Ternary
Ternary is a cloud financial management (FinOps) SaaS platform that provides unified, multi-cloud cost visibility, forecasting, and cost allocation. It enables public and private sector organisations to govern cloud spend, optimise usage, support chargeback, and improve financial accountability through secure, read-only integrations and intuitive dashboards.
Features
- Multi-cloud cost ingestion (AWS, Azure, GCP, OCI, SaaS providers)
- Near real-time cost and usage reporting
- Browser-based SaaS platform with secure remote access
- Read-only integrations with cloud providers
- Role-Based Access Control (RBAC) and scoped views
- Advanced cost allocation, showback and chargeback
- Multi-currency reporting, including GBP conversion
- Budgeting, forecasting, and ramp planning for future spend modelling
- Savings and commitment tracking
- API-first architecture
Benefits
- Improves financial governance and transparency across cloud
- Enables accurate chargeback and departmental accountability
- Supports budget control and forecasting for public sector planning cycles
- Reduces cloud waste and financial risk without impacting operations
- Scales without penalty for users, accounts, or departments
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 9 9 6 3 0 3 0 9 3 0 4 2 1 3
Contact
IOCO SOLUTIONS LIMITED
Mick Morey
Telephone: 0118 206 2938
Email: sales@ioco.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
The service relies on cloud provider billing and usage exports. Near real-time visibility is subject to the update frequency and data latency of the underlying cloud providers.
Accuracy of allocation, reporting, and forecasting is dependent on the quality and consistency of cloud billing data, tags, and account structures provided by the customer. - System requirements
- An Internet connection is required to use the service
User support
- Email or online ticketing support
- Yes
- Support response times
-
Ternary is fully supported by iOCO’s 24/7 Service Desk portal. The service is available 365 days a year. Responses are prioritised and addressed in line with the service levels detailed in the Service Level Agreement document.
P1 CRITICAL, Response Time SLA 1 hour, Target Resolution Time 8 hours
P2 HIGH, Response Time SLA 3 hours, Target Resolution Time 36 hours
P3 MEDIUM, Response Time SLA 6 hours, Target Resolution Time 72 hours
P4 LOW, Response Time SLA 24 hours, Target Resolution Time N/A - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We use OpenText SMAX which is a SAAS ticketing portal conforming to accessibility standards which the vendor test against and for which they provide accessibility conformance reports available by request here: https://www.opentext.com/about/accessibility/accessibility-conformance-reports
- Onsite support
- Yes, at extra cost
- Support levels
-
IOCO provides a flexible, public-sector-aligned support model designed to ensure service continuity while allowing customers to scale support based on operational needs.
**Normal Support**, which is included as part of the base service, provides **24x7 access to a centralised service desk** via a web-based ticketing system. Customers can log incidents, service requests, and technical queries at any time, with issues triaged according to agreed severity levels. Response and resolution targets are aligned to industry best practice, ensuring critical incidents receive immediate attention while lower-priority requests are handled in a controlled and auditable manner. This model supports day-to-day operations and provides full visibility through tracked tickets and escalation workflows.
**Premium Support** is available as an optional enhancement through a **Call-off Service Agreement**. This model is based on **pre-purchased service credits**, valid for a 12-month period, which customers can consume flexibly according to their requirements and subject to iOCO resource availability. Premium Support provides priority handling of incidents, accelerated response times, access to senior engineering resources, and proactive advisory support. It is particularly suited to customers with variable demand, complex environments, or time-critical workloads. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We will provide handholding throughout the duration of onboarding in order to make the setup and time to productivity as short as possible.
An initial introductory training session will be provided and can be supplemented by further bespoke training tailored to your needs.
Online tutorials are available as well as and extensive documentation on the website. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
When the contract ends, users retain full control over their data and can extract it using standard, documented methods.
Users can export reports and datasets directly from the service in common, open formats such as CSV and JSON, enabling continued analysis or migration to another platform. All configured reports, dashboards, and financial views can be extracted prior to termination.
In addition, users can use the REST API to programmatically extract reporting outputs and configuration data, including custom labels, budgets, and cost allocation rules, allowing these settings to be retained or recreated elsewhere.
The underlying cloud billing and usage data remains the property of the customer and continues to reside with the original cloud providers. At the end of the contract, user access to the service is removed and the customer tenant is securely deleted in line with documented data retention and disposal processes. - End-of-contract process
- Customer access to the service is withdrawn at the contract end date. Users are given the opportunity to export reports, datasets, and configuration information (such as cost allocation rules, budgets, and custom labels) using the user interface or API. The customer’s tenant is then securely decommissioned and all platform-resident data is permanently deleted in line with documented data retention and disposal policies. The customer’s original cloud billing and usage data remains with the relevant cloud providers at all times.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- The documentation is available through our public website https://docs.ternary.app/docs/home
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
The service is delivered through a secure, browser-based web interface.
The interface provides users with access to dashboards, reports, configuration settings, and administrative functions without requiring any local software installation. Access is available remotely via standard web browsers using encrypted HTTPS connections, with support for role-based access control and optional Single Sign-On.
In addition to the web interface, the service also exposes a documented REST API, allowing programmatic access for configuration, reporting, and integration with external systems such as finance, billing, or reporting platforms. - Accessibility standards
- None or don’t know
- Description of accessibility
-
The service is delivered through a browser-based web interface that supports standard accessibility features available in modern browsers and operating systems. Users can navigate core functions using a keyboard, apply browser zoom and screen magnification, and access content using browser-native screen readers. Reports can be exported for offline use with assistive tools, and Single Sign-On reduces authentication barriers.
The service is optimised for desktop use and does not currently hold formal WCAG or VPAT certification. Some complex, data-dense visualisations may be challenging for screen-reader users. Accessibility issues can be reported and are reviewed for ongoing improvement. - Accessibility testing
-
Ternary has not completed formal, third-party certified accessibility testing (such as a full WCAG 2.2 audit or VPAT) specifically with users of assistive technologies.
However, accessibility considerations are incorporated into the platform’s design, development, and testing practices, and the service is built using modern web standards that are compatible with commonly used assistive technologies. - API
- Yes
- What users can and can't do using the API
-
The service provides a secure REST API that allows users to configure and manage most aspects of the platform programmatically. Users can set up the service by creating users, roles, permissions, cloud subscriptions, budgets, custom labels, and cost allocation rules. Ongoing changes, including updates to access controls, financial rules, and reporting data exports, can also be made through the API.
The API is read-only with respect to customer cloud infrastructure and billing source data, and cannot perform operational actions or control visual dashboard layouts. Access is permission-based, secured with API keys, and subject to rate limits and security controls. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
The service is designed to be highly configurable so organisations can align it to their financial governance, reporting, and operational requirements without changing underlying cloud infrastructure.
This includes user access and permissions through role-based access control, scoped views that limit data visibility, cost allocation rules for showback and chargeback, and custom labels to enhance or replace cloud-native tagging. Users can also configure budgets, forecasts, ramp plans, currency settings, dashboards, saved reports, and data exports. API integrations can be tailored to support finance, billing, and reporting workflows.
Most configuration is performed through the browser-based user interface, allowing interactive setup and immediate feedback. For automation and repeatability, the service also exposes a REST API that enables configuration-as-code, bulk updates, and integration with external systems. All customisation is applied within the platform’s reporting and governance layer and does not impact live cloud workloads.
Who can customise the service is governed by role-based permissions. Administrators have full control over users, financial rules, and integrations. Finance and FinOps users can manage budgets, allocations, forecasting, and reporting. Read-only users can view dashboards and reports but cannot make changes. This ensures strong governance, auditability, and separation of duties.
Scaling
- Independence of resources
- The service ensures users are not affected by other customers’ demand through logical tenant isolation and elastic cloud architecture. Each customer operates in a securely segregated tenant, preventing cross-tenant access or resource contention. The platform runs on auto-scaling, serverless cloud services that dynamically adjust capacity to meet demand, ensuring consistent performance during peak usage. Resource governance controls, including API rate limiting and workload management, prevent individual users from monopolising shared resources. Continuous monitoring is used to detect and manage abnormal usage patterns. Together, these measures provide predictable performance and protect service availability for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Ternary provides a comprehensive set of service usage and financial metrics through its platform.
The service exposes metrics such as cloud spend over time (daily, monthly, yearly), usage trends by service, account, project, or cost centre, budget consumption and forecast variance, cost allocation and chargeback results, savings from commitments (for example Reserved Instances and Savings Plans), and anomaly detection indicators.
Metrics are available via interactive dashboards and reports, can be filtered and segmented by multiple dimensions, and can be exported in open formats (CSV/JSON) or accessed programmatically via the API for integration with external reporting or monitoring systems. - Reporting types
-
- API access
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Ternary
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
-
Users can export their data using standard, self-service methods provided by the platform.
Data can be exported directly through the browser-based user interface, where users can download reports and datasets in common, open formats such as CSV and JSON. This allows data to be reused in spreadsheets, finance systems, or other reporting tools.
For automated or large-scale extraction, users can export data through the REST API, which supports programmatic access to reporting outputs and configuration data, including budgets, custom labels, and cost allocation rules. API exports are authenticated, permission-based, and suitable for integration with external systems. - Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- AWS Cost and Usage Reports (CUR)
- Azure billing exports
- Google Cloud billing exports
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is delivered with a clear and measurable availability commitment designed to meet public sector expectations for reliability and transparency. Ternary provides a 99.9% monthly availability target for its core SaaS platform, covering both the web-based user interface and API access. Availability is measured on a calendar-month basis and excludes planned maintenance windows, which are scheduled during low-usage periods where possible and communicated to customers in advance.
The platform is hosted on resilient, auto-scaling cloud infrastructure engineered to minimise single points of failure and support rapid recovery in the event of an incident. Availability is continuously monitored, and any service-impacting incidents are actively managed through the support process with regular updates provided to affected users.
A formal Service Level Agreement underpins this commitment. If the guaranteed availability level is not met, customers are entitled to service credits applied to the subsequent billing period. Credits are calculated as a percentage of the affected monthly subscription fee, increasing as availability decreases. These service credits provide a clear, contractual remedy for availability breaches and are designed to be fair, transparent, and auditable. - Approach to resilience
- Available on request
- Outage reporting
-
Service status information is instead communicated directly to affected customers to avoid ambiguity and ensure accurate, contextual updates.
For incidents impacting service availability or performance, email notifications are issued to affected customers. These notifications include:
Confirmation of the incident
Scope and impact
Initial assessment and mitigation steps
Ongoing progress updates
Post-incident resolution and summary where appropriate
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using strong identity and access controls. The service enforces role-based access control, ensuring users can only perform actions and view data appropriate to their role and tenant. Authentication is secured through usernames and passwords or Single Sign-On with customer identity providers, with Multi-Factor Authentication supported. Administrative actions and access events are logged and monitored. Support channels require authenticated users to raise tickets, and support staff access is limited to the minimum required to resolve issues. Elevated access is controlled, time-bound, approved, and fully audited.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- SOC 2 Type II certification
- Information security policies and processes
-
Ternary’s security governance is underpinned by a SOC 2 Type II certification, which provides independent assurance over the design and operating effectiveness of its security controls over time. This certification covers key trust principles including security, availability, and confidentiality, and is reviewed regularly by an external auditor.
Security governance is managed through documented policies and procedures covering risk management, access control, data protection, incident response, change management, and vendor management. A senior leadership-led Risk Committee provides oversight of security risks, ensuring accountability at an executive level. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- The service uses formal configuration and change management processes to control and track all components throughout their lifecycle. Infrastructure, application code, and configuration are managed using version-controlled repositories and Infrastructure as Code, providing full traceability from development through to production and decommissioning. Separate development, staging, and production environments prevent untested changes from reaching live services. All changes are assessed through a structured change process aligned to SOC 2 and ITIL principles. Each change is reviewed for potential security impact, including effects on access control, data protection, and exposed interfaces, with approvals, testing, and audit logging enforced before deployment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Ternary uses a risk-based vulnerability management process to identify and assess potential threats to its services. Automated vulnerability scanning is performed regularly across infrastructure, applications, APIs, and third-party dependencies. Findings are analysed to determine exploitability, potential business impact, and exposure, taking into account factors such as data sensitivity, access controls, and service criticality. Independent penetration testing by a CREST-approved provider is used to validate risk and identify complex attack paths.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The service uses continuous protective monitoring to identify and respond to potential security compromises. Security-relevant events such as authentication activity, access changes, configuration updates, and system behaviour are centrally logged and monitored. Automated alerts are triggered for anomalous or suspicious activity, enabling rapid detection of potential threats. When a potential compromise is identified, incidents are triaged immediately, investigated by qualified security personnel, and escalated according to severity. Containment and remediation actions are initiated without delay, with affected customers informed where appropriate. Critical security incidents are responded to immediately, with active investigation and mitigation commencing within minutes.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The service operates a formal incident management process with predefined procedures for common events such as service outages, security incidents, performance degradation, and data ingestion issues. Incidents are classified by severity and handled using documented runbooks with clear escalation paths. Users can report incidents 24x7 via a centralised, web-based service desk, where all incidents are logged, tracked, and prioritised. Incidents are triaged immediately on receipt, with progress updates provided through the ticketing system or email. For significant incidents, customers receive a formal incident report outlining the impact, root cause, actions taken, and measures implemented to prevent recurrence.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Access can be provided to Ternary with full functionality for a limited period of up to 4 weeks.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 7%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Cbd9a8b9-8430-439f-9fb5-5e4cc928f6f4
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Working conditions which promote an inclusive working environment and promote retention and progression
-