Skip to main content

Help us improve the Digital Marketplace - send your feedback

Jumping Rivers Ltd

Web Application Security Platform ('WASP')

Our Web Application Security Platform allows you to easy monitor external resources that Shiny apps and markdown documents are using. When a user visits any application on your RStudio Connect server, this will silently trigger a comparison of your web-page with an a pre-defined allowed resource list.

Features

  • Easy installation with R package
  • Header line for most common web application firewalls
  • Central dashboard for all applications
  • Identify potential security threats
  • Lock down application hosting infrastructure to avoid future threats
  • Reduce XSS attacks

Benefits

  • Provide a single place to audit external resources
  • Provide a mechanism for setting global 3d party allow lists
  • Reduce the attack surface of Shiny and markdown web applications

Pricing

£5,000.00 a licence a year

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@jumpingrivers.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

5 5 8 0 7 5 4 9 6 0 7 9 1 3 5

Contact

Jumping Rivers Ltd Esther Gillespie
Telephone: 07740285328
Email: hello@jumpingrivers.com

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
RStudio Connect
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
This offering is only available with RStudio Connect
System requirements
100+ GB of disk storage

User support

Email or online ticketing support
Email or online ticketing
Support response times
48 hour response time
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We offer third-line support however for this application it will be managed by Jumping Rivers.
Support available to third parties
No

Onboarding and offboarding

Getting started
Installation and setup is done by Jumping Rivers with our on-boarding process
Service documentation
No
End-of-contract data extraction
There is no need to extract the data, as this remains in their infrastructure throughout the service.
End-of-contract process
We will remove the application from your system and no longer support the RStudio Connect application.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
Linux or Unix
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
No

Scaling

Independence of resources
N/A - this doesn't effect usual user interaction

Analytics

Service usage metrics
Yes
Metrics types
It is hosted on RStudio Connect
Reporting types
  • API access
  • Real-time dashboards

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
Up to Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
Never
Protecting data at rest
Other
Other data at rest protection approach
Data is not sensitive and is stored on customer internal network.
Data sanitisation process
No
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
N/A
Data export formats
CSV
Data import formats
Other
Other data import formats
N/A

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Data is hosted on client network.
Approach to resilience
Data is hosted on client internal network
Outage reporting
Public dashboard

Identity and authentication

User authentication needed
Yes
User authentication
Other
Other user authentication
Hosted on RStudio Connect follows already existing security policies.
Access restrictions in management interfaces and support channels
Hosted in RStudio Connect and this follows existing security policies.
Access restriction testing frequency
Never
Management access authentication
Other
Description of management access authentication
Hosted on RStudio Connect and this follows existing security controls.

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
19th June 2023
What the ISO/IEC 27001 doesn’t cover
Example of exclusions

8.2.2
Labelling of information An appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme adopted by the Organisation
8.3.2 Disposal of media Media shall be disposed of securely when no longer required, using formal procedures
8.3.3 Physical media transfer Media containing information shall be protected against unauthorised access, misuse or corruption during transportation
11.1.4 Protecting against external and environmental threats Physical protection against natural disasters, malicious attack or accidents shall be designed and applied
11.1.5 Working in secure areas Procedures for working in secure areas shall be designed and applied
11.2.1 Equipment siting and protection Equipment shall be sited and protected to reduce the risks from environmental threats and hazards, and opportunities for unauthorised access.
11.2.2 Supporting utilities Equipment shall be protected from power failures and other disruptions caused by failures in supporting utilities.
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
No

Security governance

Named board-level person responsible for service security
No
Security governance certified
No
Security governance approach
All data and services is hosted on the client's internal network. No access to outside is required.
Information security policies and processes
We currently follow cyber essentials and are working towards ISO27001

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All software is stored on the Jumping Rivers Git server and has a
rigorous testing service, via continuous integration.
Changes are tested on our staging server.
When updates are requires, we use an infrastructure as code model, to ensure changes are consistent across systems.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
All software is hosted on the internal client network, and follows
their security standards. No external access is required.
We monitor for security issues via Sonatype and update software when required.
Patches are applied within 28 days.
Protective monitoring type
Undisclosed
Protective monitoring approach
N/A
Incident management type
Undisclosed
Incident management approach
N/A

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

  • Fighting climate change
  • Tackling economic inequality
  • Equal opportunity
  • Wellbeing

Fighting climate change

We will promote sustainable working practices through employee sustainability guidelines.
When working in the office, our employees will utilise the comprehensive recycling and food waste management facilities throughout the building, including separate bins for paper, plastic, and other recyclable materials. We will also use the food waste bins available for composting and reduce organic waste sent to landfills.
We will continue to stay in our chosen office building due to its sustainability initiatives, including the building being equipped with solar panels to help reduce our reliance on fossil fuels and decrease greenhouse gas emissions.

Tackling economic inequality

We will actively support the communities in which we operate through education, volunteering, facilitating data science events, and community engagement initiatives.
We will implement a formal volunteering policy for our employees to promote giving back to the local and data science community.
We will promote diversity and inclusion in the workplace by fostering a culture that respects and values differences in gender, race, ethnicity, age, sexual orientation, abilities and background.
We will ensure fair wages and benefits through annual salary reviews and make sure that working conditions for all employees and contractors adhere to UK employment law and regulations, fostering a safe and healthy work environment.
Where possible, we will always prefer to partner with suppliers who have sustainable practices and/or are local to the North East.
Through structured progression and goal-setting frameworks, we will invest in employee training and development to enhance skills, knowledge, and capabilities, empowering individuals to reach their full potential and contribute meaningfully to society.
We will prioritise customer satisfaction by offering high-quality service, transparent pricing, and responsive customer support whilst ensuring ethical marketing practices.
We will prioritise the physical & mental health of employees by providing healthcare resources, including health insurance and 24/7 employee assistance programs.

Equal opportunity

Jumping Rivers is committed to encouraging equality, diversity and inclusion among our workforce. We aim to provide equality, fairness and respect for all in our employment, whether temporary, part-time or full-time. Not unlawfully discriminate because of the Equality Act 2010 protected characteristics of;
● Age
● Disability
● Gender reassignment
● Marriage or civil partnership
● Pregnancy and maternity
● Race (including colour, nationality, and ethnic or national origin)
● Religion or belief
● Sex
● Sexual orientation.
Oppose and avoid all forms of unlawful discrimination. This includes
● Pay and benefits
● Terms and conditions of employment
● Dealing with grievances and discipline
● Dismissal
● Redundancy
● Leave for parents
● Requests for flexible working
● Selection for employment, promotion, training or other developmental opportunities.

In line with the Jumping Rivers Anti-bullying and harassment policy, we encourage and support equality,diversity, and inclusion in the workplace. Jumping Rivers will make training, development, and progress opportunities available to all staff members, who will be encouraged to develop their full potential.
Decision-making concerning Jumping Rivers’ staff will be based on merit (apart from any necessary and limited exemptions and exceptions allowed under the Equality Act).
Jumping Rivers commits to reviewing employment practices and procedures when necessary to ensure fairness and update them and the policy to take account of changes in the law.

Wellbeing

We will implement a formal volunteering policy for our employees to promote giving back to the local and data science community.

We will promote diversity and inclusion in the workplace by fostering a culture that respects and values differences in gender, race, ethnicity, age, sexual orientation, abilities and background.

We will ensure fair wages and benefits through annual salary reviews and make sure that working conditions for all employees and contractors adhere to UK employment law and regulations, fostering a safe and healthy work environment.

Through structured progression and goal-setting frameworks, we will invest in employee training and development to enhance skills, knowledge, and capabilities, empowering individuals to reach their full potential and contribute meaningfully to society.

We will prioritise the physical & mental health of employees by providing healthcare resources, including health insurance and 24/7 employee assistance programs.

Pricing

Price
£5,000.00 a licence a year
Discount for educational organisations
No
Free trial available
No

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@jumpingrivers.com. Tell them what format you need. It will help if you say what assistive technology you use.