Skip to main content

Help us improve the Digital Marketplace - send your feedback

EXPONENTIAL-E LIMITED

Hybrid Cloud Infrastructure as a Service (IaaS)

Exponential-e provide Hybrid Cloud IaaS platform services to underpin your critical applications through a combination of dedicated cloud and public cloud architecture, fully integrated through high performance private networking. Management demarcation includes IaaS or PaaS.

Features

  • Enterprise Level Hardware and virtualisation software
  • Geographically diverse locations (UK based) in Tier III datacentres
  • Automation with self-service portal
  • Microsoft Server Operating System licenses included
  • 24x7x365 service support
  • Fully Redundant architecture
  • Monitoring and Management of servers available
  • Hybrid Cloud - shared and private platforms available
  • Flexible connectivity options - SDN, VPLS, Internet
  • All Flash Storage for all virtual machines

Benefits

  • Offloading infrastructure management burden
  • Increased resilience over traditional server technology
  • Improved IT Agility - significantly reduce time to implement
  • Flexible commercial models to meet budget requirements
  • Reduce Total Cost of Ownership by flexing infrastructure spending
  • Maximised server availability over multiple UK cloud nodes
  • Improved Business Continuity and Disaster Recovery
  • Faster response times to external factors impacting your business performance
  • Enables internal IT personnel to focus on application and users

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at psbids@exponential-e.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 4 1 6 1 7 6 9 1 3 2 6 8 4 4

Contact

EXPONENTIAL-E LIMITED Kay Sugg
Telephone: 02034358835
Email: psbids@exponential-e.com

About your service

Service categories

IaaS

IaaS Compute

  • Container and serverless engine compute

Virtualised x86

  • General purpose

Accelerated

  • GPUs

Service scope

Service constraints
Planned and Emergency Works:
Exponential-e will adhere to the following maintenance windows: ‘Planned Maintenance’ means pre-planned maintenance of the infrastructure relating to the service. Planned Maintenance activity may result in periods of degradation or loss of availability. In such cases, Exponential-e will aim to provide at least 14 days’ notice via email of any planned works and shall aim to perform them between 00:00 and 06:00 GMT/BST.
‘Emergency Maintenance’ Exponential-e reserves the right to carry out emergency works at any time, without notice. Every effort shall be made to contact customers before the commencement of emergency maintenance.
System requirements
  • Management of virtual machines as an additional service
  • Anti-virus can be provided as an additional service
  • Exponential-e provided VM templates or bespoke customer templates
  • Customers can bring licenses with software assurance
  • Backup of VMs can be provided as an additional service
  • Security Operations can be provided as an additional service
Cloud deployment model
Hybrid cloud

User support

Email or online ticketing support
Yes
Support response times
P1 Target Response Time - 15 mins
P2 Target Response Time - 15 mins
P3 Target Response Time - 30 mins
P4 Target Response Time - 30 mins
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Each Infrastructure as a Service site - 99.9% Dual Site solution with replication - 99.95% target Our customers are at the heart of everything that we do; from the solutions that we sell to offering a 24x7x365 UK based Service Desk as standard, we offer our customers only the very best. Flexible and modular managed services can be layered on top of our infrastructure services, covering backup and patching through to full managed server applications. Infrastructure and network monitoring 24x7x365 through our Insight Portal. Exponential-e employees aim to exceed expectations with innovation and service. They are open and transparent in their approach to ensure that our customers are kept updated at every step of the process.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Exponential-e is able to offer managed on-boarding through a variety of technologies and techniques: • Import from Open Virtualization Format (OVF) files • Import from common hypervisor files (VMDK etc.) • Online replication tools to take an image of the source virtual machine and incrementally update it until cut-over • Application level replication (i.e. SQL mirroring, log shipping, backups etc.) • Customised Exponential-e WAN circuits (layer 2 or layer 3 as appropriate) to facilitate the above options • Internet or physical transfer of images • Synchronisation VIA Server replication The on-boarding process will be managed by Exponential-e’s dedicated Cloud Project Management team using PRINCE2 project management methodology.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
The customer may extract their application based data at any point during the contract term by self-service. At the end of the term and/or if the contract is terminated, the Service Migration provisions will apply. If customised data transportation, data extraction or full virtual machine export services are required these will be charged at the prevailing time and materials day rate listed in the pricing section below. In order to action these customised services, an off-boarding service request must be raised via the Exponential-e Service Desk and due to the fact those services have not been not included within Exponential-e’s G-Cloud catalogue entry and thus do not fall within the Framework Agreement and Call Off Agreement, Exponential-e’s standard terms and conditions for professional services would apply.
End-of-contract process
At the end of contract, customers will be able to export their data. At the point of termination, all customer data, accounts and access will be permanently deleted, and will not be able to be subsequently recovered or restored.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Using the web interface
The Exponential-e shared IaaS is built on VMware vCloud Director (vCD), which includes a RESTful API interface to enable programmatic access and management of virtual assets. The extensive API list can be used to undertake many common activities, such creating/power up/power down machines and clone machines.
Web interface accessibility standard
WCAG 2.2 AAA
Web interface accessibility testing
Details available on request.
API
Yes
What users can and can't do using the API
The Exponential-e shared IaaS is built on VMware vCloud Director (vCD), which includes a RESTful API interface to enable programmatic access and management of virtual assets. The extensive API list can be used to undertake many common activities, such creating/power up/power down machines and clone machines.
API automation tools
  • Chef
  • Puppet
API documentation
Yes
API documentation formats
  • HTML
  • PDF
Command line interface
No

Scaling

Independence of resources
Our platform is fully capacity managed with pre-defined thresholds to initiate additional scaling at compute and storage layers, whilst complying with virtualisation best practises such as not contending RAM. We also offer dedicated clouds and reservation clusters to ensure requirements are fine tuned to customers requirements for isolation and performance guarantees.
Usage notifications
No

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • CPU
  • Disk
  • Memory
  • Network
  • Number of active instances
Reporting types
Regular reports
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Backup and recovery

What’s backed up
  • Virtual machines
  • Folders and Files
  • Mail Servers
  • Application servers
  • Databases
  • Microsoft 365
  • Sharepoint Online
Backup controls
Users have access to full backup and restoration functionality via a console or web interface. Please see our Cloud Online Backup service description for more information.
Datacentre setup
Multiple datacentres with disaster recovery
Scheduling backups
Users schedule backups through a web interface
Backup recovery
  • Users can recover backups themselves, for example through a web interface
  • Users contact the support team
Backup and recovery
Yes
RPO/RTO
No

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)

Availability and resilience

Guaranteed availability
Availability is calculated on a calendar monthly basis using a 730 hour month. Each shared IaaS platform is provided with a 99.9% availability SLA. Replicated and HA VMs will target 99.95% availability. The Service Credit is applied as a percentage of the IaaS Platform Monthly Charge for the HA-VMs and Replicated VMs that are Unavailable (calculated on a pro-rata basis). Monthly Charge is the Annual Charge divided by 12. > 0.01 Below required level 5%> 0.1 Below required level 10% > 0.5 Below required level 15%
Approach to resilience
We leverage multiple minimum-Tier III grade UK data centres with all services designed on fully redundant physical architecture. Combined with our backup and replication technologies, customers can achieve maximised availability and service resilience.
Outage reporting
Service report outages are reported in real-time via: - a customer dashboard - email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Details available on request
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Devices users manage the service through
  • Dedicated device on a segregated network (providers own provision)
  • Dedicated device on a government network (for example PSN)
  • Dedicated device over multiple services or networks
  • Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
  • Directly from any device which may also be used for normal business (for example web browsing or viewing external email)

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users receive audit information on a regular basis
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Exponential-e operates an ITIL standards service desk and change management process, ensuring that all changes are reviewed and approved by appropriate level prior to implementation. Customers are notified of change activity initiated by Exponential-e, while customers nominate a change approver for customer-initiated requirements.

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Details available on request.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Details available on request.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Details available on request
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Exponential-e’s Incident Management process is integrated into its ISO9001 and ISO20000-1 accredited framework. Pre-defined procedures address common events, with examples including automated scripts for capacity-related issues. Incidents are reported by users via email, phone, or ServiceNow, which generates a tracking number for efficient handling and prioritisation. These incidents are logged, allocated to appropriate teams, and resolved based on their urgency and impact. Incident updates are provided regularly, with detailed reports shared for major incidents. Post-resolution evaluations ensure continuous improvement, supported by root cause analyses and formal Reason for Outage reports.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Supplier
Virtualisation technologies used
VMware
How shared infrastructure is kept separate
Description provided on request

Energy efficiency

Energy-efficient datacentres
Yes
Description of energy efficient datacentres
All our Data Centres are ISO14001 accredited organisations with robust environmental management systems • Procuring consumed energy from sustainable energy sources wherever possible • Ensuring the use of hot/cold aisle cooling design in our Data Centres, which reduces energy consumption as the cooling is more efficient and helps our customers to reduce their carbon footprint

Pricing

Discount for educational organisations
No
Free trial available
No

Discount

Provide your minimum discount applicable to your baseline prices
5%

Formula for calculating price of your services

Formula for calculating price of your services

Which of the core deployment models you intend to offer

Private Cloud

Private Cloud - Formula for calculating price of your services


Total Cost
The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
=
Baseline Pricing
Baseline Pricing for these services will be found under the G-Cloud Service Lines, within the Pricing Document.

The applicable price point is determined by factors such as required performance levels, availability requirements, data protection, and scale.

This pricing approach allows buyers to clearly understand entry-level costs while retaining flexibility to scale performance and capacity in line with workload demands. All pricing assumptions and variables will be clearly described to ensure buyers can accurately forecast costs and assess value for money.
-
Minimum Discounting
5%
+
Onboarding Activity
Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
+
Additional sources of cost
In addition to baseline pricing, buyers may incur additional costs depending on their existing infrastructure, data volumes, and integration requirements.

One potential cost is dedicated network connectivity. For data-intensive workloads such as digital pathology, GPU computation, or HPC environments, buyers may require enhanced or private connectivity. Where required, dedicated network services can be provided and scoped separately to meet performance, security, and availability needs. For health and care organisations, this may include connectivity via the Health and Social Care Network (HSCN).
Additional variations in the costs for licencing and compute may also apply.

Data migration may also introduce additional costs. Buyers transitioning from existing on-premises or third-party storage platforms may require support to transfer large datasets, validate data integrity, and minimise service disruption. Migration activities are scoped based on data volume, complexity, and delivery timelines and can be delivered as a professional service, including discovery, planning, execution, and post-migration validation.

In greenfield deployments, where no existing data platform is in place, data migration costs would not apply.

Additional costs may arise from optional services such as enhanced resilience, bespoke configurations, or specialist support. Any such services would be clearly defined and agreed with the buyer prior to contract commencement.
-
Additional sources of cost reduction
This model provides several opportunities for cost reduction, depending on the service configuration/scaling over time. The proposed approach uses a hybrid scale-out storage architecture, combining high-performance nodes with archive-optimised nodes to deliver a single, aggregated storage platform, enabling buyers to align costs directly with workload requirements.

A primary source of cost efficiency is the ability to balance performance and archive tiers. High-performance nodes command a higher price per GB within the defined pricing range, while archive nodes offer significantly lower-cost storage for data that is accessed less frequently. By limiting high-performance capacity to only where it is required and increasing the proportion of archive nodes, buyers can reduce the overall cost per GB.

Additional savings are achieved by reducing/removing front-end performance nodes where sustained high throughput is not necessary. The platform can operate predominantly as a scale-out archive solution, optimised for capacity rather than performance.

As service demand grows, cost efficiency is maintained by selectively expanding archive capacity rather than scaling performance uniformly. This targeted approach ensures buyers only pay for capabilities needed at each stage.

Together, these configuration options allow buyers to optimise storage environments over time, lowering unit costs while retaining flexibility and performance appropriately.

Mandatory certifications

Mandatory certifications

Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure

Sole Control of the Infrastructure

ISO 9001 certification

Provided

ISO 14001 certification

Provided

ISO 27001 certification

Provided

ISO 20000-1 certification

Provided

ISO 27017 certification

Provided

Are you bidding to provide services under Lot 1b or both Lot 1a and Lot 1b?

No

Cyber Essentials

Do you have a Cyber Essentials Plus certificate?
Yes
Cyber Essentials Plus certificate Number
5dd79cac-9d43-47c5-89dc-7942d72666ee

Non-mandatory Standards and certifications

ISO 28000:2022 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Saturday 13 April 2024
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
N/a
PCI certification
Yes
Who accredited the PCI DSS certification
PCI Security Standards Council
PCI DSS accreditation date
Friday 30 January 2026
What the PCI DSS doesn’t cover
Not applicable.
Other security certifications
Yes
Any other security certifications
  • HSCN CN-SP Stage 2
  • SOC Type 1 & 2
  • ISO 27017

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at psbids@exponential-e.com. Tell them what format you need. It will help if you say what assistive technology you use.