIOSEC LIMITED Rob Wright
Telephone: 01242474970
Email: frameworks@hexiosec.com

About your service

Service categories

Applications

Content workflow and management

Content services

  • Content Sharing and Collaboration Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
N/A
System requirements
Available via your browser

User support

Email or online ticketing support
Yes
Support response times
Usually within 4 hours during office hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support is provided during office hours via email and phone. This is triaged by a Product Support Specialist, who will either resolve the query themselves or engage one of our engineering team as required.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Every new organisation will be provided with a video call and demonstration of Hexiosec Transfer so they can easily set up and start using the service. We help users start using our service by providing comprehensive online user documentation through our support portal and documentation site. This includes detailed guides on setup, secure file sharing, and API integration. We also offer responsive online support via email and in-app help during UK business hours, with typical response times within 4 hours.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
No user data is held, with the exception of any data transfers, which will remain accessible for up to 28 days (as specified by the user, the same as during the contract).
End-of-contract process
At the end of the contract any data transfers will remain accessible for up to 28 days as specified by the user (the same as during the contract).
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
N/A
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
Hexiosec Transfer provides a REST API for secure file operations and user management. Users can set up the service by authenticating via OpenID Connect (e.g., Microsoft Entra ID or Google Workspace) and generating an API key from an authenticated session. API calls require either a valid session cookie or API key header.
Through the API, users can manage their own profiles, transfer files, and perform tenant-scoped tasks based on assigned roles and groups. Changes such as resource updates or configuration adjustments are allowed only if the user has the necessary permissions. All interactions are logged for audit and compliance.
Limitations include strict role-based access control, meaning low-privilege users have limited capabilities (often read-only). API keys cannot be created without prior authentication and appropriate privileges. Requests must meet validation rules; invalid calls return errors. MFA may be enforced by the tenant’s identity provider.
Documentation is available in HTML and PDF formats, with additional internal resources. There are no limitations to the API, however client integrations will have to implement the encrypt/decrypt interface as is required for end-to-end encryption.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Organisations can apply their own branding to the Hexiosec Transfer service to give confidence to recipients. Authorised users within the organisation can configure branding customisations, and Hexiosec will assist with these customisations. Optional security features can be enforced on a user or group level, via a discussion with our support team.

Scaling

Independence of resources
Hexiosec Transfer uses scalable cloud services so there are no practical limitations through demand. The service is monitored during office hours to ensure this is the case.

Analytics

Service usage metrics
Yes
Metrics types
Users can see when their files were downloaded and by what IP address or what email address if selected. Users can see how many times their files have been downloaded. Administrators can see how many file transfers have been made and how many GB have been transferred.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
Less than once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
No user data is held by the service, with the exception of any data transfers (the purpose of the service). Users can access that data according to the policies they set up when creating the transfer. No other type of data export is applicable.
Data export formats
Other
Other data export formats
Original format they imported the data in.
Data import formats
Other
Other data import formats
Any file format can be sent via the service.

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We aim to provide continuous access to Hexiosec Transfer using high-availability infrastructure, but we do not guarantee a specific uptime level unless a separate SLA is agreed. Maintenance, updates, or unforeseen events may cause interruptions. Standard terms include email-based support during UK business hours, with no guaranteed response times unless covered by an SLA.
Approach to resilience
Available on request.
Outage reporting
Email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Hexiosec Transfer has been written as a secure file transfer capability by cyber security engineers with experience in developing crypt-key for the highest level of government security. For more information about Hexiosec Transfer, including how we restrict access in management interfaces and support channels, please ask for further information.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Hexiosec operates a single, coherent set of policies and processes aligned with ISO 27001 and NCSC Cyber Assessment Framework. Governance ensures security risk ownership at appropriate levels with documented roles and responsibilities. All employees, contractors, and third-party users must read and understand the Information Security Policy. Policies map to ISO 27001 controls and CAF objectives, supporting compliance and resilience. Risk management includes structured assessments, asset visibility through Hexiosec ASM, supply chain assurance, and defined incident response processes. Governance is reinforced by continuous improvement through regular reviews, audits, and updates, embedding security awareness and accountability across the organisation.
Information security policies and processes
Hexiosec follows a single, coherent set of policies and processes aligned with ISO 27001 and NCSC Cyber Assessment Framework objectives. Our Information Security Policy applies to all employees, contractors, and third-party users who interact with Hexiosec information. Policies map directly to ISO 27001 controls, ensuring compliance and resilience. Security risk ownership is embedded at appropriate levels with documented roles and responsibilities. Governance includes structured risk assessments, asset visibility through Hexiosec ASM, supply chain assurance, and defined incident response processes. Policies are enforced through continuous improvement, regular reviews, audits, and updates. All staff must read and understand the Information Security Policy, embedding security awareness and accountability across the organisation.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Hexiosec follows documented configuration and change management processes aligned with ISO 27001. All components are tracked through their lifecycle using formal records and audit trails to ensure accuracy and accountability. Changes are managed through structured reviews and approval workflows, with each change assessed for potential impact before implementation. This includes validation against established policies and documented controls to confirm compliance and minimise risk. Regular audits and continuous improvement cycles ensure that configuration baselines remain current and that all changes are properly recorded, authorised, and communicated across the organisation.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Hexiosec is an expert in vulnerability management. We maintain a vulnerability management plan that captures, triages, and prioritises issues based on severity and impact. Knowledge of public vulnerabilities is kept up to date through automated dependency advisories and external scanning of public-facing sites. Renovate is used for automated updates, ensuring timely remediation. Threat intelligence sources include CISA’s Known Exploited Vulnerability list and Exploit Prediction Scoring System (EPSS) data, adding real-world context to risk assessments. Combining severity, known exploits, and likelihood of active exploitation ensures critical vulnerabilities are addressed promptly while lower-severity items are managed effectively within development sprints.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Hexiosec’s incident management policy defines how vulnerabilities are escalated and communicated to relevant internal security stakeholders. Clear escalation to internal security teams ensures vulnerabilities are assessed quickly and addressed effectively, reducing the risk of delayed response. The policy also covers communication with affected customers in the event of a vulnerability or incident. Customers are notified promptly with appropriate guidance, helping them take protective action, reducing impact, and maintaining trust in Hexiosec’s services. This structured approach ensures timely reporting to internal teams and affected customers, supporting rapid containment and remediation.
Incident management type
Supplier-defined controls
Incident management approach
Hexiosec has pre-defined processes for common security events as part of its incident management policy. The policy defines how vulnerabilities and incidents are escalated and communicated to relevant internal security stakeholders, ensuring rapid assessment and effective response. Users can report incidents through established communication channels defined in the policy, which include direct escalation to internal security teams. When an incident occurs, affected customers are informed promptly with appropriate guidance to help them take protective action and reduce impact. Incident reports are provided in line with the policy, ensuring clear communication and maintaining trust in Hexiosec’s services.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
You can book a live demo to see the platform in action or create a free account to try out the key functionality. Our team will walk you through the key features and help you get set up quickly.
Link to free trial
https://transfer.hexiosec.com/signin?register=true

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
3%
Between £500,001 and £1,000,000
6%
Between £1,000,001 and £2,500,000
9%
Between £2,500,001 and £5,000,000
12%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Ba00785d-7c2f-403c-9759-0f8d8067aa6a
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Volunteering opportunities for staff
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at frameworks@hexiosec.com. Tell them what format you need. It will help if you say what assistive technology you use.