Skip to main content

Help us improve the Digital Marketplace - send your feedback

Bytes Software Services

Proofpoint Complete Package

Proofpoint's Complete package adds Email Fraud Defence, Secure Email Relay, Supplier Threat Protection, Email DLP & Encryption, Misdirected Email & Email Exfiltration, TAP ATO & ITDR Spotlight to the Core package offerings. bssgc

Features

  • Extend protection to your customers and partners.
  • full visibility and control of email sent from your organization.
  • complete view into all email in and out your organization.
  • Maintain the trust people place on your email communications.
  • Stop email fraud targeting your employees, customers, and partners
  • Implement email authentication quickly and confidently on domains and gateway.
  • Detect data exfiltration
  • Identify Risky lateral data movement
  • Identify Privilege abuse
  • Surface application misuse

Benefits

  • Replaces on-premises relays with a secure, cloud-based alternative
  • Automate the identification of legitimate email sent on your behalf.
  • Understand reasons behind—learn how to fix—each authentication failure.
  • Get ongoing guidance and support from our professional services team.
  • to deploy email authentication efficiently on your domains and gateway
  • Prevent BEC and phishing attacks that target your employees.
  • Account for email to your organization with visibility and control.
  • Authorize for email to your organization with visibility and control.
  • Reduce false positives in the SOC through high fidelity alerts
  • Ensure early attacker detection and comprehensive threat investigations

Pricing

£54.59 a user

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@bytes.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

2 9 5 3 9 1 2 6 4 3 9 6 8 6 7

Contact

Bytes Software Services Chris Swani
Telephone: +44 (0) 7951 326815
Email: tenders@bytes.co.uk

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Extension to messaging platform services – eg On Premise Exchange, Office 365, Google Apps
Cloud deployment model
Community cloud
Service constraints
See Service Level Agreement
System requirements
  • Existing mail server
  • Exchange
  • O365
  • Zimbra
  • Lotus Notes

User support

Email or online ticketing support
Email or online ticketing
Support response times
Dependant on Service Level Purchased
Support Portal - All Levels
Telephone Support Business Hours
Telephone Support 365x24x7
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Self-Service, Platinum, Premium & Global
Self-Service: primary access via portal, phone support limited to business hours P1 issues, 2 authorised support contacts
Platinum: access via portal and phone, phone support for all priorities during business hours plus P1 issues 24x7, 4 authorised support contacts
Premium: access via portal and phone, phone support for all priorities during business hours plus P1 issues 24x7, 6 authorised support contacts, assigned Technical Account Manager 
Global: available to Platinum and Premium only. phone access for all cases, all priorities 24x7x365, 12 authorised support contacts
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Installation and training / knowledge share available with dedicated engineer
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data extraction tools driven by customer.
End-of-contract process
Services cease to function.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • MacOS
  • Windows
  • Windows Phone
  • Other
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
N/A
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Utilisation of a reporting dashboard - eg Palo Alto
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
All Proofpoint SaaS systems are actively monitored with local agents collecting hundreds of metrics specific to hardware, networking, and OS. All metrics are measured against a baseline compiled from historical data. Acceptable thresholds are defined based on a combination of optimal performance targets and historical baselines.

Analytics

Service usage metrics
Yes
Metrics types
Granular Reporting of message flow, deep analysis into threats
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Proofpoint

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Access to the Proofpoint production environment, where services are hosted, is granted based on role and occurs via a 2FA encrypted VPN.
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Data extraction tools driven by customer.
Data export formats
Other
Other data export formats
N/A
Data import formats
Other
Other data import formats
N/A

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
Proofpoint has documented information security program consisting of policies, procedures and standards that aligns with the requirements of NIST 800-53 and ISO 27001. The program is owned by the Proofpoint Global Information Security group, and includes a continuous monitoring program consisting of monthly and quarterly evidence collection and review, and an annual SOC 2 Type II audit of the program.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Policies, procedures, and standards comprising the Proofpoint information security program are reviewed and updated annually by the Proofpoint Global Information Security group and approved by the Proofpoint CFO.

Availability and resilience

Guaranteed availability
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
Approach to resilience
The services run in active/active mode between a pair of gegraphically-diverse co-location facilities.
Outage reporting
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
All access to the Proofpoint production environment, where services are hosted, is via a 2FA encrypted VPN and granted based on role.
Access restriction testing frequency
At least once a year
Management access authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
All access to the Proofpoint production environment, where services are hosted, is via a 2FA encrypted VPN and granted based on role.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Less than 1 month
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
SOC 2 Type II audit report, available here: https://go.proofpoint.com/soc2_report_request.html

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
N/A
Information security policies and processes
NIST 800-53

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Proofpoint has a documented change management policy that includes requirements around documented change tickets and review and approval by the Change Review Board.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Proofpoint performs internal and external vulnerability scanning and remediates applicable findings in line with the Proofpoint patch management policy.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Proofpoint has distributed monitoring in place for availability, performance, capacity and security. Alerts are directed to a 24x7 NOC or SOC for review, remediation and/or escalation.
Incident management type
Supplier-defined controls
Incident management approach
Proofpoint has a documented Incident Response Plan that includes procedures to detect, investigate, remediate and communicate security incidents. A trained IRT team is responsible for the maintenance of the program.

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

Fighting climate change

Fighting climate change

We take our environmental management and the impact we have on the environment very seriously. We have environmental policies in place and hold the ISO14001 accreditation. Our environmental assessments are conducted annually by an external Lead ESOS Assessor; they are signed-off by the board and compliance reported to the regulator (the Environment Agency). Our environmental policy is published on our website at https://www.bytes.co.uk/company/sustainability/environmental.
Bytes achieved carbon net zero in March 2022 through approved carbon offsetting schemes. We are always seeking to reduce our impact on the environment. We aim to minimise waste, reduce pollutants and use renewable materials. Our offices have recycling facilities for cans, plastic and paper. We aim to reduce our office printing to zero within the next few years.
An Environmental Steering Committee has been established to coordinate environmental activities and drive change.
To drastically reduce our emissions, we have switched to renewable energy. Our Head Office has reached our first milestone of using a specialist 100% renewable electricity provider. We are also exploring options to install solar panels on our Headquarters building.
Other environmental initiatives include installing electric vehicle charging points and encouraging staff to commute to work without the car (setting up a car share network and installing secure cycle parking).
We produce a SECR (Streamlined Energy and Carbon Reporting) report that details the companies energy consumption and carbon emissions. This report is produced annually by an independent assessor.
This report provides details of our emissions in Scope 1, 2 and 3 categories. It details the activities previously taken to reduce emissions and also recommendations for further improvements.
For scope 1,2 and 3 emissions we aim to reduce these by 50% by 2025-2026 from our 2021 baseline.
We aim to be Net Zero by 2040, covering our own operational emissions.

Pricing

Price
£54.59 a user
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Provided by a Proofpoint Engineer once requirements are confirmed.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@bytes.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.