Skip to main content

Help us improve the Digital Marketplace - send your feedback

CLOUDWICK UK LIMITED

Amorphic Data Platform

Amorphic Data Platform is a secure, cloud-native data and AI platform on AWS that enables public-sector organisations to ingest, govern, process and analyse data at scale. Delivered as a managed service, it supports analytics, reporting and AI use cases while meeting UK public-sector security and compliance requirements.

Features

  • Enterprise data platforms and lakehouse implementations
  • Legacy data warehouse modernisation
  • Regulatory and operational reporting
  • AI-enabled analytics and insights
  • Document and unstructured data processing
  • Cross-department data sharing and collaboration

Benefits

  • Faster time to value through reusable, pre-configured data services
  • Reduced operational overhead through automation and managed services
  • Improved data governance, security and compliance
  • Scalable foundation for analytics, AI and future innovation
  • Alignment with UK public-sector cloud and security standards

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at harshdeep@cloudwick.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 6 2 4 0 7 4 4 8 1 7 0 1 1 1

Contact

CLOUDWICK UK LIMITED Harshdeep Singh
Telephone: 07450263176
Email: harshdeep@cloudwick.com

About your service

Service categories

Applications

Engineering

  • Collaborative product data management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service is limited to deployment on top of the AWS Public Cloud Services.
System requirements
Customer AWS Account needed for each Amorphic deployment

User support

Email or online ticketing support
Yes
Support response times
This is dependant of the service level taken however target response time for production applications are as below:
Severity 1 (P1)* - 1 hour (24/7/365)
Severity 2 (P2) - 4 hours (09:00-17:30 Mon - Fri)
Severity 3 (P2) - 12 hours (09:00-17:30 Mon - Fri)
Severity 4 (P2) - 24 hours (09:00-17:30 Mon - Fri)
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
No
Web chat support
No
Onsite support
No
Support levels
Business Support
- this provides basic business hours (09:00-17:00) support Monday to Friday for application infrastructure
- it includes basic quarterly service reporting and up to 3 Technical service contacts

Enterprise Support:
- this provides support during business hours (09:00-17:00) support Monday to Friday for application infrastructure
- this provides Priority 1 support (24/7/365) for application infrastructure
- includes support for custom specification for networking
- it includes quarterly service reporting and service meetings and up to 6 Technical service contacts.

Custom Support
Enables customisation of service and support
- custom support hours options for P2-P4 incidents support for application infrastructure
- custom support hours for Priority 1 incidents for application infrastructure
- support for custom specification for networking
- it includes custom service reporting and service meetings and up to X Technical service contacts.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
As a part of onboarding, Cloudwick can provide formal or informal training, which enables the customers to:
• Develop and up-skill their internal workforce, or;
• Help them in getting up-to-speed with the new tools and systems through documentation, web based training sessions and hands-on workshops.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
User can download their data from the UI, for Platform offboarding all data is backed up to a customer created S3 bucket and the application is removed from the customer AWS account.
End-of-contract process
Termination Process:
Cloudwick would expect a bi-lateral, 1 to 3 month termination period, which means that either party can choose to terminate the contract upon completion of the initial contract term. The customer or Cloudwick would comply with the governance arrangements set out in the G-Cloud Framework Agreement and Call-off Contract.

Customers would then work with the Cloudwick support team to complete the end to end service offboarding process.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
The API enables user to access the Amorphic services and resource programmatically. This facilitates using external tool, systems and to support further automation of processes.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Buyers can customise;
- the service level,
- Infrastructure for networking, access/authentication, UI branding

Users can customise:
- Their view in the UI, with widgets and dashboards

Scaling

Independence of resources
The Application is dedicated to the customer and deployed in the customers account.

Analytics

Service usage metrics
Yes
Metrics types
Our service metrics cover:
- service availability and uptime
- storage usage
- and utilisation of compute, connections and storage
- number of users
Reporting types
Regular reports
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export their data:
Individually using the platform
Using the API
Integrating Amorphic with 3rd Party Tools
Data export formats
  • CSV
  • ODF
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
Iceberg

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
The target availability for the Amorphic Application Service is 99.95% per calendar month (based on minutes of availability/total minutes per month) (“Service Level”).

The Service is deemed ‘unavailable’ from the point at which the amorphic support team is notified of the incident by [Customer] using the incident management process.

Cloudwick will have no liability for any failure to meet the Service Level to the extent arising from: (a) use of the Amorphic Service by Customer other than as authorized under the Agreement as per the Sales Order Form, (b) Customer data; (c) Customer or user equipment: (d) third party acts, or services and/or systems not provided by Amorphic; (e) general Internet problems, or other factors outside of Cloudwick’s reasonable control: (f) evaluation use of the Amorphic Service; or (g) Amorphic’s preview features (e.g. beta functionality not intended for production use). Cloudwick will have no obligation to provide support for [Customer] third party provided software or services other than those approved by Cloudwick in the documentation as described in the End User License Agreement, or for custom scripts or code not native to the Amorphic Service.
Approach to resilience
The application is deployed on AWS in the customers account in their chosen region, when the application is deployed back up / snapshots are configured for the relevant components such as Dynamo DB and Redshift. A full Disaster Recovery process is available upon request and annual DR testing is included as part of the service.

Standard AWS managed services are used for the hosted application.
Outage reporting
The customer is responsible for monitoring the availability of the application in their AWS account.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
As the application is deployed into a customers dedicated AWS account. Typically we can accommodate customers specific requirements.
Access restrictions in management interfaces and support channels
As Amorphic is deployed into the customers AWS account, access to customer management interfaces is controlled by the customer typically via SSO, and access to support channels managed by Cloudwick is restricted by email domain.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
SOC 2, Type 2
HIPAA
Cyber Essentials
Information security policies and processes
These are available upon request.

We are Certified against:
SOC 2, Type 2
HIPAA
Cyber Essentials
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
The services change management processes are aligned to each customers processes as the installations are dedicated and deployed in to a customers AWS account.

There are standard processes in please covering:
Upgrades
Patching
Maintenance
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our application code is scanned and actively monitored using a security scanning and vulnerability tool, this provides results of static code scanning and live code running in our product development environments.

We monitor for security vulnerabilities for example using the NCSC early warning system, our vendors alerts, and other methods.

Once we identify a critical / high vulnerability a patch is developed and deployed to dedicated customer environments within 2 to 7 days respectively.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
The responsibility for Protective Monitoring lays with the customer as the Amorphic Application is deployed directly into the customers account.
Incident management type
Supplier-defined controls
Incident management approach
We have pre-defined processes for common events.

Users can report incidents via email or via our service management portal.

We have standard Incident, Security and RCA templates/reports.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
3%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
7.5%
Over £5,000,001
9%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
2bc5f5e2-4dd2-4a13-b29d-eb48287e9d74
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
  • Data Security and Protection Tool Kit version 7
  • SOC2 Type2
  • HIPAA

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Volunteering opportunities for staff

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at harshdeep@cloudwick.com. Tell them what format you need. It will help if you say what assistive technology you use.