Aiven Ltd

Aiven for PostgreSQL

Aiven PostgreSQL is the worry-free SQL database service. Combining the best open-source SQL database engine with our extensive geographical coverage, automatic no-downtime migration between regions and plans, automatic real-time backup and high-availability features allows us to offer you the most advanced, fully-managed PostgreSQL Database-as-a-Service hosting.

Features

  • Managed Service
  • Software-as-a-Service
  • Highly-available
  • Automatic streaming backups
  • Support for both command line- and web interface
  • Point-in-Time-Recovery
  • Connection Pooling
  • Extensions, such as PostGIS and PL/v8
  • Logical replication utilizing pub/sub
  • Read replicas

Benefits

  • Managed Service
  • Eliminate operational overhead
  • Extensive SLAs
  • Up-and-running in minutes
  • Simple and seamless scaling
  • Available in AWS, GCP, Azure, Digital Ocean and Upcloud
  • Built-in redundancy and automatic failure recovery
  • Continuously verified backups and restore capability

Pricing

£0.22 an instance an hour

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrew.jones@aiven.io. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

4 2 5 8 3 3 4 6 2 4 4 6 8 8 2

Contact

Aiven Ltd Andrew Jones
Telephone: +447425370578
Email: andrew.jones@aiven.io

Service scope

Service constraints
N/A
System requirements
N/A

User support

Email or online ticketing support
Email or online ticketing
Support response times
Aiven operates 24/7/365 monitoring on the Cloud Services and Aiven's personnel will be automatically alerted to any service anomalies. Aiven's personnel will commence work on any issues in system operations requiring manual intervention without delay. Aiven provides Basic level support without separate charges for regular subscriptions (which includes all service plans) through email and chat regarding problems related to using and accessing the Aiven Cloud Services. Responses are provided on a best-effort basis during the same or next business day. Aiven also provides paid for Support which you can find details of here: https://aiven.io/support-services
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Web chat
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.1 AA or EN 301 549
Web chat accessibility testing
Our web chat is provided by a third party who is responsible for the development and testing activities.
Onsite support
No
Support levels
https://aiven.io/support-services
Account Director, CSM, and a Technical Account Manager is provided
Support available to third parties
No

Onboarding and offboarding

Getting started
The Getting Started Guide for each service type is available on our support site. Our expert Customer Support Managers are also happy to help customers to get started. The dedicated Customer Success Team is available to help with both onboarding and offboarding.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
All data can be downloaded through the service's API at any time during the contract period. Your dedicated Customer Success Manager can assist with both onboarding and offboarding.
End-of-contract process
Aiven's pricing is all-inclusive and transparent. That means no surprises at the end of the month, not even from highly variable costs like networking and storage. Aiven customers are free to scale up, or down Services, of their own free will.

Using the service

Web browser interface
Yes
Using the web interface
Launch, manage and monitor services. In addition, it is possible to control the service users and their access rights.
Web interface accessibility standard
None or don’t know
How the web interface is accessible
Aiven Web Interface is not specifically accounting for WSGA standard. All functionality available on Aiven Web Interface is also exposed via Aiven Command Line Client.
Web interface accessibility testing
Aiven has not concluded web interface testing with assistive technology users.
API
Yes
What users can and can't do using the API
All functionalities of Aiven are accessible through the API as through the web interface as well.
API automation tools
Terraform
API documentation
Yes
API documentation formats
HTML
Command line interface
Yes
Command line interface compatibility
  • Linux or Unix
  • Windows
  • MacOS
Using the command line interface
Users can deploy, manage and monitor services using the Aiven Web UI, command line interface or over Aiven API. All operations can be performed using any of the interfaces.

Users can manage databases (PostgreSQL/MySQL/Cassandra), topics (Kafka) and indexes (Elasticsearch). Users can manage service users, access credentials and access control lists. Finally, users can monitor service performance.

User access to various configuration options is defined in three distinct roles: admin, operator and developer.

Scaling

Scaling available
Yes
Scaling type
Manual
Independence of resources
Each Aiven customer is provisioned with independent virtual machines from the selected cloud provider and region. The resources are dedicated to the running service and not shared among Aiven customers or services.
Usage notifications
Yes
Usage reporting
  • Email
  • Other

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • CPU
  • Disk
  • Memory
  • Network
Reporting types
  • API access
  • Real-time dashboards

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
Explicit overwriting of storage before reallocation
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Backup and recovery

Backup and recovery
Yes
What’s backed up
  • Full snapshot, i.e basebackup
  • Streaming backup, i.e. WAL records
Backup controls
Supplier performs the backups of all data stored in the service.
Datacentre setup
Multiple datacentres with disaster recovery
Scheduling backups
Supplier controls the whole backup schedule
Backup recovery
Users contact the support team

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Aiven offers 99.95% availability SLA. Outages are compensated with free usage credits covering 30 times the outage period. The amount of free usage credits provided in the case of an outage may not exceed the amount charged from the over the three months preceding the outage. All outage periods and compensations are calculated by Aiven.
Approach to resilience
Aiven PostgreSQL's high-availability plans' clusters are spread across multiple availability zones for maximum redundancy. In addition, Aiven services detect and correct faults automatically, returning to the specified level of redundancy within minutes from a node loss or similar major fault.
Outage reporting
Aiven service status and information about possible outages is published at https://status.aiven.io/

Identity and authentication

User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
All access to Aiven management interfaces requires authentication and authorization. Access is only granted after mandatory operational and security training.
Access restriction testing frequency
At least once a year
Management access authentication
Public key authentication (including by TLS client certificate)
Devices users manage the service through
Dedicated device over multiple services or networks

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 1 month and 6 months

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Kiwa
ISO/IEC 27001 accreditation date
16/04/2021
What the ISO/IEC 27001 doesn’t cover
A.18.1.5 Regulation of cryptographic controls
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber essentials plus
No
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
SOC 2, PCI DSS, GDPR, HIPAA, CCPA
Information security policies and processes
Aiven follows all information security policies and processes required by the ISO 27001. Aiven CISO who is responsible for information security reports directly to the CEO. Aiven ensures that policies are followed by performing regular external and internal audits.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All Aiven source code is peer-reviewed and scanned with automated analysis tooling before
accepted into the version controlled source code repository . Deployed software is only built in
controlled CI environment from authenticated source code. Aiven configuration is only deployed
from version controlled repository . Deployed code and configuration is identified with a version
that contains a cryptographic hash of the original source.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Aiven continuously assesses the risks against our infrastructure and customer services. We perform continuous automated scanning for vulnerable or out-of-date software and/or invalid configuration, and ensure patches are installed as defined in our patching and vulnerability management policy. Aiven tracks upstream security information from software vendor repositories, security lists for major Aiven components as well as feeds from MITRE. Aiven has a public bug bounty program.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Aiven employs centralized logging. The central log is monitored for unexpected authorized
events. If compromises are detected, virtual machine or other resource is immediately isolated
from all networking and snapshotted for forensic purposes. Customers are notified about the
breach, and the workloads shifted to fresh and clean virtual machines.
Incident management type
Supplier-defined controls
Incident management approach
Aiven maintains an Incident Response Process with pre-defined responses to common incident
types. Incidents can be reported to Aiven via email at security@aiven.io. Reported incidents are
escalated as quickly as possible. Security breaches shall be investigated promptly . If criminal
action is suspected, the Information Security Officer shall contact the appropriate law
enforcement authorities immediately . Unless prohibited from doing so, the Information Security
Officer shall inform the customer on any detected or suspected unauthorized access on customer data.

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Third-party
Third-party virtualisation provider
Amazon Web Services, Microsoft, Google Cloud, Digital Ocean, Packet.net, Upcloud
How shared infrastructure is kept separate
Aiven services are implemented in virtual machines from the cloud providers. Each service instance is implemented in an independent virtual machine, and does not share resources with other customers or services.

Energy efficiency

Energy-efficient datacentres
Yes
Description of energy efficient datacentres
Energy efficiency and environmental sustainability is part of Aiven's supplier selection criteria.

In particular, Aiven utilizes Amazon Web Services, Google Cloud Platform and Microsoft Azure for the resources implementing the offered services. The three public cloud providers have ambitious commitments to both energy efficiency as well as transition to 100% renewable energy.

Social Value

Fighting climate change

Fighting climate change

Open source and cloud technologies are heading in an exciting direction. As more momentum gathers behind open source, more resources will be dedicated to important projects such as those overseen by the Open Source Security Foundation. There will also be greater capacity to leverage the advantages of open-source software to tackle the greatest challenges facing the world today, from pandemics to climate change.
Covid-19 recovery

Covid-19 recovery

N/A
Tackling economic inequality

Tackling economic inequality

N/A
Equal opportunity

Equal opportunity

Aiven is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, national origin, age, citizenship, disability, veteran status, gender identification, sexual orientation, genetic information or any other characteristic protected by law.
Wellbeing

Wellbeing

Aiven believes open standards and an open world boosts digital freedom, innovation, well-being, and mitigates conflicts. Open-source tech supports the growth of an open digital ecosystem.

Pricing

Price
£0.22 an instance an hour
Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Aiven offers trial credits of $500 that can be used for a 30-day evaluation on any, or all, of the Aiven Services. If additional credits/time is necessary, please contact Aiven for assistance.
Link to free trial
https://console.aiven.io/signup

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrew.jones@aiven.io. Tell them what format you need. It will help if you say what assistive technology you use.