System and Service Management
We deliver cloud-native system and service management software with API-driven IT operations, configuration state control and service workflows across AWS, Azure and GCP. We implement telemetry ingestion, event correlation, CMDB reconciliation, change automation, runbook orchestration and role-based access using an accelerator-led delivery model with governed updates and compliance reporting.
Features
- Cloud-hosted operations tooling managed by the supplier
- Automated configuration and policy management across environments
- Centralised IT service workflows and request handling
- Role-based access and administrative controls
- Event, log, and performance monitoring capabilities
- Standard APIs for system and tool integrations
- Automated provisioning and change execution
- Configuration drift detection and remediation
- Scalable operations aligned to workload demand
- Supplier-managed updates and platform maintenance
Benefits
- Improves operational stability through automation
- Improves operational stability through automation
- Accelerates incident and request resolution
- Improves service visibility and control
- Supports consistent IT service delivery
- Reduces operational overhead for IT teams
- Improves compliance through standardised processes
- Supports scalable operations without infrastructure management
- Enables faster response to operational changes
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 6 2 9 5 0 1 2 1 9 4 7 1 0 7
Contact
E-ZEST SOLUTIONS LIMITED
Rahul Wane
Telephone: +44 7405 005374
Email: rahul.wane@e-zest.com
About your service
- Service categories
-
Systems Infrastructure Software
System and service management
- IT operations management
- IT service management
IT automation and configuration management
- Workload management
- Datacentre system and application control
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service can extend common cloud software services, including identity and access management, monitoring and logging tools, security platforms, and integration middleware. In these scenarios, it adds management, configuration, or control capabilities. The service can also be used independently as a standalone cloud software service without reliance on other software.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Our service does not include the supply, management, or support of physical hardware. It operates on cloud-based environments and requires buyers to have suitable network connectivity and compatible cloud platforms. Planned maintenance is communicated in advance and scheduled to minimise service disruption.
- System requirements
-
- AWS Licenses as applicable
- Microsoft Licenses as applicable
- GCP Licenses as applicable
User support
- Email or online ticketing support
- Yes
- Support response times
- We provide 24×7 support when required by the client. For 24×7 engagements, we respond to support queries within one hour, including weekends and public holidays. For standard business-hours support, we respond within one business hour, with weekend coverage activated on request.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We tested the web chat using screen readers (NVDA and JAWS), keyboard-only navigation, screen magnification, and high-contrast modes. Testing covered chat access, message entry, and error handling, with improvements made based on user feedback.
- Onsite support
- Yes
- Support levels
- We provide three support levels. Standard support includes email, ticketing, and web chat during agreed service hours at no additional cost. Extended support provides 24×7 coverage with defined response and resolution targets and carries an additional monthly fee based on service scope and user volume. Premium support adds priority handling, proactive monitoring, and faster response targets at a higher monthly fee. For extended and premium support, we assign a named technical account manager or cloud support engineer who acts as the primary point of contact and coordinates technical escalations and service reviews.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We help users start using the service through defined onboarding that includes live demonstrations, access to user documentation, and online training sessions. We provide walkthrough demos to explain service scope and workflows, share role-based user guides and operating documentation, and deliver online training tailored to users. Where required, we also support assisted onboarding during the initial setup phase.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- At contract end, users can request structured data extraction in standard, non-proprietary formats. We support export of application data, configuration data, and audit logs through agreed secure transfer methods. Data extraction follows a defined off-boarding process, including validation of exported datasets and confirmation of successful handover to the buyer or their nominated supplier. Data retention and deletion align with contractual terms after completion of extraction.
- End-of-contract process
-
At the end of the contract, the service enters a controlled exit phase aligned to the agreed notice period. We work with the buyer to confirm the contract closure date, complete outstanding service activities, and agree a structured exit plan. This includes secure handover of service artefacts, configurations, documentation, and buyer-owned data in an agreed format. Access to systems is withdrawn in a controlled manner, and service accounts are decommissioned in line with security and data protection requirements. We support transition to another supplier or to an in-house team through knowledge transfer sessions and handover support.
The contract price includes standard contract close-out activities, secure return or deletion of buyer data, final reporting, and reasonable knowledge transfer needed to support service continuity. Additional costs apply only if the buyer requests extended transition support beyond the agreed exit period, bespoke data transformation or migration activities, extended system access after contract end, or continued support services under a separate agreement. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Other
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile version provides the same core functionality as the desktop version, including access to features, data, and support. The interface adapts to smaller screens with simplified navigation, touch-optimised controls, and adjusted layouts.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service interface is browser-based and provides access to configuration, administration, reporting, and user functions. It uses a responsive layout, role-based access, clear navigation, and consistent interaction patterns. Users can manage settings, view data, raise support requests, and monitor service usage through the interface.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We tested the interface using screen readers (NVDA and JAWS), keyboard-only navigation, screen magnification, and high-contrast modes, and fixed issues identified during testing.
- API
- Yes
- What users can and can't do using the API
- Users can use the API to configure core settings, manage users and roles, and integrate with other systems. They can update configurations, manage access, and exchange data through the API. Actions that affect contracts, compliance, or core system controls are restricted. Rate limits apply, and some advanced settings are read-only.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can customise workflows, user roles, access permissions, dashboards, reports, notifications, and integrations. Customisation uses configuration options available through the service interface and supported APIs, without code changes. Buyers initiate customisation through a defined request and approval process that includes impact assessment, validation, and controlled implementation. Only authorised buyer administrators and designated technical users can approve and apply customisations, in line with role-based access controls and agreed governance procedures.
Scaling
- Independence of resources
- We isolate each customer’s workload so activity from one user does not affect another. The service provisions dedicated logical environments per customer with defined resource quotas, priority rules, and tenant boundaries that prevent contention. DevOps pipelines deploy infrastructure through automated, environment-specific configurations, enforcing consistent isolation and capacity limits. Continuous monitoring, usage alerts, and automated scaling actions run through DevOps tooling to address demand changes before thresholds are reached. Where shared components exist, we apply strict tenancy controls, throttling, fault isolation, and controlled release management so performance, availability, and security remain independent for each customer.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide standard service usage and operational metrics aligned to managed software services. Metrics include service availability, uptime, incident and request volumes, response and resolution times, usage trends, capacity consumption, and basic performance indicators. Where applicable, we also provide security and compliance-related operational metrics and service-level adherence data agreed with the buyer.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
Data importing and exporting
- Data export approach
- Users request data exports through the service interface or by raising a support request. Authorised administrators approve the request, and data is provided in standard formats such as CSV or JSON.
- Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We guarantee 99.2% monthly availability, measured across core production components. Planned maintenance agreed in advance is excluded. Availability SLAs sit in the call-off contract. If availability falls below this level, buyers receive service credits applied to the next invoice, calculated against the monthly charge.
- Approach to resilience
- We do not operate supplier-owned data centres. We deliver services on hyperscale cloud platforms including Amazon Web Services, Microsoft Azure, and Google Cloud Platform. These platforms provide geographically distributed data centres, redundancy across power, network, and infrastructure, multi-availability-zone deployment, automated failover, managed backups, and platform monitoring. We design services to run across multiple availability zones with replicated managed storage and cloud-native backup and restore.
- Outage reporting
- We do not provide a supplier-owned public status dashboard. Buyers use the cloud provider’s public service health dashboards for platform incidents and maintenance. At service level, we report confirmed outages or degradation by email to agreed contacts. Automated alerts and API-based notifications use cloud-native monitoring tools and are agreed at call-off stage.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- We restrict access to management interfaces and support channels through role-based access control aligned to job responsibilities. Only authorized personnel receive access to administrative consoles, service configuration tools, and support systems. We enforce authentication using multi-factor authentication where applicable. Access requests follow a formal approval workflow and we review them regularly to remove inactive or unnecessary permissions. We log and monitor all privileged access activities, and we route support requests through controlled ticketing systems with authenticated user verification before any action.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
We operate a formal information security management framework aligned to ISO/IEC 27001, with privacy controls aligned to ISO/IEC 27701. Quality and process governance follow ISO 9001 and CMMI Level 5 practices. We support Cyber Essentials Plus and PCI-DSS Level 3 aligned services where required. HIPAA compliance applies to services that handle regulated healthcare data and is delivered where applicable.
Information security governance sits with senior management, with defined accountability for policy ownership, risk management, and incident oversight. Policies cover access control, data protection, asset management, incident response, supplier security, and business continuity. We review policies on a planned cycle and after material changes.
We apply controls through mandatory staff training, role-based access, documented operating procedures, internal audits, and periodic risk assessments. We log and manage security incidents through formal reporting and escalation processes with defined remediation actions. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We manage configuration and change through a controlled lifecycle process integrated with service and security management. We record all service components in a central configuration register, assign unique identifiers, and track versions, ownership, dependencies, and status from build through retirement. We raise all changes through a formal change workflow that includes impact analysis, security risk assessment, approval, implementation, testing, and rollback planning. Security teams review each change for data protection, access control, and vulnerability impact before approval, and we log outcomes for audit and traceability.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We assess threats using automated vulnerability scans, configuration reviews, and risk-based analysis based on service exposure and data sensitivity. We deploy critical security patches as soon as practicable and schedule non-critical patches through planned maintenance windows. We obtain threat information from cloud provider advisories, vendor security bulletins, NCSC and CERT guidance, CVE databases, and security research feeds.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We monitor services using centralised logging, automated alerts, and security monitoring tools to identify suspicious activity and indicators of compromise. We investigate alerts through defined incident response procedures, contain affected components, and apply remediation actions based on severity. We respond to security incidents immediately on detection, with priority incidents handled on a 24x7 basis where required by the buyer.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate documented incident management processes with predefined runbooks for common events such as service outages, security alerts, and access issues. Users report incidents through a service desk by ticket or email, with escalation based on impact and urgency. We provide incident reports to users that describe the issue, actions taken, resolution status, and lessons learned, with timing aligned to incident severity and contractual requirements.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1.5%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7.5%
- Over £5,000,001
- 9%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- TÜV NORD
- ISO/IEC 27001 accreditation date
- Monday 20 October 2014
- What the ISO/IEC 27001 doesn’t cover
-
Outsourced development is not covered.
Control No. - A.8.30 (ISO 27001:2022) - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- TÜV NORD
- ISO 9001 accreditation date
- Tuesday 4 April 2017
- What the ISO 9001 doesn’t cover
- Clause 8.5.1 f for validation and periodic re-evaluation of processes is not applicable.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- QRC Assurance And Solutions Pvt. Ltd.
- PCI DSS accreditation date
- Monday 23 April 2018
- What the PCI DSS doesn’t cover
-
Requirement 3: Protect Stored Account Data
Requirement 4: Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks
- are not applicable as we do not store/process any card holder data . - Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E38474a0-4f64-4e92-b784-1db63a5f9024
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Ccaa22ea-a6da-4110-8d15-7df8d9a92059
- Other security certifications
- Yes
- Any other security certifications
- ISO 27701:2019
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-