Immutable Backup as a Service (BaaS)
Immutable backup service which can protect data in M365, Azure, On-Prem and other SaaS apps. Based on Veeam technology backup by HybrIT knowledge and experience, this managed service meets the highest levels of protection including the 3-2-1-1-0 rule
Features
- Protects data in line with the 3-2-1-1-0 rule
- Flexible pay as you go commercial model
- Data stored on Immutable secure storage platform
- Able to backup multiple data sources
- Protects on-premises physical and virtual workloads
- Protects Microsoft Azure, M365 and Entra ID
- Protects SaaS solutions including Salesforce
- Fully managed by HybrIT
- Backup data can be automatically verified
- Protects against Ransomware
Benefits
- Provides Ransomware Protection
- Provides peace of mind for data owners
- Saves your team's time as HybrIT manage the backups
- Provides Immutability for compliance
- Cloud based so no infrastructure required
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 1 4 9 2 8 8 0 0 5 2 6 8 1 5
Contact
HYBRIT SERVICES LTD
Kerry O'Halloran
Telephone: 0333 015 6701
Email: bidmanagement@hybrit.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Storage
Data replication and protection
- Data Protection Software
Archiving
- Email Archiving Software
- File and Other Archiving Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- HybrIT does not currently support AWS
- System requirements
-
- Azure backups requires a Veeam appliance in Azure
- On-prem backups require a Veeam appliance on-prem
- M365 backup requires an account with appropriate permissions
User support
- Email or online ticketing support
- Yes
- Support response times
- Service levels are aligned to business impact and categorised by priority. Priority 1 applies to total service failure, with a 15-minute response and four-hour resolution target, with optional 24x7 cover available by phone only (additional charges). Priority 2 covers service degradation, with a one-hour response and resolution within one business day. Priority 3 relates to single-user incidents, responded to within four hours and resolved within three business days. Priority 4 applies to information requests, with an eight-hour response and six-business-day resolution. Service requests, including enhancements or administrative changes, are responded to within two days and completed within ten working days.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- HybrIT provides tiered support levels aligned to service criticality and deployment model. Standard Support (Business Hours) is included with all services and provides incident management, service requests, and configuration support during UK business hours. Response and resolution targets align to defined service priorities. Enhanced Support (24x7) is available for dedicated instances as an optional service, providing 24x7 cover for Priority 1 incidents. This option is charged at a 30% uplift on the base service cost. For multi-tenant services, 24x7 support for platform-level Priority 1 incidents is included as standard. Third-Party Integration Support is available as an optional add-on, providing 24x7 support for integrations with external platforms such as carriers or UC services. This service is charged at £75 per month. Dedicated instances may also include access to a named Technical Account Manager or Cloud Support Engineer, providing service oversight, escalation management, and operational guidance. This role is not included as standard for multi-tenant services and is subject to agreement. All support services are delivered in accordance with agreed service levels and escalation procedures.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- HybrIT has an onboarding process which takes care of all tasks neccesary t get the backup service running
- Service documentation
- No
- End-of-contract data extraction
- At the end of the contract the users can place a Service Request to facilitate the data extraction. We provide reasonable effort as part of the contract but if the method/location requested requires significant effort we reserve the right to charge based on our standard day rates
- End-of-contract process
- Data extraction or data deletion is included in the contract subject to reasonable effort required.
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- We follow ITIL Capacity management processes and can scale the platform in line with demand
Analytics
- Service usage metrics
- Yes
- Metrics types
- We can provide reporting on consumed licensing and consumed storage space
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Users place a Service Request for a data export and specify where they would like it and in which format
- Data export formats
- Other
- Other data export formats
-
- Veeam backup files .VBR .VIB .VRB .VBK
- For M365 data PST ZIP MSG
- Data import formats
- Other
- Other data import formats
- Veeam backup file .VBK .VIB .VRB
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee 99.9% uptime of the backup platform
There are no refunds specified in the contract for unavailability - Approach to resilience
- Available on request
- Outage reporting
- If there is a service outage we will provide updates via e-mail and SMS as part of our Major Incident process
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- .
- Access restriction testing frequency
- Never
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We are accredited to ISO 27001 and ISO9001
- Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our Change Management process is based on ITIL best practices and the procedures are part of our ISO9001 QMS. Service components are tracked via our CMDB and security is assessed as part of every change. Processes available upon request.
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- .
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- .
- Incident management type
- Undisclosed
- Incident management approach
- .
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0.5%
- Between £500,001 and £1,000,000
- 1.0%
- Between £1,000,001 and £2,500,000
- 1.5%
- Between £2,500,001 and £5,000,000
- 2.0%
- Over £5,000,001
- 2.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Wednesday 9 April 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Tuesday 27 August 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-