Not for Profit / HashiCorp / IBM Partner Service Provider Offering
Our managed HashiCorp Service Provider offering delivers secure, scalable HashiCorp platforms as cloud services for UK public sector organisations. It enables consistent provisioning, security and connectivity across hybrid and multi-cloud environments. We provide licensing, hosting, support and lifecycle management under one contract, simplifying procurement and accelerating digital delivery.
Features
- Infrastructure-as-Code using Terraform
- Centralised secrets, keys and certificate management
- Identity-based access and policy enforcement
- Secure service-to-service networking
- Hybrid and multi-cloud support
- API-driven automation and self-service workflows
Benefits
- Accelerated application and platform delivery
- Reduced operational complexity through automation
- Improved security and reduced credential sprawl
- Consistent controls across hybrid and multi-cloud estates
- Reduced vendor lock-in through open standards
- Supports DevSecOps and platform engineering operating models
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 9 9 9 5 8 0 8 5 8 8 3 2 7 4
Contact
FormusPro
Andrew Martin
Telephone: 01432345191
Email: andrewmartin@formuspro.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
Deployment centric application platforms
- Application Server Software Platforms
- Cloud Deployment-Centric Application Platforms
- Transaction Processing Monitors
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service does not require an existing software service to operate, but can extend infrastructure, CI/CD, identity, and observability platforms as part of a hybrid operating model.
- Cloud deployment model
- Hybrid cloud
- Service constraints
- These include planned maintenance windows for upgrades, patching and security updates, which are scheduled and communicated in advance. High-availability, performance and feature sets may vary depending on selected HashiCorp products, deployment architecture and cloud provider. Certain integrations and configurations may require customer-supplied infrastructure (e.g. identity providers, CI/CD tooling or network connectivity).
- System requirements
-
- Customer identity provider for SSO integration
- Customer change approvals for infrastructure or policy modifications.
- Supported cloud provider account if using customer tenancy.
- Customer-managed DNS zones for service discovery and certificate issuance.
User support
- Email or online ticketing support
- Yes
- Support response times
- We provide email and online ticketing support during UK business hours. Support tickets are acknowledged within one hour. Response and resolution times depend on priority. 24/7 support is also available.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide flexible, tiered support for HashiCorp Infrastructure and Platform services, aligned to issue priority, impact, and urgency.
Standard Support
Included with entry-level support packages.
Support is provided via email and online ticketing during UK business hours.
Tickets are acknowledged within one hour and managed using response-based SLAs.
Support is delivered by certified cloud engineers covering HashiCorp services.
Monthly support costs typically range from £405 to £2,430, depending on environment size, complexity, and required coverage.
Enterprise Support
Designed for larger or more complex HashiCorp environments.
Includes priority handling, extended support hours, and 24/7 cover for critical incidents.
A named technical account manager provides escalation management, service reviews, and governance.
Enterprise support pricing starts from £2,835 per month.
Additional Options
Pay-as-you-go support is available at £141.75 per hour.
Optional add-ons include enhanced coverage and support for wider HashiCorp ecosystems.
All support follows response-based SLAs, with priorities ranging from critical incidents to low-impact requests. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide structured onboarding to help users adopt the service efficiently. This includes discovery workshops, architecture alignment, environment provisioning, identity and CI/CD integration, and initial policy configuration. Users receive platform documentation, runbooks and knowledge articles tailored to their deployment.
We offer optional enablement services such as online training sessions, platform demonstrations, and hands-on labs for DevOps and application teams. For organisations needing deeper adoption support, we provide consultancy and platform engineering assistance covering GitOps, automation, security configuration, workload onboarding and operational best practice. Onsite enablement can be provided subject to requirement. Support teams are available to guide users through early usage, incident handling and service optimisation. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At end-of-contract, users can export all retained configuration, metadata and logs using standard interfaces before the service is deprovisioned. Data can be extracted via the web console, CLI or API, depending on the service components in use. Support is available to guide customers through the export process if required.
- End-of-contract process
- At contract end, the customer is notified in advance and offered time to extract data or extend the service. When the contract expires, access is suspended, data is securely deleted per policy, and the environment is deprovisioned.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service exposes both a web-based management interface and REST APIs for automated integration and operational control.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is accessible through a modern web interface supporting keyboard navigation, screen zoom, and standard browser accessibility settings. Users can interact using GUI, API, or CLI depending on preference, allowing flexible access for automation and non-visual workflows. However, not all components are fully optimised for assistive technologies, and some advanced features may require CLI usage. Multi-factor authentication and identity federation support users with different security needs. Documentation is provided online in accessible HTML formats.
- Accessibility testing
- The service interfaces inherit accessibility capabilities from supported web browsers and Red Hat/HashiCorp platform components. Formal testing with users of assistive technologies has not been conducted by us directly. However, underlying vendor interfaces are regularly tested against recognised accessibility standards, and customers may perform their own accessibility validation as required.
- API
- Yes
- What users can and can't do using the API
-
Users can interact with the service programmatically through HashiCorp platform APIs. They can configure infrastructure (Terraform), manage secrets and policies (Vault), and register services or networking rules (Consul). Setup tasks such as onboarding, policy creation, workspace configuration and credential management can be performed via API, and changes follow the same workflows to ensure consistency and automation.
Certain administrative actions—such as initial platform provisioning, licensing, tenant creation or network peering—cannot be completed solely via API and require support intervention or console access. Additionally, some APIs are product-specific and may not expose full UI feature parity. Users can integrate APIs into CI/CD pipelines, but high-risk operations may require elevated permissions or change approvals. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can customise service components, policies, access controls, automation workflows, integrations and deployment configurations. Customisation is performed through the web interface, CLI or API, and can be automated via IaC and CI/CD pipelines. Buyers control who can customise via role-based access control (RBAC); typically platform engineers, DevOps teams and authorised administrators can customise depending on assigned permissions.
Scaling
- Independence of resources
- We prevent cross-tenant impact through architectural isolation and resource controls. Each customer runs in logically isolated environments with enforced quotas on compute, memory, storage and network I/O to prevent resource contention. Control-plane capacity is reserved and protected from tenant workloads. Automated scaling ensures demand-driven capacity increases, and continuous monitoring allows proactive intervention before thresholds are reached. This guarantees one customer’s usage cannot degrade another’s performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides metrics that help buyers understand performance, consumption and health. This typically includes:
Platform health and availability metrics (uptime, component status)
Performance and capacity metrics (CPU, memory, storage, network utilisation)
Usage and consumption metrics (active users, API calls, workloads, deployments, secrets/issues handled)
Security and audit metrics (authentication events, policy violations, access logs)
Metrics are available via dashboards, API access and downloadable reports, allowing buyers to integrate with their own SIEM, observability or billing tools. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- HashiCorp / IBM Software Consultancy and Support
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data through the web interface, CLI or API, depending on the HashiCorp product. Data such as configurations, state files, secrets metadata, service definitions and audit logs can be exported in standard formats (for example JSON, YAML or HCL). Bulk exports can be requested through support if required.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We offer availability SLAs aligned to the HashiCorp platforms deployed. Typical service availability targets range from 99.9% to 99.99%, excluding planned maintenance windows that are communicated in advance. The SLA covers core service availability (for example control plane functions, API access and operational tooling).
- Approach to resilience
-
The service is designed for resilience across platform, infrastructure and operational layers. HashiCorp platforms support distributed architectures, clustering and automated health checks to ensure workloads recover from node failures. Control plane components can be deployed redundantly, and workloads can be spread across multiple nodes, availability zones or regions depending on buyer requirements. Storage, networking and secrets backends are configured with fault-tolerant components.
Underpinning cloud datacentres are resilient by design, with redundant power, cooling, networking and physical security. Multi-zone or multi-region deployments are available to protect against localised failures. Backups, monitoring, patching and incident response processes further reduce operational risk. Additional architecture detail is available on request. - Outage reporting
- Outages are reported through multiple channels. A service status dashboard provides real-time availability information, and customers can subscribe to email alerts for incident notifications, updates and resolutions. For automated monitoring, outage and health data can also be accessed via a status/health API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted using role-based access control (RBAC), MFA and identity federation, ensuring only authorised users can administer the platform. Privileged actions are limited to approved roles, and all access is logged for audit purposes. Support channels are authenticated through the customer portal, and only nominated contacts can raise incidents, request changes or receive sensitive information. Sensitive operations require additional verification, and no unauthorised remote access to customer environments is permitted.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We follow documented information security policies aligned to ISO/IEC 27001, NCSC cloud security principles, and vendor best practice for Hashicorpplatforms. Policies cover access control, change management, vulnerability management, incident response, data protection, and acceptable use. They are approved by senior management and reviewed regularly.
Security is governed through a defined reporting structure with responsibility assigned to a senior security lead. Compliance is ensured through internal audits, technical controls, automated monitoring, mandatory staff training, and change approval processes. Third-party assessments and penetration tests validate security controls, and non-compliance is tracked and remediated through the risk management process. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Our configuration and change management processes follow controlled lifecycle management. Service components are tracked from deployment through to retirement using asset registers, configuration management databases and version control systems. All changes—including platform updates, security patches and configuration modifications—are recorded and follow an approval workflow.
Before implementation, changes are assessed for potential security, performance and availability impact through technical review, vendor documentation, automated scanning and (where relevant) test environment validation. Security-sensitive changes undergo additional scrutiny and may require risk assessment or customer notification. Approved changes are implemented during agreed maintenance windows, monitored for success, and documented for audit and compliance purposes. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We operate a continuous vulnerability management process aligned to recognised security standards. Potential threats are identified through automated scanning, configuration assessments, HashiCorp security advisories, CVE databases, industry threat intelligence and vendor feeds. Vulnerabilities are triaged by severity, exploitability and exposure. Critical patches are deployed as quickly as possible, often within defined emergency SLAs, while lower-severity updates are applied during scheduled maintenance windows. When patches are not immediately available, compensating controls or configuration mitigations are applied. All remediation actions are tracked for audit and compliance.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- HashiCorp use centralised logging, alerts and behavioural monitoring to identify potential compromises, including suspicious authentication attempts, privilege misuse, unusual workload activity and policy violations. When a compromise is suspected, events are triaged and investigated under defined incident response procedures, which may include isolating systems, revoking credentials or applying patches. High-severity incidents are responded to immediately, and others are handled within agreed SLAs. Root cause analysis and remediation are completed for confirmed incidents.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We maintain predefined incident management procedures for common events such as outages, performance degradation, security alerts and access issues. Incidents are logged and prioritised based on impact and severity. Users can report incidents via the support portal, email or phone depending on their support tier. After resolution, incident reports can be provided on request and include details such as root cause, impact, corrective actions and future preventative measures.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
Terraform Open Source (Terraform CLI), which is fully free to use.
✅ What’s included (free):
Terraform CLI (core binary)
Infrastructure-as-code provisioning
State management (local or remote backends)
Provider ecosystem (AWS, Azure, GCP, VMware, etc.)
HCL language support
Community documentation and modules registry
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Sancert Ltd
- ISO/IEC 27001 accreditation date
- Monday 10 February 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing specific was excluded from our certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation
- ISO 9001 accreditation date
- Sunday 8 October 2023
- What the ISO 9001 doesn’t cover
- Nothing specifically was excluded in the scope for ISO 9001.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B5d64ed8-d805-47b9-8d6d-d5b8b7930150
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 0f73a075-a547-4fa1-a2bd-df536b1062d2
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-