Skip to main content

Help us improve the Digital Marketplace - send your feedback

STUDIO 24 LIMITED

WordPress website cloud hosting, support and maintenance

Studio 24 is an award-winning, accessibility-focussed agency that manages enterprise WordPress solutions for clients such as UK Parliament, HS2, and HMICFRS.

We offer managed hosting with comprehensive support and maintenance. We customise WordPress to deliver unique business and user requirements ensuring accessibility, security and data privacy compliance.

Features

  • Fully managed cloud hosting for WordPress
  • Comprehensive support, advice and training, including 24/7 support options
  • Proactive maintenance, CMS updates, and monitoring
  • CDN for performance and security, DDoS protection, and bot mitigation
  • Sustainable web design and green hosting
  • WordPress installation and configuration
  • Headless and multisite website solutions
  • Multilingual solutions, including support for Welsh-language websites
  • Accessibility, security and data privacy compliance
  • Solutions that follow GOV.UK Design Principles and Service Standards

Benefits

  • 15 years of WordPress expertise with small to large websites
  • Experience of managing large web estates with multiple websites
  • Strategic thinking to meet your business and user needs
  • Experience of working in a complex stakeholder environment
  • Supports your team to efficiently manage your website
  • Fast, secure, and reliable website
  • Experience with reliable and secure WordPress plugins
  • Customised WordPress admin to help editors manage content
  • Truly accessible solutions, WCAG 2.2 AA-level compliant
  • Open source technology with no license fees

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@studio24.net. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 0 7 9 7 1 7 8 4 5 8 6 2 3 9

Contact

STUDIO 24 LIMITED Emma Lane
Telephone: 01223 328017
Email: hello@studio24.net

About your service

Service categories

Applications

Content workflow and management

Content services

  • Enterprise Content Management Applications

Persuasive content management

  • Website Software
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
WordPress CMS
Cloud deployment model
Public cloud
Service constraints
Support, maintenance and continuous improvement is for WordPress CMS websites only
System requirements
Modern website browser

User support

Email or online ticketing support
Yes
Support response times
We have the following response SLAs for our support service: Critical 1 hour, High 2 hours, Medium 1 working day, Low 2 working days.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Our technical support & maintenance service covers software upgrades and security patches, plugin upgrades and security patches, uptime monitoring via Pingdom, hosting support and guaranteed response times. We also undertake regular maintenance, ensuring your website software and operating system software is kept up-to-date. We offer as standard in-office hours support, Monday to Friday 8am to 6pm, for an annual or monthly fee. An out-of-hours 24/7 support service is also available and has a fixed additional monthly fee and a usage fee per incident. All clients have an account manager who oversees your account and can address any concerns you may have. We supply monthly reports summarising support issues responded to, out-of-hours issues, website uptime and performance, and any ongoing problems that are being investigated. For any critical incidents we create a critical incident report which covers the root cause, details of the issue, and preventative action we have taken to minimise the risk of the issue recurring in the future.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
At the start of the service we will arrange an onboarding call to discuss how we work and agree ‘ways of working’.

This will cover roles and responsibilities, communication plan, frequency of status meetings, discussion of risks and mitigations, and importantly ensure we have an agreed understanding of the scope of work for the service.

We provide training on WordPress for your team (in person or online), and supply supporting documentation where required. We also provide instructions on how to use and access our support system (Zendesk), so clients can report and access any issues that need addressing.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
We will supply a copy of the website codebase, data, and uploaded assets. All files are sent securely using encrypted email via Proton Mail (Swiss hosted secure email service). We can supply data and content multiple times.
End-of-contract process
We have an open and supportive approach with our clients and support them when a contract ends with migrating to a new supplier. At the end of a service contract we will advise clients on the offboarding process and what work is required to migrate to a new supplier.

We: Backup and archive website files; Send copy of website files to client securely; Archive git repo; Archive services; Client offboarding survey.

Where possible, we can migrate the Git code repository to the new supplier. This contains the full audit history of changes to your website code.

We also ensure a handover meeting takes place so we can transfer as much knowledge as possible. Any documentation is also shared. We are happy to liaise with the new supplier to ensure this process is smooth.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The WordPress CMS control panel works on mobile, though some features are easier to use on larger screens. There is an optional mobile app you can use to manage your website on mobile.

All WordPress websites are designed to be mobile-friendly and work just as well on smaller mobile screens as on larger desktop screens. We design websites to be mobile-first, adjusting content/layouts/navigations where required.
Service interface
Yes
User support accessibility
WCAG 2.2 AAA
Description of service interface
Via a web browser, or the optional mobile app, WordPress admins can access the CMS to add, amend or delete content for their website.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
WordPress continually improves the accessibility of the CMS and WordPress themes. For more details see https://make.wordpress.org/accessibility/handbook/get-involved/audits-and-testing/

We build robust, accessible websites using progressive enhancement, as recommended by the GOVUK Service Manual.

We have created our own HTML/CSS starter kit Amplify to help embed best practices in our work. It’s accessible, has been tested on the W3C redesign project, and is open source (sharing our learnings with the community).
API
Yes
What users can and can't do using the API
The primary service interface for modern WordPress is the REST API, which allows applications to interact with WordPress sites. The WordPress API allows full access to managing content, users and media. More details are available at https://developer.wordpress.org/rest-api/

We have over 25 years experience integrating with external web services and building APIs to enhance existing, or introduce new functionality. We can integrate WordPress plugins with external APIs or build custom web applications to integrate with APIs where the requirements are more complex.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
All of our work centres around business and user needs. Based on your requirements we can customise applications or websites in a number of ways including design, content management, workflows and editing processes, plugins, front and backend functionality, third party integrations, hosting, security and accessibility.

Scaling

Independence of resources
Our hosting service is isolated to individual clients so you do not share resources with other clients. You will be supplied with your own cloud server and associated services (e.g. database service, Elastic Cloud search service, etc). We do not offer shared hosting services.

Analytics

Service usage metrics
Yes
Metrics types
We provide a number of metrics to our clients and can customise these according to client needs.

We recommend Matomo for privacy-aware analytics or Google Analytics 4.

At a minimum all clients are provided with web analytics via Matomo or Google. This includes website visitors, page views. We can set up custom events and reporting as required.

We also report on bandwidth usage (network traffic) and storage used.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
You can export WordPress content as XML format from the WordPress admin area / Tools. For more info see https://learn.wordpress.org/tutorial/tools-import-and-export/

We can supply a full export of the WordPress database in SQL or CSV format.
Data export formats
  • CSV
  • Other
Other data export formats
  • XML
  • Database export (SQL, CSV)
Data import formats
  • CSV
  • Other
Other data import formats
  • XML
  • Database export (SQL, CSV)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We can offer 99.9% or 99.99% SLA for your website. 99.99% SLA requires redundant hosting in multiple data centres, to ensure we have a disaster recovery environment we can switch over to quickly.

We offer a guaranteed uptime SLA for your website, the maximum total credit for a monthly billing period shall not exceed 100% of the monthly service fee for the directly affected services.

If we fail to meet the guaranteed uptime SLA for your website we will pay a 5% credit of the monthly fee for that service and a further 5% for each additional 30 minutes the server is not available.

Scheduled maintenance is excluded from this SLA and covers any maintenance explicitly agreed with the customer. Downtime is recorded from the point at which a critical issue is raised or the monitoring system detects the website is down for more than 5 consecutive minutes.
Approach to resilience
Our hosting service is designed to be resilient and capable of handing high levels of traffic. All services are isolated and not shared with other clients. We use CDN services to efficiently serve static content, cache web pages and mitigate against DDoS attacks. We continuously monitor services so we can take action if there are any issues.

Our High Availability hosting service also includes redundancy and auto scaling. We set up high availability hosting in 2 geographically separate data centres. We set up auto scaling which can scale services in response to traffic and automatically scales down once traffic has reduced.
Outage reporting
Our support team will reach out to the client's emergency contacts to notify them of any site downtime by email and telephone. A support ticket will be created in our online support portal (Zendesk) to ensure the client is kept up to date.

We will also share an incident report with the client following resolution.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to our support system (Zendesk) is restricted by username and password. Studio 24 staff must also use two-factor authentication.

Access to hosting platforms by Studio 24 staff is restricted by username, password and two-factor authentication.

Access to cloud hosting services is locked down by secure VPN and SSH keys.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We take security seriously at Studio 24 and this is led at a board level by Managing Director Simon Jones. We maintain public documentation detailing our approach to security at https://github.com/studio24/security-principles/ which is based on National Cyber Security Centre (NCSC) cloud security principles. We regularly run staff training and review our standards in response to published guidance and current industry best practice.
Information security policies and processes
We have a published data breach policy at https://github.com/studio24/security-principles/blob/main/data-breaches.md

If we have evidence of a data breach this must be reported to the Managing Director, or another Senior Director if he is on leave, who will assist in reviewing information and client liason. We will report any incidents to clients immediately and within the same working day.

Security and Data Protection training is undertaken on an annual basis with the entire team.

The board reviews information security on an annual basis.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We use open source tools Ansible and Terraform to manage and track changes to our hosting services. We store configuration as code, which is tracked in a git repository. We can share access to this with clients, if required.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
For WordPress websites we use GitHub Dependabot to track security vulnerabilities in PHP packages. We also use Patchstack to monitor security vulnerabilities in WordPress core and plugins. This service alerts on issues and provides virtual patching to block access to vulnerable URLs.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We regularly review website traffic via CDN monitoring and web access logs. Our CDN service includes DDoS protection and bot mitigation. Where issues are identified we raise a support ticket and investigate in more depth. We may work with other senior staff and liaise with our hosting and CDN suppliers to understand root cause and plan our mitigation.

If we find a potential compromise we treat this as a critical issue and respond within 1 hour.
Incident management type
Supplier-defined controls
Incident management approach
We have a robust incident management process. Incidents are logged in our support system (Zendesk) and can be created by automated alerts from our monitoring system or by client-submitted support requests. Clients can send urgent support tickets via email. Clients with out-of-hours support can also call a dedicated support number which automatically creates a critical support ticket and pages support staff to respond.

After any critical support incident we create an incident report within 5 working days, which details the incident, the root cause, and any preventative action we will take to reduce the risk of reoccurance.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Ddcbfcd8-ffc6-4ed7-a788-ac27e7deabe5
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
7236b381-e563-41ee-a078-109101c5c6e7
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@studio24.net. Tell them what format you need. It will help if you say what assistive technology you use.