Connectivity Hub (Cloud Connectivity Aggregation) - CoreGov
“Core’s Connectivity Hub provides a resilient, dual‑datacentre cloud aggregation platform for ExpressRoute, Direct Connect and other dedicated links. Sites connect through VPN, MPLS or private circuits to gain secure, standardised multi‑cloud access with scalable throughput from sub‑gigabit to multi‑gigabit capacity, removing the need for individual dedicated circuits at each location
Features
- Centralised aggregation of dedicated multi‑cloud connectivity circuits.
- Dual‑datacentre, high‑availability cloud connectivity platform.
- Supports VPN, MPLS and private site‑to‑hub connections.
- Software‑defined routing and traffic management controls.
- Unified access to Azure, AWS, and major cloud platforms.
- Scalable bandwidth options from hundreds of Mb to multi‑Gb.
- Segmented, policy‑driven security for all connected sites.
- Encrypted site‑to‑hub connections using industry‑standard protocols.
- Continuous monitoring with performance and availability insights.
- Rapid onboarding without per‑site dedicated circuit deployment.
Benefits
- Reduce connectivity costs through shared, centralised cloud circuits.
- Improve resilience with dual‑site high‑availability design.
- Simplify multi‑site cloud access through one aggregated hub.
- Strengthen security with centralised, consistent policy enforcement.
- Accelerate onboarding of new or temporary locations.
- Enable cloud portability without re‑engineering networks.
- Enhance performance with predictable, private cloud connectivity.
- Reduce operational overhead through software‑defined management.
- Support hybrid and multi‑cloud strategies effortlessly.
- Gain clear visibility through unified performance reporting.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 3 8 5 9 8 4 4 0 8 4 7 6 9 5
Contact
CORE TECHNOLOGY SYSTEMS (U.K.) LIMITED
Paul Saer
Telephone: +44 (0) 207 626 0516
Email: tenders@core.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Network
Network infrastructure software
- Software-defined networking (SDN)
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- The service depends on third‑party connectivity and datacentre providers, whose availability, performance and security are outside Core’s direct control. Customer sites must support approved IPsec, MPLS or private‑link configurations, and conflicting network ranges may prevent onboarding. The Hub uses fixed underlying hardware (e.g., SonicWall firewalls, Dell switches) which cannot be altered by buyers. Planned maintenance, firmware updates and vendor patching may require scheduled downtime. Service improvements or changes involving carrier networks or cloud providers may require third‑party coordination. Local customer infrastructure must meet required technical standards to ensure resilient connectivity across the dual‑datacentre platform.
- System requirements
-
- Customer firewalls must support approved IPsec VPN encryption and authentication.
- Customer networks must accept predefined Connectivity Hub IP address ranges.
- Local devices must support active–passive VPN failover configuration.
- Customer-routing must avoid NAT conflicts and prevent asymmetric traffic issues.
- MPLS or private circuits must be procured-maintained by buyer.
- Customer equipment must support required Diffie‑Hellman groups and AES encryption.
- Firewall rules must allow mandated Hub VPN and security policies.
- Customer teams must implement required routing and firewall configuration changes.
- Local bandwidth must support intended traffic volumes to the Hub.
- Customer devices must support approved IPsec gateway security characteristics.
User support
- Email or online ticketing support
- Yes
- Support response times
- Response times are dependent on the nature of the request. For Managed Services tickets, the response times for different request types are listed in the Service Description document.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Our webchat solution is configurable, allowing us to tailor the interface by enabling or disabling features for different clients. This can help simplify navigation for users who need a less cluttered interface. Security roles can be configured to limit or expand access to certain features, which can help create simpler experiences for users who might struggle with complex navigation. Users can submit tickets, access knowledge bases, and use service catalogues without direct staff interaction, which could benefit users who prefer asynchronous communication. Our platform also supports integrations with Teams, Slack, and chat applications, which may allow users to choose communication channels that work best for them.
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
- Core run an ITIL aligned Service Desk and incident management approach. All service requests can be made directly to our 24/7 ServiceDesk function. First line or Second Line technical analyst or engineers engage with all service tickets until successfully closed. All customers can also engage with a named Account Manager and Customer Success Manager. Core typically structures Managed Services into modular SKUs, allowing customers to select the level of support they need - for example Service Desk, End User Compute, Microsoft365 Support, Infrastructure Support and Azure Managed Services. All of these SKU's are individually priced and pricing is referenced in the relevant Service Definition document
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We help buyers start using the service through a structured onboarding process managed entirely by Core. Buyers provide required network details, after which Core configures and activates their connection to the Connectivity Hub. Standard onboarding packages cover VPN connections, Cloud Exchange connections and physical cross‑connects. Core guides the buyer through prerequisites, security settings, routing requirements and testing. Once the connection is validated, traffic is enabled through the Hub, allowing immediate access to cloud services via private connectivity.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Connectivity Hub does not store customer data. When the contract ends, buyers extract their data simply by redirecting traffic to their new target networks or cloud environments. Offboarding involves removing or reconfiguring VPN, MPLS or private connections rather than exporting stored data. Core provides guidance to ensure a smooth transition with no service disruption.
- End-of-contract process
- At the end of the contract, the buyer’s network traffic is redirected to their new environment and Core decommissions the Connectivity Hub connections, including VPN, Cloud EX, MPLS and Cross‑Connect links. Connectivity Hub does not store any customer data, so no data extraction is required. Buyers remain responsible for any third‑party connectivity with fixed contract terms. The price includes use of the Hub platform, Hub‑side infrastructure, monitoring, patching, vulnerability management and standard onboarding packages. Additional costs apply for cloud or carrier circuits (e.g., ExpressRoute, Direct Connect, MPLS), Cloud EX ports, bespoke onboarding or offboarding work, and any fixed‑term third‑party connection charges.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Our onboarding and offboarding documentation is provided in standard digital formats (DOCX and PDF). While these formats are widely compatible with common screen‑readers and assistive technologies, the documentation itself is not currently authored to a formal accessibility standard such as WCAG 2.1.
Alternative accessible formats (e.g., ODF, large‑print, Easy Read, HTML, audio) are not currently produced by default but may be made available on request.
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Connectivity Hub guarantees that users are not affected by demand from other users through a single‑tenant architecture, dedicated per‑tenant bandwidth, and multi‑terabit backbone capacity. Traffic is isolated using separate routing domains, firewalls, and policies. The platform’s scale‑out design and continuous performance monitoring ensure that no customer’s usage can reduce another’s bandwidth or service quality.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Yes. Core provides service usage metrics in the form of operational reporting, including bandwidth utilisation, service health and performance monitoring. These metrics are delivered through regular managed service reports rather than through a customer-facing dashboard. The Connectivity Hub operates at network level, so no per-user usage analytics are generated.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Connectivity Hub primarily processes data in transit and does not store customer content at rest. Any system-level data that is retained, such as logs, configuration data, and authentication material, is encrypted at rest using industry-standard AES‑256 encryption, consistent with Core’s ISO 27001–aligned security framework.
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Connectivity Hub does not store customer data. Users do not need to export any data when the contract ends. Instead, buyers simply redirect their network traffic to their new target services or cloud environments. No data extraction is required, as the service provides connectivity only and does not hold customer data at rest.
- Data export formats
- Other
- Other data export formats
- N/a
- Data import formats
-
- CSV
- Other
- Other data import formats
- N/a
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- Data between the buyer’s network and the Connectivity Hub is protected using encrypted IPsec VPN tunnels, CPA‑aligned gateway security, and dedicated firewall appliances. All traffic is encrypted using approved algorithms (AES‑128/AES‑256) and terminated on secure, isolated firewall infrastructure. Where private circuits are used, traffic avoids the public internet entirely and remains protected by strict routing and segmentation controls.
- Data protection within supplier network
- Other
- Other protection within supplier network
- Data within the Connectivity Hub is protected using a multi‑layer security architecture. Traffic is secured through deep packet inspection, stateful firewalling, and IPS/IDS threat detection provided by SonicWALL NSA and SuperMassive appliances. All tenants are isolated using segregated routing and firewall policies. The Hub is hosted in secure Tier‑1 datacentres and maintained with continuous patching, vulnerability management and hardware refresh cycles. This ensures all internal Hub traffic remains encrypted where possible, inspected where necessary, and protected from unauthorised access or movement.
Availability and resilience
- Guaranteed availability
-
The Connectivity Hub service is built with high resilience across multiple datacentres, enabling us to guarantee 99.95% availability each month. This ensures that customer traffic can always be routed through at least one of the platform’s redundant paths. If availability drops below the guaranteed level, customers are automatically entitled to a service credit equal to one average Service Day, calculated from the month’s Daily Charges.
In addition to platform availability, the service includes strict response and resolution commitments for incidents. Severity 1 issues require a rapid response—typically within one hour—and resolution within four hours, with further service credits applied if these targets are not met. This SLA structure is designed to deliver operational reliability while protecting customers if service levels fall short. Overall, the Connectivity Hub blends high‑availability architecture with clear, measurable financial remedies to ensure consistent performance and transparency. - Approach to resilience
-
The Connectivity Hub is designed with strong, built‑in resilience to ensure continuous, uninterrupted service. It operates across two geographically separate Tier 1 Equinix datacentres—London Docklands (LD8) and Slough (LD6)—providing geographic redundancy and business continuity. If one site becomes unavailable, the other continues to operate without impacting service.
The platform uses active/active architecture, multiple redundant firewall clusters, and as many as eight available traffic paths, meaning network traffic can always be routed through a healthy path. Automated monitoring via ICMP and SNMP probes detects any component failure instantly, triggering proactive incident handling.
Because every major element of the design has a failover counterpart, the service avoids partial outages: issues either have no impact or automatically reroute to maintain continuity. This resilient multi‑layer design underpins the service’s ability to meet its 99.95% availability guarantee, even during hardware, link, or site‑specific failures. - Outage reporting
- The Connectivity Hub includes fully automated outage detection and incident reporting as part of its managed service. All core components are continuously monitored using ICMP and SNMP probes via an out‑of‑band management platform. If any device or service becomes unresponsive, an automated alert is immediately generated and a ticket is raised within the Core Service Desk. Outages are categorised as either service‑affecting (P1) or non‑service‑affecting (P4), with P1 incidents automatically escalated to the customer’s Incident Management function, where Core participates in the major incident process until resolution. Internally, engineering teams make use of real‑time dashboards provided by the underlying firewall and analytics platforms, including up/down status timelines, flow activity views, and log analysis tools, enabling rapid diagnosis and response. However, there is no public‑facing status dashboard, API, or customer‑subscribed email alerting mechanism. All outage notifications are delivered through the established Service Desk process to ensure consistent tracking, reporting, and communication. This approach ensures customers receive timely and accountable updates while maintaining operational visibility through Core’s managed service processes
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Other
- Other user authentication
- Users must be authenticated to access the service. Connectivity to the platform is only permitted through authenticated IPsec VPN connections, ensuring that all organisations, devices, and partners establish a secure, validated session before any traffic is routed. The service supports industry‑standard authentication methods, including IKEv1 and IKEv2, and only authorised, pre‑configured networks are able to connect. In line with wider identity services, authentication can also be integrated with Microsoft‑based identity platforms such as ADFS or Azure AD, enabling organisations to apply MFA and Conditional Access policies where required. Anonymous or unauthenticated access is not supported in the service design.
- Access restrictions in management interfaces and support channels
- Access to management interfaces is tightly restricted through role‑based access control, ensuring only authorised personnel can perform administrative actions. Privileged access is granted on a least‑privilege basis and enforced through Microsoft Entra ID and Conditional Access policies. Support channels are also controlled: users must authenticate via approved Service Desk routes, and identity is verified before any action is taken. Core’s ISO 27001‑aligned Service Desk operates defined procedures and audit trails to ensure that all administrative and support access is secure, permission‑based, and fully traceable.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Other
- Description of management access authentication
- Management access is protected through privileged identity controls and strict authentication requirements. Administrative users are never permitted to use their normal day‑to‑day accounts for privileged operations; instead, they must authenticate using dedicated administrator identities (“a‑accounts”). These accounts are subject to enforced Multi‑Factor Authentication (MFA) and Conditional Access policies, including restrictions to known, corporately‑issued devices. This ensures that access is only granted from trusted identities and secure endpoints
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Core operates a fully ISO 27001‑certified Information Security Management System (ISMS), supported by formal policies covering confidentiality, integrity, availability, access control, incident management, risk assessment, business continuity and supplier management. All employees receive mandatory security awareness training, with additional specialist training for staff in sensitive roles. Security responsibilities are defined in job descriptions and contracts, and policy breaches are managed under our disciplinary process.
The ISMS is overseen by a dedicated Information Security Steering Group chaired by the COO and supported by the CISO, IT Manager and senior risk specialists. Policies are reviewed at least annually and continuously improved through internal audits, external ISO 27001 surveillance audits, risk assessments and automated compliance monitoring. Staff are required to report security incidents or weaknesses immediately via documented procedures. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Core operates ITIL‑aligned configuration and change management processes, benchmarked at CMM Level 3–4. Configuration items are tracked throughout their lifecycle using customer CMDBs, Intune, Azure and ITSM tooling, ensuring accurate, continually updated records. All changes follow a formal ITIL process, including risk and security assessment, CAB review, client approval, and full auditability. Security impact is evaluated using Microsoft native tooling (Defender, Secure Score) to ensure no adverse effect on identity, access or service integrity. All changes are documented, traceable, and aligned with customer governance.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Core operates a proactive, ITIL‑aligned vulnerability management process. Threats are continuously assessed using Microsoft Defender, Secure Score, Azure Security Centre, Sentinel SIEM and weekly Nessus scans to identify vulnerabilities and misconfigurations. We deploy critical and security patches within 14 days in line with NCSC guidance, with accelerated deployment for zero‑day threats using automated Endpoint Manager and Azure Update Management workflows. Threat intelligence is sourced from Microsoft’s security ecosystem, Tenable CVE feeds, NCSC advisories and SIEM‑driven correlation, ensuring rapid awareness and remediation of emerging risks.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Core delivers continuous protective monitoring using Microsoft Sentinel SIEM, Defender for Endpoint/Servers, and Azure Defender to identify potential compromises through behavioural analytics, real‑time alerting, threat intelligence and proactive threat hunting. When a potential compromise is detected, alerts are triaged by our security operations processes, with automated containment actions (e.g. isolating devices, disabling accounts) and escalation to our engineers. Incident response follows predefined playbooks and documented communication paths. Core provides rapid response, with 24/7 monitoring and immediate triage, and P1 security incidents responded to within minutes via Sentinel‑driven alerting.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Core operates ITIL‑aligned incident management with predefined processes for common events, including a full Major Incident Management (MIM) workflow covering P1 and P2 incidents. Users report incidents via phone, email, or the self‑service portal, or incidents may be auto‑raised through monitoring. When an incident is logged, it is triaged, prioritised, and assigned, with automated notifications and, for P1s, initiation of a live bridging call and stakeholder communications. Response times follow strict SLAs, including 30‑minute response for P1 incidents. We issue formal incident reports for all major incidents.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Other
- Other public sector networks
- The service connects to departmental MPLS networks
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau (part of the Amtivo Group)
- ISO/IEC 27001 accreditation date
- Thursday 27 February 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ad9ffc7a-28e4-460b-bccb-fc914b3420df
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 13867168-d605-4ed3-9481-13e21f4ae9bc
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-