Appvia Wayfinder
A developer self-service platform: Provide self-service capabilities to Developers, ensuring secure and consistent infrastructure and application deployments on Azure, AWS and GCP.
Manage a fleet of Kubernetes Clusters, (GKE, AKS, EKS) and Helm packages with automated workload identities and package up Terraform modules for self-service with application deployment templates.
Features
- Team Workspaces: Have one place to organise your cloud
- Environment Management: Self-service deployment environments
- Application Workload Isolation: Simplified workload infrastructure
- Automated DNS and Certificates: Instantly secured application endpoints
- Cloud Resource Provisioning: Make Terraform self-service
- Troubleshooting: Resolve application issues quickly
- Test, Deploy and Isolate Data and Applications: Reduce security risks
- Self-Service Clusters: Developer-friendly Kubernetes
- Integrated Solutions: Integrate into your existing DevOps tools
- Distribute Policy: Manage self-service with policies
Benefits
- Improved Developer productivity and velocity
- Reduce deployment time and increase release frequency
- Reduce cloud spend with predictive cloud costs
- Improve application reliability with integrated troubleshooting tools
- Reduce operational costs with Kubernetes fleet management
- Improve security with automated isolated data, workloads and environments
- Reduce cloud costs with delete of unused and ephemeral environments
- Improve security with secure-by-default well-tested and validated self-service components
- Reduce operational costs through self-service capabilities for developers
- Drive consistency and standardisation across your software delivery
Pricing
£120 a unit a year
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
6 2 1 1 1 1 5 9 5 2 0 3 0 3 5
Contact
Appvia Ltd
Appvia
Telephone: 0203 488 4234
Email: info@appvia.io
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Wayfinder extends the capabilities of the Cloud vendors, GCP, Azure and AWS by providing a developer self-service experience with guardrails and baked in security.
- Cloud deployment model
- Public cloud
- Service constraints
- N/A
- System requirements
-
- You must have AWS, GCP or Azure Cloud
- You must use container software for application delivery
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
Standard plan:
P1 - 4 hours Mon-Fri 9-5pm
P2 - 1 day Mon-Fri 9-5pm
P3 - 2 days Mon-Fri 9-5pm
P4 - 5 days Mon-Fri 9-5pm
Enterprise plan:
P1 - 1 hours 24x7 365 days a year
P2 - 4 hours 24x7 365 days a year
P3 - 1 days 24x7 365 days a year
P4 - 2 days 24x7 365 days a year - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 A
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
There are two support levels:
Standard Plan
Starting at: 100 x vCPU £30,000 per annum
Increases in bulks of 100 vCPU with discounts applied
P1 - 4 hours Mon-Fri 9-5pm
P2 - 1 day Mon-Fri 9-5pm
P3 - 2 days Mon-Fri 9-5pm
P4 - 5 days Mon-Fri 9-5pm
Enterprise Plan
20% increase of the cost of standard
P1 - 1 hours 24x7 365 days a year
P2 - 4 hours 24x7 365 days a year
P3 - 1 days 24x7 365 days a year
P4 - 2 days 24x7 365 days a year - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide extensive documentation, getting started guides, how-to guides, videos and also onsite training if required at an extra cost.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
All data is owned by the customer as this is a customer installed product inside of the customers cloud account.
No data is stored by Appvia outside of general telemtry data which is anonymised and has no unique customer information in it. - End-of-contract process
-
After the contract ends, the license will expire and not renew. On expiry of the license, Wayfinder will no longer manage the resources in the Cloud and will not allow for any furhter creation, modification or management of AWS, GCP or Azure.
Resources can remain active and running, but only deletion of the resources can be performed. Any migration away from the product will be done by the customer.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Only the frontend user interface works currently on mobile devices. There are limitations to the amount of information made available to the mobile device on non-critical pieces of information.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- There is a CLI interface that is used in CI/CD workflows as well as locally by developers and platform engineers.
- Accessibility standards
- None or don’t know
- Description of accessibility
- No additional testing is performed.
- Accessibility testing
- No additional testing is performed
- API
- Yes
- What users can and can't do using the API
-
Everything in Wayfinder is API driven, this means that all interactions of all aspects of the product can be done via the API.
This can be achieved by using our CLI, (command line interface) for a better experience and applying the API objects to our authenticated API.
Users can also read our API documentation if they choose to work directly with it using a different Client outside of the supported and provided tools. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise the service:
Integration into your own IDP
Integration into your own Cloud
Users/groups
Kubernetes clusters, in-cluster helm packages and terraform cloud resources
Custom policies
Custom cloud tags
Custom workspace names
Custom DNS
Customer internal certificate managers
Custom route tables
Scaling
- Independence of resources
- This is hosted by the customer, if the installation guide is followed with our supported installation modules, then this will be setup in a scalable and reliable way. Any modification of these settings will be owned by the customer.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Telemtry data is obtained based on usage only and not specific user data. This telemtry data is:
Number of users and groups
Number of vcpus
Number of clusters/nodes
Number of environments
Number of cloud providers
Number of cloud resources
Number of packages - Reporting types
- Reports on request
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- There is an export and import feature to allow for data to be exported and imported using our CLI command.
- Data export formats
- Other
- Data import formats
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
SLAs are provided on the support service as outlined in the support area.
SLAs on the installed Wayfinder are owned by customer directly as this is installed and managed by the customer directly inside of their own cloud provider. - Approach to resilience
- Resiliency is provided by a third-party vendor i.e. AWS, GCP or Azure. The level of resiliency is dictated by the customers installation methods and how the service is chosen to be run.
- Outage reporting
- The installation of the service is owned by the customer and outages would be reported directly to Appvia via our support portal, following our support guidelines.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Through RBAC controls
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- N/A
- Information security policies and processes
- N/A
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All software is tracked as code and backed up in a cloud-run service. All releases are versioned to semantic versioning standards. Release notes are part of every release and are documented on our historically.
All code is scanned using third-party products for vulnerabilities as well as dependencies managed automatically using dependabot. - Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Continuously vulnerability assessment against several CVE lists and automated patching and upgrades.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Dedicated IDS/IPS combined with multiple layers of security
- Incident management type
- Undisclosed
- Incident management approach
-
Raise tickets through an online ticketing system.
We engineer away common issues.
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
Fighting climate changeFighting climate change
Wayfinder provides ways for teams to operate the cloud in a more sustainable way. By providing product and developer teams with a way of reducing their overall carbon footprint by giving teams way to right size infrastructure, turn off environments when not needed as well as deleting infrastructure that is not being used automatically.
Pricing
- Price
- £120 a unit a year
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Includes all features from enterprise version, but limited to 3 clusters and 50 vCPUs.
- Link to free trial
- https://portal.appvia.io/trial?utm_source=gcloud