Forrit One
Forrit is an Azure-native PaaS CMS, allowing users to leverage Azure's infrastructure and AI services, making it a future-proof, scalable solution. Forrit provides an low/no code content management experience with enterprise-grade security and localization features. Forrit’s Service Delivery Hub allows fast, scripted deployment of all the Azure services you need.
Features
- Automated configuration processes
- Full Microsoft Entra ID integration
- Consolidated dashboard
- Component Editor
- Page Builder
- Page Editor
- Popular SDK's
- Asset Library
- Headless, Composable API's
- Microsoft Translator API
Benefits
- Simplifies resource configuration processes
- Enables rapid and secure website creation
- Delivers global reach and infinite scale
- Maximises the security of your webpages
- Consolidates your web estate
- Ensures brand consistency
- Enables easy building and editing of webpages
- Allows rapid localisation
- Leverages Azure's cloud services and tools
- Delivers significant cost savings
Pricing
£1,000 a unit a month
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
6 8 3 8 8 5 8 3 2 1 0 5 4 5 5
Contact
Forrit Technology Ltd
Forrit
Telephone: 0131 460 1874
Email: enquiries@forrit.com
Service scope
- Service constraints
-
The Service has the following constraints.
Microsoft Azure Cloud platform – the Forrit One solution currently runs on Azure and Azure PaaS native services
Microsoft Azure Entra ID/AD – all Forrit One authentication/Authorisation is completed via Entra ID/Azure AD - System requirements
- Azure Tenant and subscription (Forrit can set up)
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- SLA’s are fully defined and agreed in SOW.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 AA or EN 301 549
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- SLA’s are fully defined and agreed in SOW.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Training can be provided at extra cost or as part of managed service team activities.
Online user documentation is available at https://docs.forrit.com - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- A copy of the database content is provided.
- End-of-contract process
- At the end of any contract, the Forrit One platform would continue to run within the clients subscription without service interruption. The Forrit One platform would no longer get any platform/system upgrades unless agreed previously. All client data/customisation will remain and can be used as the client requires.
Using the service
- Web browser interface
- Yes
- Using the web interface
- Users can manage their entire web estate from one location in the Forrit One CMS web interface. They can create, manage, approve and deploy content to the channels that the CMS supports.
- Web interface accessibility standard
- WCAG 2.1 AA or EN 301 549
- Web interface accessibility testing
- Web interface testing is completed on all projects and aligns to the customers accessibility standards. Testing can include manual testing, automated testing and the use of various accessibility testing tools and screen readers. E.g. Site Improve, Jaws etc.
- API
- Yes
- What users can and can't do using the API
- Users can manage their entire web estate from one location in the Forrit CMS API should they choose, the supported process is via the web interface. They can create, manage, approve and deploy content to the channels that the CMS supports.
- API automation tools
-
- Terraform
- Other
- Other API automation tools
-
- ARM
- Bicep
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- Command line interface
- No
Scaling
- Scaling available
- Yes
- Scaling type
- Automatic
- Independence of resources
- Forrit One is a PaaS service deployed into the customers Azure tenant.
- Usage notifications
- Yes
- Usage reporting
-
- SMS
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Other
- Other metrics
-
- Metrics about users
- Response times
- Detailed errors
- Failures
- Availability
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a Tigerscheme qualified provider or a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Physical access control, complying with SSAE-16 / ISAE 3402
- Data sanitisation process
- Yes
- Data sanitisation type
- Explicit overwriting of storage before reallocation
- Equipment disposal approach
- A third-party destruction service
Backup and recovery
- Backup and recovery
- Yes
- What’s backed up
-
- The entire PaaS service infrastructure and content
- SQL Database
- Storage Account
- Application Services
- Content
- Backup controls
- Backups are controlled by the service and are automatically setup. These backups can be managed in the standard way via Microsoft Azure portal.
- Datacentre setup
-
- Multiple datacentres with disaster recovery
- Multiple datacentres
- Scheduling backups
- Supplier controls the whole backup schedule
- Backup recovery
- Users contact the support team
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- 99.95% availability, with service credits provided where availability SLA is not met.
- Approach to resilience
-
Microsoft datacenters are engineered to provide 99.999% availability.
Service deployed to multiple locations in an active/active setup. - Outage reporting
- Uptrends, emails, supplier meetings
Identity and authentication
- User authentication
-
- 2-factor authentication
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is controlled by Azure active directory and member ship to the correct RBAC roles and permissions
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Username or password
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Dedicated device over multiple services or networks
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- QAS International
- ISO/IEC 27001 accreditation date
- 04/03/2024
- What the ISO/IEC 27001 doesn’t cover
- N/a
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
- ISO27001 and Cyber essentials
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Product change management is controlled through Azure DevOps and the full cycle from idea to implementation is captured within that system. Changes are agreed at a steering committee, then enter the development life cycle. The team has adopted the Agile Scrum process.
Organisational change management is controlled and documented in Jira. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Forrit makes use of Microsoft 365, all laptops and hardware are within a compliant configuration using Microsoft Intune. Patching is done automatically and eventually forced if the user keeps snoozing the update.
- Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
-
Proactive monitoring is done by a 3rd party tool called Uptrends. Uptrends will do Synthetic Monitoring of the Forrit One platform and published endpoints. If an error is detected it will alert the support teams who will start the incident process and verify the failure.
Security Monitoring at an additional cost is completed by Azure Sentinel.
Full SLA’s and response times are agreed within the MBA/SOW. - Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management is completed with the use of Jira service desk. Incidents are logged by the customer, any updates reports are provided by email.
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- No
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- Azure, as a part of Microsoft, has been 100 per cent carbon neutral since 2012. By 2025, Azure will shift to 100 per cent supply of renewable energy, meaning that they will have power purchase agreements (PPA) for green energy contracted for 100 per cent of carbon-emitting electricity consumed by all their data centers.
Social Value
- Social Value
-
Social Value
Tackling economic inequalityTackling economic inequality
Involved in the Apprenticeship scheme Scotland and currently have 12 GA's in the programme and looking to hire 2 more in 2024
Pricing
- Price
- £1,000 a unit a month
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Details upon application.