Amorphic Data Platform
Amorphic Data Platform is a secure, cloud-native data and AI platform on AWS that enables public-sector organisations to ingest, govern, process and analyse data at scale. Delivered as a managed service, it supports analytics, reporting and AI use cases while meeting UK public-sector security and compliance requirements.
Features
- Enterprise data platforms and lakehouse implementations
- Legacy data warehouse modernisation
- Regulatory and operational reporting
- AI-enabled analytics and insights
- Document and unstructured data processing
- Cross-department data sharing and collaboration
Benefits
- Faster time to value through reusable, pre-configured data services
- Reduced operational overhead through automation and managed services
- Improved data governance, security and compliance
- Scalable foundation for analytics, AI and future innovation
- Alignment with UK public-sector cloud and security standards
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 6 2 4 0 7 4 4 8 1 7 0 1 1 1
Contact
CLOUDWICK UK LIMITED
Harshdeep Singh
Telephone: 07450263176
Email: harshdeep@cloudwick.com
About your service
- Service categories
-
Applications
Engineering
- Collaborative product data management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service is limited to deployment on top of the AWS Public Cloud Services.
- System requirements
- Customer AWS Account needed for each Amorphic deployment
User support
- Email or online ticketing support
- Yes
- Support response times
-
This is dependant of the service level taken however target response time for production applications are as below:
Severity 1 (P1)* - 1 hour (24/7/365)
Severity 2 (P2) - 4 hours (09:00-17:30 Mon - Fri)
Severity 3 (P2) - 12 hours (09:00-17:30 Mon - Fri)
Severity 4 (P2) - 24 hours (09:00-17:30 Mon - Fri) - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Business Support
- this provides basic business hours (09:00-17:00) support Monday to Friday for application infrastructure
- it includes basic quarterly service reporting and up to 3 Technical service contacts
Enterprise Support:
- this provides support during business hours (09:00-17:00) support Monday to Friday for application infrastructure
- this provides Priority 1 support (24/7/365) for application infrastructure
- includes support for custom specification for networking
- it includes quarterly service reporting and service meetings and up to 6 Technical service contacts.
Custom Support
Enables customisation of service and support
- custom support hours options for P2-P4 incidents support for application infrastructure
- custom support hours for Priority 1 incidents for application infrastructure
- support for custom specification for networking
- it includes custom service reporting and service meetings and up to X Technical service contacts. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
As a part of onboarding, Cloudwick can provide formal or informal training, which enables the customers to:
• Develop and up-skill their internal workforce, or;
• Help them in getting up-to-speed with the new tools and systems through documentation, web based training sessions and hands-on workshops. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- User can download their data from the UI, for Platform offboarding all data is backed up to a customer created S3 bucket and the application is removed from the customer AWS account.
- End-of-contract process
-
Termination Process:
Cloudwick would expect a bi-lateral, 1 to 3 month termination period, which means that either party can choose to terminate the contract upon completion of the initial contract term. The customer or Cloudwick would comply with the governance arrangements set out in the G-Cloud Framework Agreement and Call-off Contract.
Customers would then work with the Cloudwick support team to complete the end to end service offboarding process. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- The API enables user to access the Amorphic services and resource programmatically. This facilitates using external tool, systems and to support further automation of processes.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise;
- the service level,
- Infrastructure for networking, access/authentication, UI branding
Users can customise:
- Their view in the UI, with widgets and dashboards
Scaling
- Independence of resources
- The Application is dedicated to the customer and deployed in the customers account.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Our service metrics cover:
- service availability and uptime
- storage usage
- and utilisation of compute, connections and storage
- number of users - Reporting types
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Users can export their data:
Individually using the platform
Using the API
Integrating Amorphic with 3rd Party Tools - Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Iceberg
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
The target availability for the Amorphic Application Service is 99.95% per calendar month (based on minutes of availability/total minutes per month) (“Service Level”).
The Service is deemed ‘unavailable’ from the point at which the amorphic support team is notified of the incident by [Customer] using the incident management process.
Cloudwick will have no liability for any failure to meet the Service Level to the extent arising from: (a) use of the Amorphic Service by Customer other than as authorized under the Agreement as per the Sales Order Form, (b) Customer data; (c) Customer or user equipment: (d) third party acts, or services and/or systems not provided by Amorphic; (e) general Internet problems, or other factors outside of Cloudwick’s reasonable control: (f) evaluation use of the Amorphic Service; or (g) Amorphic’s preview features (e.g. beta functionality not intended for production use). Cloudwick will have no obligation to provide support for [Customer] third party provided software or services other than those approved by Cloudwick in the documentation as described in the End User License Agreement, or for custom scripts or code not native to the Amorphic Service. - Approach to resilience
-
The application is deployed on AWS in the customers account in their chosen region, when the application is deployed back up / snapshots are configured for the relevant components such as Dynamo DB and Redshift. A full Disaster Recovery process is available upon request and annual DR testing is included as part of the service.
Standard AWS managed services are used for the hosted application. - Outage reporting
- The customer is responsible for monitoring the availability of the application in their AWS account.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- As the application is deployed into a customers dedicated AWS account. Typically we can accommodate customers specific requirements.
- Access restrictions in management interfaces and support channels
- As Amorphic is deployed into the customers AWS account, access to customer management interfaces is controlled by the customer typically via SSO, and access to support channels managed by Cloudwick is restricted by email domain.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
SOC 2, Type 2
HIPAA
Cyber Essentials - Information security policies and processes
-
These are available upon request.
We are Certified against:
SOC 2, Type 2
HIPAA
Cyber Essentials - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
The services change management processes are aligned to each customers processes as the installations are dedicated and deployed in to a customers AWS account.
There are standard processes in please covering:
Upgrades
Patching
Maintenance - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Our application code is scanned and actively monitored using a security scanning and vulnerability tool, this provides results of static code scanning and live code running in our product development environments.
We monitor for security vulnerabilities for example using the NCSC early warning system, our vendors alerts, and other methods.
Once we identify a critical / high vulnerability a patch is developed and deployed to dedicated customer environments within 2 to 7 days respectively. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- The responsibility for Protective Monitoring lays with the customer as the Amorphic Application is deployed directly into the customers account.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
We have pre-defined processes for common events.
Users can report incidents via email or via our service management portal.
We have standard Incident, Security and RCA templates/reports. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7.5%
- Over £5,000,001
- 9%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2bc5f5e2-4dd2-4a13-b29d-eb48287e9d74
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- Data Security and Protection Tool Kit version 7
- SOC2 Type2
- HIPAA
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Volunteering opportunities for staff
-