CheckRed Security Posture Management Platform
CheckRed gives security teams full visibility and control across cloud, SaaS, & DNS environments. Prevent misconfigurations, secure identities (human & non-human), manage workload vulnerabilities, and maintain continuous compliance (e.g CAF, NIS2, DORA, GDPR, Cyber Essentials, ISO27001), stopping threats before they strike, without agents or added complexity.
Features
- Cloud Security Posture Management (CSPM)
- DNS Security Posture Management (DNSPM)
- SaaS Security Posture Management (SSPM)
- Certificate Security Posture Management (CERTSPM)
- Workload Security Posture Management
- Compliance Framework Management and Audit
- Detailed Reporting and Alerting
- Identity Security Posture Management (IAMSPM)
- Remediation Guidance for all misconfigurations
- Multi-Tenanted
Benefits
- Identify misconfigurations that lead to vulnerabilities
- Misconfiguration remediation instructions
- Security Framework compliance and auditing
- Workflow visibility and management
- Full Cloud, SaaS, IAM and DNS inventory
- Continuous compliance
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 7 7 7 0 9 6 8 8 4 4 9 8 6 6
Contact
STONESTHRO LTD
Andy Bates
Telephone: 07880783166
Email: andy.bates@stonesthro.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- SaaS, Cloud, Identity, DNS and workload services
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- No
- System requirements
- SaaS and Cloud Licensing
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 24 hours
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Only one support level, however if additional support is needed for the customer this can be discussed and will be an extra cost
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- There is training available (onsite training is chargeable). Training, onboarding and service management documentation and online training is available
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- For audit purposes, data is retained for 90 days. Customers can extract that through a variety of means. After 90 days, the data is permanently removed.
- End-of-contract process
- On contract completion access if removed, however up until 90 days after contract expires data can be requested through a ticketing system
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Via the CheckRed knowledgebase in recorded video format
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- User Interface for the management of the CheckRed service
- Accessibility standards
- None or don’t know
- Description of accessibility
- N/A
- Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
- All services can be managed through the CheckRed API
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- CheckRed uses automatic hyperscaler auto-scaling. There is a service availability SLA
Analytics
- Service usage metrics
- Yes
- Metrics types
- Cloud, SaaS, DNS, Inventories, User Audit Trails
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- CheckRed
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- API or bespoke reporting
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Bespoke reports
- Data import formats
- Other
- Other data import formats
- API access
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Availability SLA's will be made available
- Approach to resilience
- Available on request
- Outage reporting
- Outages can be reported via dashboard, API or email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Via Role Based Access and MFA
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- SOC2
- Information security policies and processes
- As well as ISO27001 and SOC2, CheckRed follows CSA STAR level 1 compliance
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Components are tracked through their lifetime. Changes are assessed for their security impact. Security controls are in place throughout the whole lifecycle - DevSec.
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Available on request
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Available on request
- Incident management type
- Supplier-defined controls
- Incident management approach
- There are pre-defined processes for common events. Users can report events through a ticketing system. Incidents are reported via email and ticketing system
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- 15 day up to three applications tested
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 18%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Eda8b040-5636-4501-8dfd-375f408288e3
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- HIPAA via Zadara as primary cloud provider
- ISO27017 of our primary supplier Zadara
- SOC1 via Zadara primary cloud supplier
- SOC2 via Zadara primary cloud supplier
- ISO27018 via Zadara primary cloud supplier
- IRAP via Zadara primary cloud supplier
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-