Guided Cloud Cost Optimisation & Resale
Multi-Cloud resale, FinOps cost management and optimisation for Amazon Web Service (AWS), Google Cloud (GCP), Microsoft Azure, IBM Cloud and other cloud vendors. Spend visibility and governance. Ability to prepay for future services. Zero fee.
Features
- Cloud purchasing, cost management, cost governance and cost optimisation
- Access discounts not available from cloud providers direct
- Free, no service fee
- Maintain existing technical service delivery relationships
- Compatible with the One Government Value Agreement and AWS Marketplace
- Secure, requiring non-intrusive access to cost and usage meta-data only
- Multiple clouds with a single invoice
- Requires no technical changes to cloud usage
- All cloud usage ownership remains with the customer
- Potentially extendable to neo-cloud vendors upon request
Benefits
- Optimised cloud spend on terms that suit you
- Simplified, understandable cloud billing and purchasing
- Access to independent cloud billing experts
- Greater insight in cloud usage and cloud spend
- Maintain existing technical service delivery relationships
- Contractual terms to buy cloud the way that suits you
- Supports EDP and private pricing agreements
- Reinvest savings in further innovation
- Strategic Blue Account Manager available for support
- Access to FinOps Consultants for wider cloud financial management support
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 0 0 8 9 3 0 4 2 1 7 9 5 1 0
Contact
STRATEGIC BLUE SERVICES LIMITED
Freya Harland
Telephone: 0736 0498154
Email: support@strategic-blue.com
About your service
- Service categories
-
Systems Infrastructure Software
Cloud Financial Management
- Cloud Financial Management (FinOps)
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No constraints
- System requirements
- Multi-cloud service
User support
- Email or online ticketing support
- Yes
- Support response times
-
General Strategic Blue invoice support tickets are answered within 48 hours, Monday to Friday.
AWS Support case response time depends on severity. The support response times for Business+ or Enterprise Support tiers are available at https://aws.amazon.com/premiumsupport/compare-plans/ - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Webchat is provided via a Slack channel.
https://slack.com/intl/en-gb/accessibility-plan - Onsite support
- No
- Support levels
-
Technical support for your cloud is provided via the relevant cloud provider, customers can select the level of support that they require. Basic, Business plus, or Enterprise.
Strategic Blue provides support for billing and invoicing questions and cost optimisation support. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Our team will guide you through the best onboarding approach for you, depending on which of our supported cloud you use. AWS, Google, are our primary service, but other clouds vendors are available on request. We will become your reseller to manage your AWS invoicing and payment processes. This does not impact the ownership of your individual usage accounts or data.
We will implement best practice Role Based Access Control to keep our access separate from your usage. As detailed in our Service Description, this enables us to securely control and manage the access needed to deliver our service. - Service documentation
- Yes
- Documentation formats
-
- ODF
- End-of-contract data extraction
-
Customers retain ownership of their data throughout the contract, and simply provide access to Strategic Blue to view their cost and usage information.
At the end of the contract that access is revoked by the customer by reversing the onboarding process.
Historic billing data is retained to answer tax or invoicing queries, and is available upon request. - End-of-contract process
-
At the end of the contract the customer can remove Strategic Blue access to the billing information and a final invoice will be issued. The customer's billing will then be managed directly by the cloud vendor, customer or to another supplier.
There is no additional off-boarding cost at the end of the contract.
A detailed customer and vendor-specific off-boarding process document will be provided as part of the service. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
PrePay is an optional additional service to simplify billing and cloud cost tracking
we support multiple cloud cost visibility options to meet customer needs
Scaling
- Independence of resources
-
Our service is predominantly for contracting and billing, and is independent of customer usage. Our services are cloud-native and can scale as the business grows.
We can provide spend alerts to customers if their cloud usage is predicted to be significantly higher than an agreed baseline.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- AWS, Azure, Google Cloud, IBM Cloud
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Customers will automatically retain access to their data, so no export required
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Availability of cloud services is provided by highly available services from the cloud vendors across multiple datacentres and regions.
Specific SLAs will depend on the support level purchased - Approach to resilience
- Strategic Blue services are cloud-native and highly resilient across multiple availability zones.
- Outage reporting
- Each Cloud vendor provides a service health web page
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- Secure access to our portal via username and MFA. Access to cloud services is managed by the customer to ensure security is suitable for the task.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials and CSA STAR
- Information security policies and processes
-
Strategic Blue has implemented an ISO9001 , 14001 and ISO27001 set of formal documented policies and processes that provide guidance for operations and information security within the organisation. Policies address purpose, scope, roles, responsibilities and management commitment. CSA CCM v4 (STAR level 1) and Cyber Essentials have also been implemented.
All employees have access to the policies and have regular updates to familiarise themselves with the policies.
Leadership involvement provides clear direction and visible support for security initiatives. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Strategic Blue manages its systems through a continuous integration and deployment pipeline.
Customers are responsible for managing and deploying their configuration and change control processes. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Strategic Blue conducts periodic penetration testing against its systems to ensure they are secure.
Customers are responsible for managing vulnerability testing for their services - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Strategic Blue has processes in place, as part of ISO27001, to monitor and report on incidents and potential breaches.
Responsibility for protective monitoring of customer workloads remains with the customer - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Strategic Blue has a service management system to manage and track any incidents which occur.
Customers can submit tickets for Strategic Blue to review via email. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Monday 10 November 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing, it covers all parts of the business
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Monday 10 November 2025
- What the ISO 9001 doesn’t cover
- Nothing, it covers all parts of the business
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Tuesday 14 February 2023
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
- Nothing, it covers all parts of the business
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ecf82c78-5d5c-4909-a2dd-b36d85cda541
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
-