BastionHub
BastionHub is a fully audited and high security Privileged Access Management solution. It provides remote Just In Time access to sensitive systems or networks. It allows system owners to grant temporary fully audited access to environments with the ability to revoke access in an instance
Features
- Fully managed service
- Fully audited
- Live Stream of users' activity
- Secure scalable Infrastructure
- Integrate with existing business applications
- Linux, Windows and OSX environments
- Secure Supplier Access
Benefits
- Fully Monitored Access Control
- Grant temporary Just In Time access to Privileged users
- Manage supplier or contractor access to internal systems
- Accessible via any browser
- Remote Access
- No need to provide contractors / suppliers with IT kit
- Compliant with legal requirements
Pricing
£0.49 a device an hour
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
5 1 8 4 9 4 3 6 6 8 7 2 1 3 0
Contact
BLANKBOX TECHNOLOGIES LTD
Jacques de la Porte
Telephone: +449
Email: sales@blankbox.tech
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- N/A
- System requirements
-
- Reliable internet connection (5Mbps minimum)
- HTML5 enabled browser
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Email and online ticketing support are available within normal business hours (Monday to Friday 09:00-17:00). Emails and tickets are responded to within 1 working hour. Out of hours support is available at additional cost.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Standard support is included in the contract and provided within normal business hours (Monday - Friday, 9-5, excluding UK Public Holidays).
Out of office hours support can be provided at additional cost. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide onboarding documentation with the option for remote or onsite onboarding training.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- System owners have access to their users' data throughout their use of BastionHub. If at the end of a contract the user requires a bulk extract of all data, an authenticated link to their bulk extract can be provided to the user.
- End-of-contract process
- At the end of the contract access to BastionHub is terminated through the disabling of accounts. User accounts, data and audit logs are securely deleted after 30 days. More detail can be provided on request.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- A subset of the BastionHub features such as Live View and auditing are available on a mobile device
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- BastionHub's API can be used by a customer's existing business applications to query or download customer generated data in BastionHub.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Customers can customise
*their virtual environments (device type, OS, installed applications etc)
*the Network Nodes their Kiosks use (firewall rules, logging etc)
* a wide range of other infrastructure and software
Scaling
- Independence of resources
- Customers can request dedicated environments thus guaranteeing a 100% access to resources.
Analytics
- Service usage metrics
- Yes
- Metrics types
- BastionHub collects a range of metrics for the purpose of auditing and reporting including but not limited to the following: User generated portal events, online session meta data, Just in Time session audit data, portal security events such as authentication and data access events.
- Reporting types
-
- API access
- Real-time dashboards
- Reports on request
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a Tigerscheme qualified provider or a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- BastionHub offers a range of data that can be exported. Auditing data can be exported via a Reporting function or the API.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
The guaranteed level of availability is 99.5% this does not include planned maintenance windows or local internet bandwidth issues users may experience such as download speeds dropping below below the minimum requirement.
SLA's can be found in the service definition document. - Approach to resilience
- BastionHub infrastructure resilience is designed and built inline with industry best practice. More information is available in request.
- Outage reporting
- Outages and service incidents are reported via email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Username or password
- Other
- Other user authentication
- LDAP and Active Directory integration are available
- Access restrictions in management interfaces and support channels
- Management access is limited to restricted channels with enhanced levels of authentication and access control in line with our Access Control Policy. More details can be provided.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
- Other
- Description of management access authentication
- Some management access is restricted to white listed source IP addresses.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- 16/11/2021
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
- All areas of the BastionHub Platform and management networks are covered
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
-
- Cyber Essentials
- NCSC Certified Cyber Professional (CCP)
- Certified Cloud Security Professional (CCSP)
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CCM version 3.0
- ISO/IEC 27001
- Information security policies and processes
-
Information Security Policy
Mobile Device Policy
Remote Access Policy
Access Control Policy
Cryptography Policy
Cryptography Key Management Policy
Acceptable Use of Information Assets Policy
Information Transfer Policy
Secure Development Policy
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
- All production environment changes are documented in a change control process. Changes are reviewed, tested and approved in Pre-Production first before being deployed to Production.
- Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
- We receive threat information from a range of sources, including but limited to Vendor Security Bulletins, NCSC Security feeds and in-house Cyber Threat Intelligence Assessments. In addition to these, technical vulnerability scans are conducted in all environments. All vulnerabilities (including our own developed code) are patched and managed in line with our Secure Development and Patching Policies: ‘Critical’ patches are deployed within hours of release. ‘Important’ patches deployed within 1 week of release.‘Other’ patches are deployed within 4 weeks of a release.
- Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
-
BastionHub uses a reactive system to monitor for security events. All relevant logs and feeding into a SIEM platform which produces reports and dashboard alerts. Feeds are taken from firewalls, IDS/IPS and servers within the environments.
Security incidences or unusual log entries are investigated and assigned a support ticket as soon as alerts are triggered. - Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
- Our incident response plan is based on NIST SP 800-61 and CREST CISR Guidance. Users can report incidents via email, phone or the ticketing system. Incident updates and summaries are provided to users. Detailed Incident Reports are recorded internally as part of our Information Security Governance.
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
BastionHub supports government and private sector agencies researching and combating climate change by providing cost-effective and completely secure remote access to systems and data. Further documentation available on request.Covid-19 recovery
BastionHub supports government agencies, particularly NHS and Care Sector, by providing secure remote access to authorised agents accessing highly sensitive personal health data to support Covid-19 recovery. Further documentation available on request.Tackling economic inequality
BastionHub supports government and private sector agencies researching and combating economic inequality by providing cost-effective and completely secure remote access to systems and data. Further documentation available on request.Equal opportunity
BastionHub supports government and private sector agencies researching, monitoring, and supporting equal opportunity adherence by providing cost-effective and completely secure remote access to agency systems and data. Further documentation available on request.Wellbeing
BastionHub supports companies and employees in implementing and monitoring and tracking corporate wellbeing policies by providing cost-effective and completely secure remote access to sensitive data. Further documentation available on request.
Pricing
- Price
- £0.49 a device an hour
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We offer a free trial for 30 days of up to 3 remote access users