Skip to main content

Help us improve the Digital Marketplace - send your feedback

BLANKBOX TECHNOLOGIES LTD

BastionHub

BastionHub is a fully audited and high security Privileged Access Management solution. It provides remote Just In Time access to sensitive systems or networks. It allows system owners to grant temporary fully audited access to environments with the ability to revoke access in an instance

Features

  • Fully managed service
  • Fully audited
  • Live Stream of users' activity
  • Secure scalable Infrastructure
  • Integrate with existing business applications
  • Linux, Windows and OSX environments
  • Secure Supplier Access

Benefits

  • Fully Monitored Access Control
  • Grant temporary Just In Time access to Privileged users
  • Manage supplier or contractor access to internal systems
  • Accessible via any browser
  • Remote Access
  • No need to provide contractors / suppliers with IT kit
  • Compliant with legal requirements

Pricing

£0.49 a device an hour

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@blankbox.tech. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

5 1 8 4 9 4 3 6 6 8 7 2 1 3 0

Contact

BLANKBOX TECHNOLOGIES LTD Jacques de la Porte
Telephone: +449
Email: sales@blankbox.tech

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
N/A
System requirements
  • Reliable internet connection (5Mbps minimum)
  • HTML5 enabled browser

User support

Email or online ticketing support
Email or online ticketing
Support response times
Email and online ticketing support are available within normal business hours (Monday to Friday 09:00-17:00). Emails and tickets are responded to within 1 working hour. Out of hours support is available at additional cost.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Standard support is included in the contract and provided within normal business hours (Monday - Friday, 9-5, excluding UK Public Holidays).

Out of office hours support can be provided at additional cost.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide onboarding documentation with the option for remote or onsite onboarding training.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
System owners have access to their users' data throughout their use of BastionHub. If at the end of a contract the user requires a bulk extract of all data, an authenticated link to their bulk extract can be provided to the user.
End-of-contract process
At the end of the contract access to BastionHub is terminated through the disabling of accounts. User accounts, data and audit logs are securely deleted after 30 days. More detail can be provided on request.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
A subset of the BastionHub features such as Live View and auditing are available on a mobile device
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
BastionHub's API can be used by a customer's existing business applications to query or download customer generated data in BastionHub.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Customers can customise
*their virtual environments (device type, OS, installed applications etc)
*the Network Nodes their Kiosks use (firewall rules, logging etc)
* a wide range of other infrastructure and software

Scaling

Independence of resources
Customers can request dedicated environments thus guaranteeing a 100% access to resources.

Analytics

Service usage metrics
Yes
Metrics types
BastionHub collects a range of metrics for the purpose of auditing and reporting including but not limited to the following: User generated portal events, online session meta data, Just in Time session audit data, portal security events such as authentication and data access events.
Reporting types
  • API access
  • Real-time dashboards
  • Reports on request

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a Tigerscheme qualified provider or a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v3.0
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
BastionHub offers a range of data that can be exported. Auditing data can be exported via a Reporting function or the API.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
The guaranteed level of availability is 99.5% this does not include planned maintenance windows or local internet bandwidth issues users may experience such as download speeds dropping below below the minimum requirement.

SLA's can be found in the service definition document.
Approach to resilience
BastionHub infrastructure resilience is designed and built inline with industry best practice. More information is available in request.
Outage reporting
Outages and service incidents are reported via email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Username or password
  • Other
Other user authentication
LDAP and Active Directory integration are available
Access restrictions in management interfaces and support channels
Management access is limited to restricted channels with enhanced levels of authentication and access control in line with our Access Control Policy. More details can be provided.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Description of management access authentication
Some management access is restricted to white listed source IP addresses.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
Yes
CSA STAR accreditation date
16/11/2021
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
All areas of the BastionHub Platform and management networks are covered
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
  • Cyber Essentials
  • NCSC Certified Cyber Professional (CCP)
  • Certified Cloud Security Professional (CCSP)

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CCM version 3.0
  • ISO/IEC 27001
Information security policies and processes
Information Security Policy
Mobile Device Policy
Remote Access Policy
Access Control Policy
Cryptography Policy
Cryptography Key Management Policy
Acceptable Use of Information Assets Policy
Information Transfer Policy
Secure Development Policy

Operational security

Configuration and change management standard
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach
All production environment changes are documented in a change control process. Changes are reviewed, tested and approved in Pre-Production first before being deployed to Production.
Vulnerability management type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach
We receive threat information from a range of sources, including but limited to Vendor Security Bulletins, NCSC Security feeds and in-house Cyber Threat Intelligence Assessments. In addition to these, technical vulnerability scans are conducted in all environments. All vulnerabilities (including our own developed code) are patched and managed in line with our Secure Development and Patching Policies: ‘Critical’ patches are deployed within hours of release. ‘Important’ patches deployed within 1 week of release.‘Other’ patches are deployed within 4 weeks of a release.
Protective monitoring type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach
BastionHub uses a reactive system to monitor for security events. All relevant logs and feeding into a SIEM platform which produces reports and dashboard alerts. Feeds are taken from firewalls, IDS/IPS and servers within the environments.
Security incidences or unusual log entries are investigated and assigned a support ticket as soon as alerts are triggered.
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
Our incident response plan is based on NIST SP 800-61 and CREST CISR Guidance. Users can report incidents via email, phone or the ticketing system. Incident updates and summaries are provided to users. Detailed Incident Reports are recorded internally as part of our Information Security Governance.

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

  • Fighting climate change
  • Covid-19 recovery
  • Tackling economic inequality
  • Equal opportunity
  • Wellbeing

Fighting climate change

BastionHub supports government and private sector agencies researching and combating climate change by providing cost-effective and completely secure remote access to systems and data. Further documentation available on request.

Covid-19 recovery

BastionHub supports government agencies, particularly NHS and Care Sector, by providing secure remote access to authorised agents accessing highly sensitive personal health data to support Covid-19 recovery. Further documentation available on request.

Tackling economic inequality

BastionHub supports government and private sector agencies researching and combating economic inequality by providing cost-effective and completely secure remote access to systems and data. Further documentation available on request.

Equal opportunity

BastionHub supports government and private sector agencies researching, monitoring, and supporting equal opportunity adherence by providing cost-effective and completely secure remote access to agency systems and data. Further documentation available on request.

Wellbeing

BastionHub supports companies and employees in implementing and monitoring and tracking corporate wellbeing policies by providing cost-effective and completely secure remote access to sensitive data. Further documentation available on request.

Pricing

Price
£0.49 a device an hour
Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We offer a free trial for 30 days of up to 3 remote access users

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@blankbox.tech. Tell them what format you need. It will help if you say what assistive technology you use.