Skip to main content

Help us improve the Digital Marketplace - send your feedback

FormusPro

Not for Profit / HashiCorp / IBM Partner Service Provider Offering

Our managed HashiCorp Service Provider offering delivers secure, scalable HashiCorp platforms as cloud services for UK public sector organisations. It enables consistent provisioning, security and connectivity across hybrid and multi-cloud environments. We provide licensing, hosting, support and lifecycle management under one contract, simplifying procurement and accelerating digital delivery.

Features

  • Infrastructure-as-Code using Terraform
  • Centralised secrets, keys and certificate management
  • Identity-based access and policy enforcement
  • Secure service-to-service networking
  • Hybrid and multi-cloud support
  • API-driven automation and self-service workflows

Benefits

  • Accelerated application and platform delivery
  • Reduced operational complexity through automation
  • Improved security and reduced credential sprawl
  • Consistent controls across hybrid and multi-cloud estates
  • Reduced vendor lock-in through open standards
  • Supports DevSecOps and platform engineering operating models

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrewmartin@formuspro.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 9 9 9 5 8 0 8 5 8 8 3 2 7 4

Contact

FormusPro Andrew Martin
Telephone: 01432345191
Email: andrewmartin@formuspro.com

About your service

Service categories

Application Development and Deployment

Application platforms

Deployment centric application platforms

  • Application Server Software Platforms
  • Cloud Deployment-Centric Application Platforms
  • Transaction Processing Monitors
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The service does not require an existing software service to operate, but can extend infrastructure, CI/CD, identity, and observability platforms as part of a hybrid operating model.
Cloud deployment model
Hybrid cloud
Service constraints
These include planned maintenance windows for upgrades, patching and security updates, which are scheduled and communicated in advance. High-availability, performance and feature sets may vary depending on selected HashiCorp products, deployment architecture and cloud provider. Certain integrations and configurations may require customer-supplied infrastructure (e.g. identity providers, CI/CD tooling or network connectivity).
System requirements
  • Customer identity provider for SSO integration
  • Customer change approvals for infrastructure or policy modifications.
  • Supported cloud provider account if using customer tenancy.
  • Customer-managed DNS zones for service discovery and certificate issuance.

User support

Email or online ticketing support
Yes
Support response times
We provide email and online ticketing support during UK business hours. Support tickets are acknowledged within one hour. Response and resolution times depend on priority. 24/7 support is also available.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide flexible, tiered support for HashiCorp Infrastructure and Platform services, aligned to issue priority, impact, and urgency.
Standard Support
Included with entry-level support packages.
Support is provided via email and online ticketing during UK business hours.
Tickets are acknowledged within one hour and managed using response-based SLAs.
Support is delivered by certified cloud engineers covering HashiCorp services.
Monthly support costs typically range from £405 to £2,430, depending on environment size, complexity, and required coverage.
Enterprise Support
Designed for larger or more complex HashiCorp environments.
Includes priority handling, extended support hours, and 24/7 cover for critical incidents.
A named technical account manager provides escalation management, service reviews, and governance.
Enterprise support pricing starts from £2,835 per month.
Additional Options
Pay-as-you-go support is available at £141.75 per hour.
Optional add-ons include enhanced coverage and support for wider HashiCorp ecosystems.
All support follows response-based SLAs, with priorities ranging from critical incidents to low-impact requests.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide structured onboarding to help users adopt the service efficiently. This includes discovery workshops, architecture alignment, environment provisioning, identity and CI/CD integration, and initial policy configuration. Users receive platform documentation, runbooks and knowledge articles tailored to their deployment.

We offer optional enablement services such as online training sessions, platform demonstrations, and hands-on labs for DevOps and application teams. For organisations needing deeper adoption support, we provide consultancy and platform engineering assistance covering GitOps, automation, security configuration, workload onboarding and operational best practice. Onsite enablement can be provided subject to requirement. Support teams are available to guide users through early usage, incident handling and service optimisation.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At end-of-contract, users can export all retained configuration, metadata and logs using standard interfaces before the service is deprovisioned. Data can be extracted via the web console, CLI or API, depending on the service components in use. Support is available to guide customers through the export process if required.
End-of-contract process
At contract end, the customer is notified in advance and offered time to extract data or extend the service. When the contract expires, access is suspended, data is securely deleted per policy, and the environment is deprovisioned.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service exposes both a web-based management interface and REST APIs for automated integration and operational control.
Accessibility standards
None or don’t know
Description of accessibility
The service is accessible through a modern web interface supporting keyboard navigation, screen zoom, and standard browser accessibility settings. Users can interact using GUI, API, or CLI depending on preference, allowing flexible access for automation and non-visual workflows. However, not all components are fully optimised for assistive technologies, and some advanced features may require CLI usage. Multi-factor authentication and identity federation support users with different security needs. Documentation is provided online in accessible HTML formats.
Accessibility testing
The service interfaces inherit accessibility capabilities from supported web browsers and Red Hat/HashiCorp platform components. Formal testing with users of assistive technologies has not been conducted by us directly. However, underlying vendor interfaces are regularly tested against recognised accessibility standards, and customers may perform their own accessibility validation as required.
API
Yes
What users can and can't do using the API
Users can interact with the service programmatically through HashiCorp platform APIs. They can configure infrastructure (Terraform), manage secrets and policies (Vault), and register services or networking rules (Consul). Setup tasks such as onboarding, policy creation, workspace configuration and credential management can be performed via API, and changes follow the same workflows to ensure consistency and automation.

Certain administrative actions—such as initial platform provisioning, licensing, tenant creation or network peering—cannot be completed solely via API and require support intervention or console access. Additionally, some APIs are product-specific and may not expose full UI feature parity. Users can integrate APIs into CI/CD pipelines, but high-risk operations may require elevated permissions or change approvals.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise service components, policies, access controls, automation workflows, integrations and deployment configurations. Customisation is performed through the web interface, CLI or API, and can be automated via IaC and CI/CD pipelines. Buyers control who can customise via role-based access control (RBAC); typically platform engineers, DevOps teams and authorised administrators can customise depending on assigned permissions.

Scaling

Independence of resources
We prevent cross-tenant impact through architectural isolation and resource controls. Each customer runs in logically isolated environments with enforced quotas on compute, memory, storage and network I/O to prevent resource contention. Control-plane capacity is reserved and protected from tenant workloads. Automated scaling ensures demand-driven capacity increases, and continuous monitoring allows proactive intervention before thresholds are reached. This guarantees one customer’s usage cannot degrade another’s performance.

Analytics

Service usage metrics
Yes
Metrics types
The service provides metrics that help buyers understand performance, consumption and health. This typically includes:

Platform health and availability metrics (uptime, component status)

Performance and capacity metrics (CPU, memory, storage, network utilisation)

Usage and consumption metrics (active users, API calls, workloads, deployments, secrets/issues handled)

Security and audit metrics (authentication events, policy violations, access logs)

Metrics are available via dashboards, API access and downloadable reports, allowing buyers to integrate with their own SIEM, observability or billing tools.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
HashiCorp / IBM Software Consultancy and Support

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data through the web interface, CLI or API, depending on the HashiCorp product. Data such as configurations, state files, secrets metadata, service definitions and audit logs can be exported in standard formats (for example JSON, YAML or HCL). Bulk exports can be requested through support if required.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We offer availability SLAs aligned to the HashiCorp platforms deployed. Typical service availability targets range from 99.9% to 99.99%, excluding planned maintenance windows that are communicated in advance. The SLA covers core service availability (for example control plane functions, API access and operational tooling).
Approach to resilience
The service is designed for resilience across platform, infrastructure and operational layers. HashiCorp platforms support distributed architectures, clustering and automated health checks to ensure workloads recover from node failures. Control plane components can be deployed redundantly, and workloads can be spread across multiple nodes, availability zones or regions depending on buyer requirements. Storage, networking and secrets backends are configured with fault-tolerant components.

Underpinning cloud datacentres are resilient by design, with redundant power, cooling, networking and physical security. Multi-zone or multi-region deployments are available to protect against localised failures. Backups, monitoring, patching and incident response processes further reduce operational risk. Additional architecture detail is available on request.
Outage reporting
Outages are reported through multiple channels. A service status dashboard provides real-time availability information, and customers can subscribe to email alerts for incident notifications, updates and resolutions. For automated monitoring, outage and health data can also be accessed via a status/health API.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted using role-based access control (RBAC), MFA and identity federation, ensuring only authorised users can administer the platform. Privileged actions are limited to approved roles, and all access is logged for audit purposes. Support channels are authenticated through the customer portal, and only nominated contacts can raise incidents, request changes or receive sensitive information. Sensitive operations require additional verification, and no unauthorised remote access to customer environments is permitted.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We follow documented information security policies aligned to ISO/IEC 27001, NCSC cloud security principles, and vendor best practice for Hashicorpplatforms. Policies cover access control, change management, vulnerability management, incident response, data protection, and acceptable use. They are approved by senior management and reviewed regularly.

Security is governed through a defined reporting structure with responsibility assigned to a senior security lead. Compliance is ensured through internal audits, technical controls, automated monitoring, mandatory staff training, and change approval processes. Third-party assessments and penetration tests validate security controls, and non-compliance is tracked and remediated through the risk management process.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our configuration and change management processes follow controlled lifecycle management. Service components are tracked from deployment through to retirement using asset registers, configuration management databases and version control systems. All changes—including platform updates, security patches and configuration modifications—are recorded and follow an approval workflow.

Before implementation, changes are assessed for potential security, performance and availability impact through technical review, vendor documentation, automated scanning and (where relevant) test environment validation. Security-sensitive changes undergo additional scrutiny and may require risk assessment or customer notification. Approved changes are implemented during agreed maintenance windows, monitored for success, and documented for audit and compliance purposes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We operate a continuous vulnerability management process aligned to recognised security standards. Potential threats are identified through automated scanning, configuration assessments, HashiCorp security advisories, CVE databases, industry threat intelligence and vendor feeds. Vulnerabilities are triaged by severity, exploitability and exposure. Critical patches are deployed as quickly as possible, often within defined emergency SLAs, while lower-severity updates are applied during scheduled maintenance windows. When patches are not immediately available, compensating controls or configuration mitigations are applied. All remediation actions are tracked for audit and compliance.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
HashiCorp use centralised logging, alerts and behavioural monitoring to identify potential compromises, including suspicious authentication attempts, privilege misuse, unusual workload activity and policy violations. When a compromise is suspected, events are triaged and investigated under defined incident response procedures, which may include isolating systems, revoking credentials or applying patches. High-severity incidents are responded to immediately, and others are handled within agreed SLAs. Root cause analysis and remediation are completed for confirmed incidents.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We maintain predefined incident management procedures for common events such as outages, performance degradation, security alerts and access issues. Incidents are logged and prioritised based on impact and severity. Users can report incidents via the support portal, email or phone depending on their support tier. After resolution, incident reports can be provided on request and include details such as root cause, impact, corrective actions and future preventative measures.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Terraform Open Source (Terraform CLI), which is fully free to use.

✅ What’s included (free):

Terraform CLI (core binary)

Infrastructure-as-code provisioning

State management (local or remote backends)

Provider ecosystem (AWS, Azure, GCP, VMware, etc.)

HCL language support

Community documentation and modules registry

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
1%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
3%
Between £1,000,001 and £2,500,000
4%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Sancert Ltd
ISO/IEC 27001 accreditation date
Monday 10 February 2025
What the ISO/IEC 27001 doesn’t cover
Nothing specific was excluded from our certification.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation
ISO 9001 accreditation date
Sunday 8 October 2023
What the ISO 9001 doesn’t cover
Nothing specifically was excluded in the scope for ISO 9001.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
B5d64ed8-d805-47b9-8d6d-d5b8b7930150
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
0f73a075-a547-4fa1-a2bd-df536b1062d2
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andrewmartin@formuspro.com. Tell them what format you need. It will help if you say what assistive technology you use.