Skip to main content

Help us improve the Digital Marketplace - send your feedback

Nimbox Ltd.

Nimbox Vault

Vault lets your teams easily collaborate on OFFICIAL information, whilst retaining audit controls. Vault provides secure file sharing, real-time collaborative document editing, backup, remote file server access, and cloud storage. It is UK sovereign, hosted in accredited UK data centres, with end-to-end encryption protecting data at rest and in transit.

Features

  • Real-time file syncing and backup, for desktops and servers
  • Protect work, with unlimited version history and global file lockin
  • Data protection at all levels, with transparent end-to-end cryptography
  • Easy to deploy SaaS, with system and application integration
  • Online team file preview and edit, for instant results
  • External sharing, with free password protected and audited accounts
  • Outlook plugin, reducing email system administration and storage overheads
  • Active Directory (AD) / LDAP authentication, for domain integration
  • Team collaboration folders, making working on documents together easy
  • Organisation dashboard, providing administrator tools and detailed reporting

Benefits

  • Collaborating securely; files and teams protected by military strength cryptography
  • Accessing files remotely; without compromising security or privacy
  • Retaining audit control; validate proper use of Departmental data
  • Comprehensive auditing and tracking; with exportable logs of user activity
  • Safe sharing; ensure files are shared with only authorised people
  • Consolidated repository; create a hybrid cloud of current file servers
  • Easily create backups; from folder to whole machines
  • Unlimited versioning; retain a historical archive of your files
  • Global file locking; prevent changes from being overwritten
  • Familiarity; similar to public cloud services e.g. Dropbox, OneDrive, Box

Pricing

£10 to £25 a user a month

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@nimbox.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

5 5 6 5 7 8 0 3 5 4 1 8 8 8 4

Contact

Nimbox Ltd. Kerri Milburn
Telephone: 03454 757574
Email: hello@nimbox.co.uk

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The platforms listed on the 'Supported Operating Systems' Knowledge Base article have been tested for support with the Nimbox Vault service, and whilst other compatibilities may exist, they are not officially supported. You may access the article here: http://support.nimbox.co.uk/knowledge_base/topics/supported-operating-systems
System requirements
  • Access to a PC, Mac, or mobile device
  • Internet connection

User support

Email or online ticketing support
Email or online ticketing
Support response times
Standard response SLA for email tickets is 2 hours 9 to 17:30 Mon-Fri Excluding Bank Holidays.
Weekend and Bank Holidays are not offered as standard.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
If you purchase a 'Standard' subscription, we'll handle your support request via email. Support is included in the subscription.
If you purchase a 'Premium' user account subscription, we'll handle your support request via telephone or email. Support is included in the subscription.
On-site support may be arranged by contacting our support team, however this will be charged at our standard consultancy rates.

We provide access to a team of remote support engineers, and also a Customer Service Manager.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Getting started with Nimbox Vault is simple, and we'll work with you to deploy the service across your teams. Nimbox will provide easy to follow documentation, user training, and on-site support (subject to an additional charge). Plus, our support and engineering team is on hand to ensure the deployment is trouble free.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Users can simply download all the data they store within Nimbox Vault, in a 'ZIP' folder. The user doesn't need to interact with us, as this process can be initiated, and completed, from within the user's online dashboard.
End-of-contract process
When the contract has ended, and if you don't want to extend your use of the Nimbox service, we'll give you thirty days to download your files and data. This process is initiated, and completed, by the buyer.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • MacOS
  • Windows
  • Windows Phone
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
No
User support accessibility
WCAG 2.1 A
API
Yes
What users can and can't do using the API
Nimbox API connectivity is available for all subscribers, but does have a fair usage limit of 2000 requests per hour (this can be increased if you contact us).

Getting started with the Nimbox API is simple, and our support team can walk you through the initial process.

The Nimbox API is organised around REST. Our API is designed to have predictable, resource-oriented URLs, and to use HTTP response codes to indicate API errors. We use built-in HTTP features, like HTTP authentication and HTTP verbs, which can be understood by off-the-shelf HTTP clients. JSON will be returned in all responses from the API, including errors.

The API includes, provisioning, user & device management, and storage management.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
As part of the 'Premium' plan's features, subscribers may configure custom branding within their service. This branding will show for all users, both internal, and for external users. It is present on the web, desktop, and mobile applications.

Scaling

Independence of resources
Nimbox hard-provisions storage space for users, based on the amount allocated to their subscription plan. We also host on an elastic virtual hosting platform, which allows us to add resource quickly to cope with sudden increases in resource demand.

Analytics

Service usage metrics
Yes
Metrics types
Administrators are provided with real-time information dashboards, and configurable reports, showing: storage overviews (including consumption over time, usage by file type); file and user activity; bandwidth usage; device status and health; and, details of accounts, admins, machines, roots, files, and revisions; plus, many additional metrics.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Users can simply download all the data they store within Nimbox Vault, in a 'ZIP' folder. The user doesn't need to interact with us, as this process can be initiated, and completed, from within the user's online dashboard.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • Original format
  • The format that was originally used to import the data
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • Any format supported by their file system
  • Nimbox supports any data format for upload

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Nimbox strives, as part of our design, to always be available. And, whilst no specific service level is assured, we have been operating at over 99.99% availability since we started in 2012. You can find more details about our refund policy in our Subscriber Agreement.
Approach to resilience
Vault is hosted in Tier 3+, ISO27001:2022 certified data centres, which have 24x7x365 on-site security, zonal swipe card entry, CCTV systems, perimeter fencing with controlled access, fire suppression systems, in-rack early warning temperature sensors and fire detection in all rooms, ceilings and below raised floors, N+1 UPS, and N+1 generators with a minimum 48 hours of fuel.
Our solution is powered by VMware technologies, and utilises automatic replication and failover. We test our failover procedures regularly.

Our platform is also monitored 24x7x365 from our system centre, and by Pingdom AB. Our platform is monitored for availability, reliability, and speed. A comprehensive external security testing programme is run each week to ensure that our service is secure from known exploits, new vulnerabilities, and targeted attacks.
Outage reporting
We’re always monitoring the Nimbox platform. If there are any interruptions to your service, we’ll post details on our public status page, https://status.nimbox.co.uk, where users can subscribe to live incident updates.

You can subscribe to alerts via email.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Username or password
Access restrictions in management interfaces and support channels
Whilst Nimbox accepts support requests from any Nimbox user, we only action user or service-impacting requests when authorisation has been provided by named organisation administrators. Currently this authorisation comes via a telephone call placed to a department number that is known to be safe.
Access restriction testing frequency
At least every 6 months
Management access authentication
2-factor authentication

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Less than 1 month

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Standards Institute
ISO/IEC 27001 accreditation date
13/07/2024
What the ISO/IEC 27001 doesn’t cover
N/a
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
No
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We operate our infrastructure exclusively in ISO27001:2022 certified data centres, and your service is provisioned and maintained by an ISO27001:2022 certified team.
Our service and software is fully compliant with HMG’s Cloud Security Principles, and aligned with CESG’s Good Practice Guides. We have built our service around the technical and policy controls that are suggested by these programmes. As such, our service can host information that is classified up to OFFICIAL under the UK Government Protective Marking Scheme.
We hold a Certificate of Assurance that testifies to our compliance with the requirements of the UK Government Cyber Essentials Scheme.
Information security policies and processes
The information Nimbox manages, in both electronic and hard copy, is appropriately secured to protect against the consequences of breaches of confidentiality, failures of integrity or interruptions to the availability of that information.

In deploying a robust Information Security Management System (ISMS), Nimbox aims to reduce the risk of incidents to an acceptable level.

Nimbox’s Information Security Officer has direct responsibility for maintaining Security Policy and providing advice and guidance on its implementation. It is the responsibility of all employees and 3rd Parties working within the scope of this Information Security Management System to comply with security policy at all times and report weakness or incidents that contravene or may contravene policy to the Information Security Officer.

All management are directly responsible for implementing security policy and supporting procedures within their business area, and for adherence by their staff.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Nimbox follows a structured change control process that provides for the tracking of assets throughout their lifetime. Our change control process follows an industry-standard methodology of: 1, identifying a requirement for change; 2, defining an implementation plan; 3, raising a change request on our change application; 4, approval by a technical manager; 5, implementation of the change on a development environment; 6, testing of the change on that development environment; 7, implementation of the change on the production environment; 8, testing of the change on that production environment; 9, completing the change documentation, and post change report.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We thoroughly investigate all reported security vulnerabilities, and aim to make this process as transparent as possible. Our security programme includes our platform, public web assets, and third party services (but only where the attack can exploit our customers directly). We aim to respond to all vulnerability reports within 24 hours. The Security Team reviews all reported vulnerabilities and takes steps to validate and reproduce them. Once the review is complete, and the vulnerability has been confirmed, the vulnerability will be fixed, and public disclosure arranged. You may read more about our vulnerability reporting programme here on our website, https://www.nimbox.co.uk/technology-security/#vulnerabilityreporting.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Nimbox's protective monitoring approach is compliant with HMG’s Cloud Security Principles and aligns with CESG’s Good Practice Guides.

We analyse service component heuristics for 'normal' baseline application behaviour, and notify system administrators on exception for analysis.
If we discover a breach of Customer Information, we shall inform our regulator (the Information Commissioner) within 72 hours of the discovery, and our Customers within 7 days. Notification to users may be sent via email, postal mail, or telephone.
Incident management type
Supplier-defined controls
Incident management approach
Nimbox's incident management approach is compliant with HMG’s Cloud Security Principles and aligns with CESG’s Good Practice Guides.

Our in-house monitoring system raises issue tickets via email with our servicedesk for incidents which require human review. Users and administrators are able to submit issues using our support ticket system as a unified process, and these incidents are responded to and escalated as needed by the support team, in writing within the system.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

Fighting climate change

Fighting climate change

Nimbox Vault service combats climate change by consolidating servers and reducing energy usage, and also reduce the demand for physical hardware, leading to decreased energy consumption and lower carbon emissions associated with manufacturing, operating, and disposing of such equipment. Supporting remote working initiatives through highly available data helps to reduce commuting and further lowers carbon emissions.

Pricing

Price
£10 to £25 a user a month
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We provide all customers with a 14 day free trial, which is fully-featured, and extendable on a case-by-case basis.
Link to free trial
https://www.nimbox.co.uk/pricing/#Trial

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@nimbox.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.