Skip to main content

Help us improve the Digital Marketplace - send your feedback

IOCO SOLUTIONS LIMITED

Ternary

Ternary is a cloud financial management (FinOps) SaaS platform that provides unified, multi-cloud cost visibility, forecasting, and cost allocation. It enables public and private sector organisations to govern cloud spend, optimise usage, support chargeback, and improve financial accountability through secure, read-only integrations and intuitive dashboards.

Features

  • Multi-cloud cost ingestion (AWS, Azure, GCP, OCI, SaaS providers)
  • Near real-time cost and usage reporting
  • Browser-based SaaS platform with secure remote access
  • Read-only integrations with cloud providers
  • Role-Based Access Control (RBAC) and scoped views
  • Advanced cost allocation, showback and chargeback
  • Multi-currency reporting, including GBP conversion
  • Budgeting, forecasting, and ramp planning for future spend modelling
  • Savings and commitment tracking
  • API-first architecture

Benefits

  • Improves financial governance and transparency across cloud
  • Enables accurate chargeback and departmental accountability
  • Supports budget control and forecasting for public sector planning cycles
  • Reduces cloud waste and financial risk without impacting operations
  • Scales without penalty for users, accounts, or departments

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@ioco.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 9 9 6 3 0 3 0 9 3 0 4 2 1 3

Contact

IOCO SOLUTIONS LIMITED Mick Morey
Telephone: 0118 206 2938
Email: sales@ioco.uk

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service relies on cloud provider billing and usage exports. Near real-time visibility is subject to the update frequency and data latency of the underlying cloud providers.

Accuracy of allocation, reporting, and forecasting is dependent on the quality and consistency of cloud billing data, tags, and account structures provided by the customer.
System requirements
An Internet connection is required to use the service

User support

Email or online ticketing support
Yes
Support response times
Ternary is fully supported by iOCO’s 24/7 Service Desk portal. The service is available 365 days a year. Responses are prioritised and addressed in line with the service levels detailed in the Service Level Agreement document.
P1 CRITICAL, Response Time SLA 1 hour, Target Resolution Time 8 hours
P2 HIGH, Response Time SLA 3 hours, Target Resolution Time 36 hours
P3 MEDIUM, Response Time SLA 6 hours, Target Resolution Time 72 hours
P4 LOW, Response Time SLA 24 hours, Target Resolution Time N/A
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We use OpenText SMAX which is a SAAS ticketing portal conforming to accessibility standards which the vendor test against and for which they provide accessibility conformance reports available by request here: https://www.opentext.com/about/accessibility/accessibility-conformance-reports
Onsite support
Yes, at extra cost
Support levels
IOCO provides a flexible, public-sector-aligned support model designed to ensure service continuity while allowing customers to scale support based on operational needs.

**Normal Support**, which is included as part of the base service, provides **24x7 access to a centralised service desk** via a web-based ticketing system. Customers can log incidents, service requests, and technical queries at any time, with issues triaged according to agreed severity levels. Response and resolution targets are aligned to industry best practice, ensuring critical incidents receive immediate attention while lower-priority requests are handled in a controlled and auditable manner. This model supports day-to-day operations and provides full visibility through tracked tickets and escalation workflows.

**Premium Support** is available as an optional enhancement through a **Call-off Service Agreement**. This model is based on **pre-purchased service credits**, valid for a 12-month period, which customers can consume flexibly according to their requirements and subject to iOCO resource availability. Premium Support provides priority handling of incidents, accelerated response times, access to senior engineering resources, and proactive advisory support. It is particularly suited to customers with variable demand, complex environments, or time-critical workloads.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We will provide handholding throughout the duration of onboarding in order to make the setup and time to productivity as short as possible.
An initial introductory training session will be provided and can be supplemented by further bespoke training tailored to your needs.
Online tutorials are available as well as and extensive documentation on the website.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
When the contract ends, users retain full control over their data and can extract it using standard, documented methods.

Users can export reports and datasets directly from the service in common, open formats such as CSV and JSON, enabling continued analysis or migration to another platform. All configured reports, dashboards, and financial views can be extracted prior to termination.

In addition, users can use the REST API to programmatically extract reporting outputs and configuration data, including custom labels, budgets, and cost allocation rules, allowing these settings to be retained or recreated elsewhere.

The underlying cloud billing and usage data remains the property of the customer and continues to reside with the original cloud providers. At the end of the contract, user access to the service is removed and the customer tenant is securely deleted in line with documented data retention and disposal processes.
End-of-contract process
Customer access to the service is withdrawn at the contract end date. Users are given the opportunity to export reports, datasets, and configuration information (such as cost allocation rules, budgets, and custom labels) using the user interface or API. The customer’s tenant is then securely decommissioned and all platform-resident data is permanently deleted in line with documented data retention and disposal policies. The customer’s original cloud billing and usage data remains with the relevant cloud providers at all times.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
The documentation is available through our public website https://docs.ternary.app/docs/home

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service is delivered through a secure, browser-based web interface.

The interface provides users with access to dashboards, reports, configuration settings, and administrative functions without requiring any local software installation. Access is available remotely via standard web browsers using encrypted HTTPS connections, with support for role-based access control and optional Single Sign-On.

In addition to the web interface, the service also exposes a documented REST API, allowing programmatic access for configuration, reporting, and integration with external systems such as finance, billing, or reporting platforms.
Accessibility standards
None or don’t know
Description of accessibility
The service is delivered through a browser-based web interface that supports standard accessibility features available in modern browsers and operating systems. Users can navigate core functions using a keyboard, apply browser zoom and screen magnification, and access content using browser-native screen readers. Reports can be exported for offline use with assistive tools, and Single Sign-On reduces authentication barriers.

The service is optimised for desktop use and does not currently hold formal WCAG or VPAT certification. Some complex, data-dense visualisations may be challenging for screen-reader users. Accessibility issues can be reported and are reviewed for ongoing improvement.
Accessibility testing
Ternary has not completed formal, third-party certified accessibility testing (such as a full WCAG 2.2 audit or VPAT) specifically with users of assistive technologies.

However, accessibility considerations are incorporated into the platform’s design, development, and testing practices, and the service is built using modern web standards that are compatible with commonly used assistive technologies.
API
Yes
What users can and can't do using the API
The service provides a secure REST API that allows users to configure and manage most aspects of the platform programmatically. Users can set up the service by creating users, roles, permissions, cloud subscriptions, budgets, custom labels, and cost allocation rules. Ongoing changes, including updates to access controls, financial rules, and reporting data exports, can also be made through the API.

The API is read-only with respect to customer cloud infrastructure and billing source data, and cannot perform operational actions or control visual dashboard layouts. Access is permission-based, secured with API keys, and subject to rate limits and security controls.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
The service is designed to be highly configurable so organisations can align it to their financial governance, reporting, and operational requirements without changing underlying cloud infrastructure.

This includes user access and permissions through role-based access control, scoped views that limit data visibility, cost allocation rules for showback and chargeback, and custom labels to enhance or replace cloud-native tagging. Users can also configure budgets, forecasts, ramp plans, currency settings, dashboards, saved reports, and data exports. API integrations can be tailored to support finance, billing, and reporting workflows.

Most configuration is performed through the browser-based user interface, allowing interactive setup and immediate feedback. For automation and repeatability, the service also exposes a REST API that enables configuration-as-code, bulk updates, and integration with external systems. All customisation is applied within the platform’s reporting and governance layer and does not impact live cloud workloads.

Who can customise the service is governed by role-based permissions. Administrators have full control over users, financial rules, and integrations. Finance and FinOps users can manage budgets, allocations, forecasting, and reporting. Read-only users can view dashboards and reports but cannot make changes. This ensures strong governance, auditability, and separation of duties.

Scaling

Independence of resources
The service ensures users are not affected by other customers’ demand through logical tenant isolation and elastic cloud architecture. Each customer operates in a securely segregated tenant, preventing cross-tenant access or resource contention. The platform runs on auto-scaling, serverless cloud services that dynamically adjust capacity to meet demand, ensuring consistent performance during peak usage. Resource governance controls, including API rate limiting and workload management, prevent individual users from monopolising shared resources. Continuous monitoring is used to detect and manage abnormal usage patterns. Together, these measures provide predictable performance and protect service availability for all users.

Analytics

Service usage metrics
Yes
Metrics types
Ternary provides a comprehensive set of service usage and financial metrics through its platform.

The service exposes metrics such as cloud spend over time (daily, monthly, yearly), usage trends by service, account, project, or cost centre, budget consumption and forecast variance, cost allocation and chargeback results, savings from commitments (for example Reserved Instances and Savings Plans), and anomaly detection indicators.

Metrics are available via interactive dashboards and reports, can be filtered and segmented by multiple dimensions, and can be exported in open formats (CSV/JSON) or accessed programmatically via the API for integration with external reporting or monitoring systems.
Reporting types
  • API access
  • Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Ternary

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
Data sanitisation process
No
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Users can export their data using standard, self-service methods provided by the platform.

Data can be exported directly through the browser-based user interface, where users can download reports and datasets in common, open formats such as CSV and JSON. This allows data to be reused in spreadsheets, finance systems, or other reporting tools.

For automated or large-scale extraction, users can export data through the REST API, which supports programmatic access to reporting outputs and configuration data, including budgets, custom labels, and cost allocation rules. API exports are authenticated, permission-based, and suitable for integration with external systems.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • AWS Cost and Usage Reports (CUR)
  • Azure billing exports
  • Google Cloud billing exports

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is delivered with a clear and measurable availability commitment designed to meet public sector expectations for reliability and transparency. Ternary provides a 99.9% monthly availability target for its core SaaS platform, covering both the web-based user interface and API access. Availability is measured on a calendar-month basis and excludes planned maintenance windows, which are scheduled during low-usage periods where possible and communicated to customers in advance.

The platform is hosted on resilient, auto-scaling cloud infrastructure engineered to minimise single points of failure and support rapid recovery in the event of an incident. Availability is continuously monitored, and any service-impacting incidents are actively managed through the support process with regular updates provided to affected users.

A formal Service Level Agreement underpins this commitment. If the guaranteed availability level is not met, customers are entitled to service credits applied to the subsequent billing period. Credits are calculated as a percentage of the affected monthly subscription fee, increasing as availability decreases. These service credits provide a clear, contractual remedy for availability breaches and are designed to be fair, transparent, and auditable.
Approach to resilience
Available on request
Outage reporting
Service status information is instead communicated directly to affected customers to avoid ambiguity and ensure accurate, contextual updates.

For incidents impacting service availability or performance, email notifications are issued to affected customers. These notifications include:

Confirmation of the incident
Scope and impact
Initial assessment and mitigation steps
Ongoing progress updates
Post-incident resolution and summary where appropriate

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using strong identity and access controls. The service enforces role-based access control, ensuring users can only perform actions and view data appropriate to their role and tenant. Authentication is secured through usernames and passwords or Single Sign-On with customer identity providers, with Multi-Factor Authentication supported. Administrative actions and access events are logged and monitored. Support channels require authenticated users to raise tickets, and support staff access is limited to the minimum required to resolve issues. Elevated access is controlled, time-bound, approved, and fully audited.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
No audit information available
Access to supplier activity audit information
No audit information available
How long system logs are stored for
Less than 1 month

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
SOC 2 Type II certification
Information security policies and processes
Ternary’s security governance is underpinned by a SOC 2 Type II certification, which provides independent assurance over the design and operating effectiveness of its security controls over time. This certification covers key trust principles including security, availability, and confidentiality, and is reviewed regularly by an external auditor.

Security governance is managed through documented policies and procedures covering risk management, access control, data protection, incident response, change management, and vendor management. A senior leadership-led Risk Committee provides oversight of security risks, ensuring accountability at an executive level.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
The service uses formal configuration and change management processes to control and track all components throughout their lifecycle. Infrastructure, application code, and configuration are managed using version-controlled repositories and Infrastructure as Code, providing full traceability from development through to production and decommissioning. Separate development, staging, and production environments prevent untested changes from reaching live services. All changes are assessed through a structured change process aligned to SOC 2 and ITIL principles. Each change is reviewed for potential security impact, including effects on access control, data protection, and exposed interfaces, with approvals, testing, and audit logging enforced before deployment.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Ternary uses a risk-based vulnerability management process to identify and assess potential threats to its services. Automated vulnerability scanning is performed regularly across infrastructure, applications, APIs, and third-party dependencies. Findings are analysed to determine exploitability, potential business impact, and exposure, taking into account factors such as data sensitivity, access controls, and service criticality. Independent penetration testing by a CREST-approved provider is used to validate risk and identify complex attack paths.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
The service uses continuous protective monitoring to identify and respond to potential security compromises. Security-relevant events such as authentication activity, access changes, configuration updates, and system behaviour are centrally logged and monitored. Automated alerts are triggered for anomalous or suspicious activity, enabling rapid detection of potential threats. When a potential compromise is identified, incidents are triaged immediately, investigated by qualified security personnel, and escalated according to severity. Containment and remediation actions are initiated without delay, with affected customers informed where appropriate. Critical security incidents are responded to immediately, with active investigation and mitigation commencing within minutes.
Incident management type
Supplier-defined controls
Incident management approach
The service operates a formal incident management process with predefined procedures for common events such as service outages, security incidents, performance degradation, and data ingestion issues. Incidents are classified by severity and handled using documented runbooks with clear escalation paths. Users can report incidents 24x7 via a centralised, web-based service desk, where all incidents are logged, tracked, and prioritised. Incidents are triaged immediately on receipt, with progress updates provided through the ticketing system or email. For significant incidents, customers receive a formal incident report outlining the impact, root cause, actions taken, and measures implemented to prevent recurrence.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Access can be provided to Ternary with full functionality for a limited period of up to 4 weeks.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
7%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Cbd9a8b9-8430-439f-9fb5-5e4cc928f6f4
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Working conditions which promote an inclusive working environment and promote retention and progression

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@ioco.uk. Tell them what format you need. It will help if you say what assistive technology you use.