Cloudhouse Guardian - Subscription Licensing
Guardian provides technology estate visibility enabling automated Change Enablement agnostic of on-premise, cloud or hybrid combination. Guardian can monitor configurations on many categories of IT Assets including Windows & Linux Servers, Desktops, Network Devices, Databases, Cloud Platforms and SAAS solutions. See your technology estate, understand and reconcile Change within it.
Features
- Detect Misconfiguration across devices and digital assets
- Manage configuration state and monitor configuration drift
- Define and monitor organisation custom policies against digital assets
- Benchmark assets against the Centre for Internet Security Standards
- Assure Compliance against organisation policies, standards
- Process Auditing of operations and actions against digital assets
- Change Management Auto Reconciliation
Benefits
- Detect misconfigurations against policies and standards
- Provide Compliance and hardening reports against digital assets
- Audit change management process across digital assets
- Automatically generate incident tickets against configuration and policy failures
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 0 0 2 5 4 4 4 6 8 9 2 3 5 4
Contact
CLOUDHOUSE TECHNOLOGIES LTD
Nelem Kumari
Telephone: +44 (0)7801 323 540
Email: management@cloudhouse.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Guardian integrates with Service Now creating incidents and on resolution auto reconciling changes against tickets.
Guardian integrates and can create tickets in Jira.
Supports Slack for notifications. - Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
-
- SaaS Appliance runs on GCP, Azure, AWS or on Premise
- Local connection manager VM machine required within client network
- Monitored Digital assets require connection to local connection manager
User support
- Email or online ticketing support
- Yes
- Support response times
- Same day
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support & Maintenance of the product is provided as part of the SaaS licence. SLA's Sev 1 Response 1 hour, Resolution 3 days, Sev 2, Response 1 day, Resolution 10 days, Sev 3, Response 3 days, Resolution 1 month, Sev 4, Response 5 days, Resolution 3 months. We will provide a named account manager and a named support contact.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We would run a deployment engagement to support the user onboarding and deploying the product. Thereafter we would provide training, support and account management for the customer.
There is an on-line documentation system: https://help.cloudhouse.com - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- At the end of contract the customers appliance instance and it's associated services will be securely deleted. The customer can request a data export if required. We will confirm that this process has been completed and issue a deletion certificate.
- End-of-contract process
- At the end of the contract we will remove the Clients Instance. We hold the data for 30 days before deletion. Guardian is priced on a per node basis, where a node is a digital asset. Nodes are licensed on an annual subscription basis. The node licence cost include support & maintenance of the Guardian application. There is an additional Professional Services charge for the kick start project (circa 10 days). This and additional consultancy is charged at a standard day rate.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- N/A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
Web based GUI
See the following documentation
https://help.cloudhouse.com - Accessibility standards
- None or don’t know
- Description of accessibility
- Standard Web browser interface
- Accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
-
Please see details of the API here
https://guardian-docs.cloudhouse.com/p/Content/Guardian/API/The%20Guardian%20API.htm
All GUI functionality is available via the API - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- It is expected that the services will be configured against the clients digital assets. Assets will be Grouped and Reported as per the client's operational and organisations requirement. Client specific Policies will be created and applied across the digital estate as required by the Enterprise and its operations, security and compliance policies and procedures. We can change the customer Logo and Logon Message
Scaling
- Independence of resources
- The SaaS platform is deployed within a cloud‑native environment designed for elastic scaling. Customer data is segregated using dedicated data sinks, ensuring strict independence of resources and no cross‑tenant data access.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Node Licence usage is monitored and report as required to customer to ensure compliance with the Subscription agreement.
- Reporting types
-
- API access
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Guardian supports integration and extraction of data into other products and services, via it's API, and REST Endpoint Integration model, for example to Slack, Email, Jira, Service Now.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Import from Active Directory
- CMDB's
- Import from ServiceNow, Azure, AWS, GCP
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Primary availability is derived from the availability of GCP and Azure.
Cloudhouse shall use commercially reasonable endeavours to make the Hosting Services available to Customer as described in the Subscription Services, on a “as is” and “as available” basis without any representations, warranties, or covenants of any kind whatsoever on behalf of Cloudhouse, as provided by the Third Party Provider and subject to the Third Party Terms. - Approach to resilience
- This information is available on request.
- Outage reporting
- Via email or support integration service if this has been defined and implemented for the customer, e.g. Slack
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Guardian has a role based access hierarchy.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security Governance is managed by the Head of Engineering, and the CTO/CEO is the responsible owner. We are ISO9001 accredited and Section 8.9 of this Standard Data Privacy and Security forms our Governance Framework in our Quality Management System.
- Information security policies and processes
-
Our ISP covers: Organisational Security, Functional Responsibilities, Separation of Duties, Information Risk Management, Information Classification and Handling, IT Asset Management, Personnel Security, Cyber Incident Management, Physical and Environmental Security, Account Management and Access Control, Systems Security, Collaborative Computing Devices, Vulnerability Management, Operational Security.
The Security Team reports to the Head of Engineering, who reports to the CTO. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Changes to components are managed through our development and release process. Artefacts are promoted through an automated build chain, including security scanning and analysis.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We use MS 365 defender and Google security posture to analyse IT systems for vulnerabilities. Our patch SLA's: Critical Severity 3 days, High Severity 2 weeks.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Microsoft Defender EndPoint and other event sources aggregated to a Sentinal SIEM with a 24x7 managed detection and response service.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
We have a fully defined incident management process.
User report incidents via email, slack, phone or web portal.
Reports are provided via email. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
Included is the provision of a fully enabled and functional Guardian trial instance.
Not included is the conversion of trial instances into proof of concept (POC) or production environments. Also broader changes to Guardian outside of the trial experience are not included.
Trial duration initially set to 7 days. - Link to free trial
- https://trial.getguardian.io/users/register
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI Assurance UK Limited
- ISO 9001 accreditation date
- Saturday 22 March 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-