Skip to main content

Help us improve the Digital Marketplace - send your feedback

ASTUN TECHNOLOGY LIMITED

Astun Clarity for Metadata Management and Data Discoverability

Astun Clarity is a cloud based metadata service that provides both internal metadata maintenance and discovery services with a workflow for quality approval and subsequent publication of a subset of records to data.gov.uk or another standards compliant portal.

Features

  • Gemini 2.3 and INSPIRE compliant service
  • Automatic validation of metadata against schema
  • Support for custom schemas
  • QA and Approval for Publication workflows
  • Serve metadata via an OGC CSW to the data.gov.uk portal
  • Organisational and departmental hierarchy
  • Separate internal and public metadata
  • Internal and Public discovery services
  • No need to implement any additional technology locally
  • Enterprise Grade Support

Benefits

  • Custom cloud based metadata service
  • Uses GeoNetwork like most of the world's spatial data infrastructures
  • Full support for UK GEMINI metadata standards
  • Metadata Publishing provides full UK Location Programme compatibility
  • Ensures that data is managed and discoverable across your organisation
  • Provides real business value and business efficiency
  • Multiple catalogs for both internal-facing and external-facing metadata
  • Serve metadata to data.gov.uk and other standards compliant portals
  • Automated Metadata Creation and Update, saving time and resources

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@astuntechnology.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 8 8 6 5 0 1 9 2 2 8 4 9 0 0

Contact

ASTUN TECHNOLOGY LIMITED Astun Technology Sales Team
Telephone: 01372 744009
Email: sales@astuntechnology.com

About your service

Service categories

Application Development and Deployment

Data management

Data integration and intelligence

  • Metadata Management Software
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Most planned maintenance will be undertaken without interrupting service availability, however in the event that this is not possible downtime will be scheduled and customers notified in advance.
System requirements
  • Compliant with OGC WMS 1.1.1, 1.3.0
  • Compliant with OGC WFS 1.0.0, 1.1.0
  • Compliant with OGC CSW 2.0.2

User support

Email or online ticketing support
Yes
Support response times
Our guaranteed response time, during working hours, is under 2 hours for all ticket classifications.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
IShare in the Cloud Application Support is included within an iShare in the Cloud Open Enterprise Agreement.

Astun provide the following iShare in the Cloud Support as standard:
1. Advice on maintaining iShare in the Cloud.
2. Access to official iShare in the Cloud and community forums.
3. Advice on configuring and extending iShare in the Cloud.
4. Instructions on how to remedy common faults.
5. Resolution of issues related directly to a serious flaw in iShare in the Cloud.
6. The Customer may obtain iShare in the Cloud Application support by logging a request on Astun’s Support Portal.

First line support is provided via a permanently staffed Service Desk with second and third line support by consultancy and development teams for fault diagnosis and resolution. Customer access to web based Service Desk provides real time ticket management and correspondence on all customer tickets.

For support conditions, support processes, the service level agreement and escalation procedures are detailed in the accompanying document - Astun Platform Terms & Conditions
Support available to third parties
Yes

Onboarding and offboarding

Getting started
On receipt of a purchase order Astun Technology will: Issue Project Initiation Documents and host kick off call / meeting; Set up Astun Clarity server within customer Virtual Private Cloud; Configure Astun Clarity. Liaise with customer on configuration options; Commence delivery of additional configuration and consultancy services. Astun provide onsite training for administrators and user documentation.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
In the event that the customer terminates the service they can download their data from the service in a standard file format or as a database export/backup. Customers should extract a copy of their data before their contract expires.
End-of-contract process
On receipt of a written request to terminate the Astun Clarity service and subject to there being no unpaid charges outstanding, Astun will delete the hosted environment including all servers, datasets, user details and customer specific configuration stored within Astun Clarity. Any further "Off-boarding" assistance is chargeable in accordance with Astun's rate card.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Full details of the service interfaces can be found in the Service Definition.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
None.
API
Yes
What users can and can't do using the API
You can integrate with Clarity using the underlying GeoNetwork API for things like:
Creating/updating/deleting metadata records
Searching and exporting metadata (often as XML/JSON)
Bulk operations (e.g. via scripts in Python, as mentioned in training notes)
API documentation
No
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Customisation by agreement and/or with the purchase of Call-Off Consultancy service days. Customisation options include: Custom styling, custom filters, support for custom schemas, custom validation error messages and schematron rules and custom reports.

Scaling

Independence of resources
Customers have their own dedicated virtual private cloud.

Analytics

Service usage metrics
Yes
Metrics types
Customers can obtain metrics using Google Analytics.
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
The administration console can be used to export data in a wide variety of formats.
Data export formats
  • CSV
  • Other
Other data export formats
  • All common data formats as supported by GDAL/OGR
  • OGC Web Services
Data import formats
  • CSV
  • Other
Other data import formats
  • All common data formats as supported by GDAL/OGR
  • OGC Web Services

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Astun Clarity is hosted on a high availability cloud infrastructure with a failover backup to at least three independent data centres for maximum resilience. Internal availability testing indicates availability in excess of 99.6% Response times for map rendering are typically less than 1 second at the server. The services are continually monitored with automated messages sent to several staff in the event of a deterioration or failure.
Approach to resilience
Astun Clarity is hosted within the Amazon Web Services environment (AWS). The entire cloud environment is backed up to at least three independent data centres to provide additional resilience in the unlikely event that the primary availability zone becomes unavailable.
Outage reporting
Astun set up a series of alarms to monitor the customer's cloud service. These alarms are triggered if any pre-set limits to system resources are reached (e.g. disk space). This enables Astun to address the majority of issues before any potential outage. We also use our GeoHealth check system to monitor servers and ensure they are up and working. The customer is informed of any potential problems by email or phone.

Identity and authentication

User authentication needed
Yes
User authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces are restricted to login in via remote desktop over a dedicated VPN between customer network estate and the virtual private cloud environment dedicated to the customer. Access by Astun is also over VPN.
Access restriction testing frequency
At least every 6 months
Management access authentication
Dedicated link (for example VPN)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Astun has a formal Information Security Policy that provides a framework for the management of information security within our business processes.
Information security policies and processes
In addition to our Information Security Policy we are also Cyber Essentials Plus accredited. Astun Clarity is hosted on Amazon Web Services (which is ISO 27001 accredited). Users should make appropriate decisions regarding what data to deploy within Astun Clarity.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Changes to all Astun components are managed and tracked through their lifetime via a centralised bug-tracking, issue-tracking and project-management software application (JIRA) and associated private code repository (BitBucket) managed under source control. The software is built through a repeatable build process and after passing formally defined test cases is tagged to a specific version number at the point of release. Only released software is deployed to the customer virtual private cloud environments. Potential security impacts are assessed via a process of peer review.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Information on potential threats is continuously assessed through review of key online resources (release notes, security articles etc) for all third party components (operating systems, databases, frameworks etc). Penetration testing of the full system (including Astun components) is undertaken by independent third parties on all significant software releases. Whilst patch releases are routinely issued on a monthly basis, key security vulnerabilities are patched and released as soon as Astun become aware of them, irrespective of the stage in the release cycle.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
All cloud servers are set up with alarms that monitor key system resources on the server itself allowing the detection of compromises such as denial of service attacks. In addition external monitoring services are set up to make routine periodic requests to the servers (typically every 15 mins), to check that they remain responsive, and send out alerts if any servers are unavailable. Incidents are responded to as soon as we become aware of them. Logging is enabled on the servers to provide an audit trail of potential compromises for subsequent investigation.
Incident management type
Supplier-defined controls
Incident management approach
Security related incidents are categorised as a Priority 1 within our Service Desk system, and allocated to third line support personnel (developer) for immediate investigation and resolution. Users are able to report such incidents via the Service Desk (phone, email and web form), which is routinely monitored throughout the working day by first line support staff. Contemporaneous notes are taken during the incident and recorded against the service desk ticket, which provides a detailed report of the incident itself. Key performance indicators are also published from the Service Desk System and routinely reviewed by management on a weekly basis.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
The scope of the trial will be by agreement. The customer may be required to pay for the services required to set up the trial.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
4a22f9be-2434-4332-b30e-325709b17072
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
73eeab73-0e12-4943-b337-3d2c0a37d3d2
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@astuntechnology.com. Tell them what format you need. It will help if you say what assistive technology you use.