FullProxy Ltd

F5 NGINX App Protect - Direct / AWS CPPO

NGINX App Protect is a modern app‑security solution that works seamlessly in DevOps environments as you deliver apps from code to customer. Built on F5’s market‑leading WAF, our software runs natively on NGINX Plus and integrates security controls into your apps.

Features

  • Advance Web Application Firewall ( WAF )
  • Web server
  • API Gateway
  • WAF Security controls
  • Kubernetes Ingress controller
  • Streaming Media
  • High availability (HA)
  • Monitoring
  • Content cache

Benefits

  • Use the same WAF that powers the F5 Networks WAF
  • Deliver static assets with unparalleled speed and efficiency:
  • Deliver modern-applications at scale, manage and secure your business-critical APIs
  • Secure and protect your applications
  • Create Kubernetes applications
  • Scalably deliver streaming media
  • Scalable and reliable HA deployments:
  • Diagnose and debug complex application architectures

Pricing

£1 to £500,000 a unit

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at g-cloud@fullproxy.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

4 5 3 7 6 0 6 5 1 2 5 1 8 1 1

Contact

FullProxy Ltd Chris Templeton / Ewan Ferguson
Telephone: 0141 291 5500
Email: g-cloud@fullproxy.com

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Other NGINX products
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
Details provided within supplied documentation
System requirements
  • Requirements dependant upon environment in which NGINX Plus is deployed.
  • See vendor web site or documentation for details
  • Minimum requirements are available at f5.com

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Response time SLAs are negotiable with the client

For full information: https://fullproxy.com/support/
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes, at an extra cost
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
N/A
Web chat accessibility testing
N/A
Onsite support
Yes, at extra cost
Support levels
Access to F5 Support differs with contract purchased. F5 Support are available 24x7x365

For full information: https://fullproxy.com/support/
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Pre-sales consultancy
Online training
User documentation
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
No user data is retained as part of the service.
End-of-contract process
Renewal notice issued 90 days prior to contract end date.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Configuration, Analysis
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Configuration of the BIG-IP VE will be unique to the application environment it supports.

Scaling

Independence of resources
The underlying resources (CPU and Memory) are under the control of the client and can be extended if required. The product is sold based on per instance therefore a client may have to purchase multiple instances if usage goes beyond initially anticipated levels.

Analytics

Service usage metrics
Yes
Metrics types
In excess of 100 merics are available within NGINX Plus
Reporting types
  • API access
  • Real-time dashboards

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
NGINX, part of F5 Networks

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
Never
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
Configuration data can be archived in a compressed multi-file archive or single file format and downloaded. The API can also be used to export the config.
Data export formats
Other
Other data export formats
  • Text
  • ZIP
Data import formats
Other
Other data import formats
  • Text
  • ZIP

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Availability of the deployed service is the responsibility of the customer
Approach to resilience
Available on request
Outage reporting
Email / SMS API alerts / Syslog

Identity and authentication

User authentication needed
Yes
User authentication
Username or password
Access restrictions in management interfaces and support channels
Role based access control
Access restriction testing frequency
At least every 6 months
Management access authentication
Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
QMS International Ltd
ISO/IEC 27001 accreditation date
30/11/2022
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Security governance policies available upon request
Information security policies and processes
Security governance policies available upon request

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
F5 Networks can provide documentation on their configuration and change management approach on request.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
F5 Networks can provide documentation on their vulnerability management approach on request.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
F5 Networks can provide documentation on their proactive monitoring approach on request.
Incident management type
Supplier-defined controls
Incident management approach
F5 Networks can provide documentation on their incident management approach on request.

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

FullProxy position can be provided upon request
Covid-19 recovery

Covid-19 recovery

FullProxy position can be provided upon request
Tackling economic inequality

Tackling economic inequality

FullProxy position can be provided upon request
Equal opportunity

Equal opportunity

FullProxy position can be provided upon request
Wellbeing

Wellbeing

FullProxy position can be provided upon request

Pricing

Price
£1 to £500,000 a unit
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Full featured, time limited trial license.
Link to free trial
https://www.nginx.com/free-trial-request/

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at g-cloud@fullproxy.com. Tell them what format you need. It will help if you say what assistive technology you use.