Skip to main content

Help us improve the Digital Marketplace - send your feedback

EXPONENTIAL-E LIMITED

Azure Stack

Exponential-e Azure Stack Hub, Edge & HCI Service is a hybrid cloud platform that enables the provision of Azure Virtual Machines, SQL Server Databases, and Marketplace items from dedicated infrastructure hosted in your own facilities. It is also available in portable, ruggedised form for expeditionary land, sea, or air operations.

Features

  • Azure native compute deployed at your existing secure hosting facilities
  • Fully integrated with Azure
  • Option to bring-your-own Windows licenses
  • Can extend Azure technologies to locations without continuous connectivity
  • Ruggedised versions for expeditionary land, sea, or air operations
  • Lifecycle management & validated patches
  • Validated compute and storage nodes
  • Monitoring and Management by Exponential-e with integration to Support Desk

Benefits

  • Dedicated infrastructure meets specific security and compliance requirements
  • Leverage common CI/CD/DevOps skills across public-cloud and dedicated facilities
  • Deploy Azure based compute at the edge in expeditionary scenarios
  • Deploy Azure based compute for static use cases

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at psbids@exponential-e.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 5 2 7 3 8 9 6 2 3 8 8 1 2 0

Contact

EXPONENTIAL-E LIMITED Kay Sugg
Telephone: 02034358835
Email: psbids@exponential-e.com

About your service

Service categories

IaaS

IaaS Compute

  • Bare metal
  • Container and serverless engine compute

Virtualised x86

  • General purpose
  • Compute optimised
  • Memory optimised

Accelerated

  • GPUs

Service scope

Service constraints
Managed with Azure portals and services as a dependency.
System requirements
  • Suitable facilities if to be customer-hosted
  • Suitable network uplinks with BGP
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud

User support

Email or online ticketing support
Yes
Support response times
P1 Target Response Time - 15 mins
P2 Target Response Time - 15 mins
P3 Target Response Time - 30 mins
P4 Target Response Time - 30 mins
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Exponential-e provides the Azure Stack as a 24x7 managed service.

We manage the appliance health, software upgrades and availability on an ongoing basis. Customer will be responsible for all backup jobs, remediation and policy management unless electing for our managed backup service, whereby we undertake management, remediation and policy management for protect items (this is provided within our Flex Manage Service offerings as a supplementary service).
Support available to third parties
Yes

Onboarding and offboarding

Getting started
The service low-level design is developed through a series of workshops run jointly by Exponential-e and our infrastructure providers Dell Technologies & Microsoft. Dell provide the systems and physical installation and perform the base configuration according to the low-level design.

Exponential-e onboard the services for support and management, connect the system to the desired Azure tenancy, and provide billing and (where required) licensing.

Exponential-e can also provide training where required.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data can be transferred to any other Azure availability zone or third-party hosting following standard Azure connectivity principles.
End-of-contract process
All transition work from the contract undertaken by Exponential-e may be considered additional services and subject to additional charges.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Using the web interface
The Azure Stack appears as an availability zone within the associated Azure tenancy and is managed via Azure portals as with all other aspects of the Azure platform.
Web interface accessibility standard
WCAG 2.2 AAA
Web interface accessibility testing
See: https://azure.microsoft.com/mediahandler/files/resourcefiles/microsoft-azure-compliance-offerings/Microsoft%20Azure%20Compliance%20Offerings.pdf
API
Yes
What users can and can't do using the API
Azure Stack uses the same APIs as do the Azure services delivered from public availability zones.
API automation tools
  • Ansible
  • Chef
  • SaltStack
  • Terraform
API documentation
Yes
API documentation formats
  • HTML
  • PDF
Command line interface
Yes
Command line interface compatibility
  • Linux or Unix
  • Windows
  • MacOS
  • Other
Using the command line interface
Resources deployed on Azure Stack can be managed via PowerShell or Azure CLI in the same way as if they were deployed on a public Azure availability zone.

Scaling

Independence of resources
The Azure Stack platform as deployed by Exponential-e is dedicated to a single tenant and appears within the associated Azure subscription as an availability zone.
Usage notifications
Yes
Usage reporting
  • API
  • Email
  • Other
Other usage reporting
Via regular Service Reporting.
Optimising consumption
Yes
Automatic scaling
Yes

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • CPU
  • Disk
  • HTTP request and response status
  • Memory
  • Network
  • Number of active instances
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Backup and recovery

What’s backed up
  • NTFS and ReFS volumes, shares, folders, files and system state
  • SQL Server 2019, 2017, 2016 and 2014
  • Exchange Server 2019 and 2016
  • Mailboxes and mailbox databases in an Exchange DAG
  • SharePoint 2019 and 2016 farms and front-end web server content
  • All other services under Azure Stack can be backed up
Backup controls
The Microsoft Azure Backup Service manages backups to and restores from the Azure Stack offering.

Protection groups are used to configure and manage data protection. A protection group is a collection of data sources that share the same protection configuration. The protection configuration is the collection of settings common to a protection group, such as the protection group name, protection policy, storage allocations, and replica creation method.

At regular intervals that you can configure, the service creates a recovery point for the protected data source, which is a version of the data which can be recovered.
Datacentre setup
Multiple datacentres with disaster recovery
Scheduling backups
Users schedule backups through a web interface
Backup recovery
  • Users can recover backups themselves, for example through a web interface
  • Users contact the support team
Backup and recovery
Yes
RPO/RTO
No

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
If provided on a customer site, availability cannot be provided with an SLA as Exponential-e cannot provide an SLA for customer owned power and security. The appliance is a fully redundant hardware design to remove single points of failure and would therefore be considered a 99.9% architecture. If deployed in an Exponential-e Data Centre, a single site solution is provided with 99.9% availability, or 99.95% for a dual site deployment.
Approach to resilience
Azure Stack is provided as a pre-validated configuration designed by Dell Technologies and approved by Microsoft. The system uses a standard N+1 resilient architecture with no single point of failure. Further information available on request.
Outage reporting
Service status is reported in real-time via the Azure management plane. Additionally, Exponential-e report outages via: a customer dashboard and email alerts. Exponential-e are ISO2000-1 accredited and follows standard ITIL conformant processes to notify affected customers in the event of a service outage.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Details available on request.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Devices users manage the service through
  • Dedicated device on a segregated network (providers own provision)
  • Dedicated device over multiple services or networks
  • Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
  • Directly from any device which may also be used for normal business (for example web browsing or viewing external email)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Depending on the sector we are engaging with, we work with the customer to align design, process and policy to the most appropriate framework. We typically align all services to ISO27001, ISO27017, and NCSC requirements. Exponential-e maintain accreditations under Cyber Essentials and Cyber Essentials Plus.

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Details available on request.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Details available on request.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Details available on request.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Exponential-e’s Incident Management process is integrated into its ISO9001 and ISO20000-1 accredited framework. Pre-defined procedures address common events, with examples including automated scripts for capacity-related issues. Incidents are reported by users via email, phone, or ServiceNow, which generates a tracking number for efficient handling and prioritisation. These incidents are logged, allocated to appropriate teams, and resolved based on their urgency and impact. Incident updates are provided regularly, with detailed reports shared for major incidents. Post-resolution evaluations ensure continuous improvement, supported by root cause analyses and formal Reason for Outage reports
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Third-party
Third-party virtualisation provider
Microsoft Azure
How shared infrastructure is kept separate
Azure Stack when provided by Exponential-e is deployed as a single tenant appliance.

Energy efficiency

Energy-efficient datacentres
Yes
Description of energy efficient datacentres
Exponential-e datacentres comply with ISO 950001 - Energy Management System (or ESOS). Exponential-e also holds ISO 14001 and ISO 50001.

Pricing

Discount for educational organisations
No
Free trial available
No

Discount

Provide your minimum discount applicable to your baseline prices
5%

Formula for calculating price of your services

Formula for calculating price of your services

Which of the core deployment models you intend to offer

Private Cloud

Private Cloud - Formula for calculating price of your services


Total Cost
The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
=
Baseline Pricing
Baseline Pricing for these services will be found under the G-Cloud Service Lines, within the Pricing Document.

The applicable price point is determined by factors such as required performance levels, availability requirements, data protection, and scale.

This pricing approach allows buyers to clearly understand entry-level costs while retaining flexibility to scale performance and capacity in line with workload demands. All pricing assumptions and variables will be clearly described to ensure buyers can accurately forecast costs and assess value for money.
-
Minimum Discounting
5%
+
Onboarding Activity
Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
+
Additional sources of cost
In addition to baseline pricing, buyers may incur additional costs depending on their existing infrastructure, data volumes, and integration requirements.

One potential cost is dedicated network connectivity. For data-intensive workloads such as digital pathology, GPU computation, or HPC environments, buyers may require enhanced or private connectivity. Where required, dedicated network services can be provided and scoped separately to meet performance, security, and availability needs. For health and care organisations, this may include connectivity via the Health and Social Care Network (HSCN).
Additional variations in the costs for licencing and compute may also apply.

Data migration may also introduce additional costs. Buyers transitioning from existing on-premises or third-party storage platforms may require support to transfer large datasets, validate data integrity, and minimise service disruption. Migration activities are scoped based on data volume, complexity, and delivery timelines and can be delivered as a professional service, including discovery, planning, execution, and post-migration validation.

In greenfield deployments, where no existing data platform is in place, data migration costs would not apply.

Additional costs may arise from optional services such as enhanced resilience, bespoke configurations, or specialist support. Any such services would be clearly defined and agreed with the buyer prior to contract commencement.
-
Additional sources of cost reduction
This model provides several opportunities for cost reduction, depending on the service configuration/scaling over time. The proposed approach uses a hybrid scale-out storage architecture, combining high-performance nodes with archive-optimised nodes to deliver a single, aggregated storage platform, enabling buyers to align costs directly with workload requirements.

A primary source of cost efficiency is the ability to balance performance and archive tiers. High-performance nodes command a higher price per GB within the defined pricing range, while archive nodes offer significantly lower-cost storage for data that is accessed less frequently. By limiting high-performance capacity to only where it is required and increasing the proportion of archive nodes, buyers can reduce the overall cost per GB.

Additional savings are achieved by reducing/removing front-end performance nodes where sustained high throughput is not necessary. The platform can operate predominantly as a scale-out archive solution, optimised for capacity rather than performance.

As service demand grows, cost efficiency is maintained by selectively expanding archive capacity rather than scaling performance uniformly. This targeted approach ensures buyers only pay for capabilities needed at each stage.

Together, these configuration options allow buyers to optimise storage environments over time, lowering unit costs while retaining flexibility and performance appropriately.

Mandatory certifications

Mandatory certifications

Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure

Sole Control of the Infrastructure

ISO 9001 certification

Provided

ISO 14001 certification

Provided

ISO 27001 certification

Provided

ISO 20000-1 certification

Provided

ISO 27017 certification

Provided

Are you bidding to provide services under Lot 1b or both Lot 1a and Lot 1b?

No

Cyber Essentials

Do you have a Cyber Essentials Plus certificate?
Yes
Cyber Essentials Plus certificate Number
5dd79cac-9d43-47c5-89dc-7942d72666ee

Non-mandatory Standards and certifications

ISO 28000:2022 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Saturday 13 April 2024
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
N/a
PCI certification
Yes
Who accredited the PCI DSS certification
PCI Security Standards Council
PCI DSS accreditation date
Friday 30 January 2026
What the PCI DSS doesn’t cover
Not applicable.
Other security certifications
Yes
Any other security certifications
  • HSCN CN-SP Stage 2
  • SOC Type 1 & 2
  • ISO 27017

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at psbids@exponential-e.com. Tell them what format you need. It will help if you say what assistive technology you use.