iboss Zero Trust Secure Access Service Edge
iboss utilises a containerised cloud architecture allowing customers to easily migrate from legacy appliances, whilst maintaining 100% dedicated IP address space in the cloud. This allows for PDNS intergration, and admin created GDPR Zones with dedicated UK datacentres. Packages include Core Filtering, Malware detection and Data Loss Prevention
Features
- Complete web & internet content filtering
Benefits
- Complete web & internet content filtering
Pricing
£6,500 a unit a year
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
7 2 2 9 2 1 0 0 3 7 4 9 1 6 1
Contact
Softcat Limited
Charles Harrison
Telephone: 01628 403403
Email: psitq@softcat.com
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
- None
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
Standard Support Package: S1 - 2hrs; S2 - 4 hrs; S3/S4 - 24 hrs.
Mission Critical Support Package: S1 - 15 mins; S2 - 1hr; S3/4 - 4hrs. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Web chat
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Iboss leverages third party chat software with integrated support for assistive technology users
- Web chat accessibility testing
- Iboss leverages third party chat software with integrated support for assistive technology users
- Onsite support
- Yes, at extra cost
- Support levels
-
Standard Support Package
Mission Critical Support Package - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Iboss offers both professional services as well as an aligned SE with each customer for implementation taking the client through the roll out of iboss to the organization as well as providing assistance and guidance during migration work and other hurdles as they appear.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Data can be downloaded from the iboss platform
- End-of-contract process
- At the end of the contract, data is deleted within the iboss cloud within 24 hours
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Windows Phone
- Other
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Other than different applications that are used for each OS the features are the same regardless of the device
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service interface is the iboss cloud management portal. This portal provides customers a ‘Single Pane of Glass’ for policy orchestration and reporting and allows administrators to control the service on a national or global scale.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Access to the iboss interface is web based and is browser independent
- Accessibility testing
- Users work with our product through a responsive interface
- API
- Yes
- What users can and can't do using the API
- Users are able to manage any control offered by the iboss GUI via our API.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Customization is availble for branding of reports and block/ alert pages. As well as customized reporting and alert with content specified by the report creator.
Scaling
- Independence of resources
- The advantage of the iboss cloud platform is the use of horizontal scaling vs. "larger" gateways. By using horizontal scaling, additional work units (containerized gateways) are added as capacity demands increase. This allows for infinite scale as bandwidth continues into the Terabit era. For each additional containerized gateway that is added automatically to a customer's containerized gateway collection, additional work unit capacity is added for both bandwidth and cloud requests. This increase in capacity is tightly measured as the capacity of each containerized gateway is known. The Containerized Cloud Gateway architecture provides a multi-tenant platform without a shared data plan
Analytics
- Service usage metrics
- Yes
- Metrics types
- Usage is published within the product dashboards which includes bandwidth processed, web access, source and distination IP amongst other
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- Iboss
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Physical access control, complying with SSAE-16 / ISAE 3402
- Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Users can export data via reporting export, Syslog, CSV, PDF, HTML Etc. Policy items can be exported as Json or CSV
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- HTML
- CSV
- JSON
- FTP
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- All data in motion are encrypted. Security and compliance meet FIPS and Common Criteria specifications. Encryption at rest is secured via AES-256. TLS 1.2 is used to encrypt data in transit.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- We follow ISO 27001 and 9001 guidelines. Customer's data is level 'Confidential' which is top confidentiality level. iboss also has classifications for levels of data to ensure correct protection: internal data, confidential data, and restricted use data.
Availability and resilience
- Guaranteed availability
- Iboss will use commercially reasonable efforts to ensure that the Service will have an Availability of 99.99999% as measured over each calendar month during the Term. In the event of a Service Level Failure, Customer will be eligible to receive the applicable Service Credit according to the terms set forth in this SLA.
- Approach to resilience
- The iboss cloud infrastructure is built with High Availability in mind and is native to the Node based architecture. From the ability to have work units automatically expand horizontally to load balancing, the platform is designed for full redundancy and high availability. User deployments are setup to dynamically redirect traffic to the cloud in the closest resource while providing the highest level of performance and availability. If any gateway is out of service, traffic is automatically routed to the other available gateways. iboss also partners with top tier Data Centers that meet SSAE 16 SOC1 and SOC 2 compliance and our Security Analysts monitor the network 24/7 leveraging real time monitoring tools.
- Outage reporting
- If the client is impacted due to an outage, iboss will push the notification through an email distribution list and the change will be posted on iboss's website. Notifications of any significant outages will occur via email and phone confirmation. Maintenance of the platform is also fully controlled by the customer and can be scheduled or manually instigated to suit the customer maintenance windows.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- Authentication can be via SAML or seamless transparent Single Sign-On with iboss agents.
- Access restrictions in management interfaces and support channels
- The iboss platform provides complete customizable role-based access where administrators can restrict access to any area of the web security controls including allow/block list, all policies, configuration and controls.
- Access restriction testing frequency
- Less than once a year
- Management access authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Description of management access authentication
- Authentication can be performed using SAML, Kerberos/NTLM, LDAP or the iboss cloud connectors for SSO. This includes authentication for end users as well as administrative functions. The iboss cloud admin portal can be tied to Okta, Ping or any SAML compliant Identity Provider. MFA is also supported for admin login using Microsoft of Google Authenticator.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- ISF-ISR
- ISO/IEC 27001 accreditation date
- 26/10/2022
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2007 certification
- No
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- May-21
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
- N/A
- PCI certification
- No
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 27001 & 9001
- SOC 2
- FIPS 140-2 & Common Criteria
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- SOC 2/SSAE 16
- Information security policies and processes
- Strategic alignment is constantly communicated and reviewed by senior management. All business functions are controlled through defined objectives, policies, delegation of authorities, and monitoring.
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
-
1. request change
2. categorize and prioritize change
3. analyze and justify change
4. approve and schedule change
5. plan and complete implementation of change
6. post-implementation review - Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
- Iboss follows a Vulnerability Management Standard. The primary vulnerability tool used is QualysGuard which scans network infrastructure on a regular scheduled basis and generates reports for vulnerabilities across all assets. The Network Operations Team regularly reviews the results and remediates/mitigates the risks accordingly.
- Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
-
The Network Operations Center has a 24x7 team of engineers who are constantly monitoring the cloud performance across the globe. A continuous automated assessment is performed to proactively ensure the integrity of the service. If during this automated process an alert is thrown the Network Operations Team is immediately notified. The Network Operations team will then take the appropriate steps to assess and as needed mitigate the alert.
The team also performs regular vulnerability and penetration tests to prevent unauthorized access attempts and any potential malicious activity - Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
- Detection and Analysis, Containment, Eradication, and Recovery, Post-Incident Activity
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
Softcat are dedicated to reducing our environmental impact and actively promoting sustainability. Our commitment to sustainability is a core aspect of our business strategy, driving us to innovate and lead in the creation of a more sustainable future for our company and the communities we serve. This commitment is embedded in our policies, operating procedures, and training programs.
We are proud to be the first FTSE 250 company to be awarded 5-star status in relation to the United Nations Sustainable Development Goals.
We aim to achieve a Carbon Net-Zero Value Circle by 2040 by prioritising renewable energy, reducing natural resource use, minimising waste, and safeguarding biodiversity in compliance with environmental legislation.
At Softcat, we have taken significant steps towards securing renewable energy across our organisation, reducing our scope 1 & 2 emissions. We had the target of using 100% Renewable Energy across all our locations by 2024. We successfully delivered against this target ~2 years early.
In May 2023 we took delivery of 15 electric vehicles, replacing all existing fossil-fuelled company cars used by employees for business means. The implementation of the EV pool fleet will see a saving of over 80 tons of CO2e per year. A huge impact on our Net Zero targets.Tackling economic inequality
As a value-add reseller, Softcat outsources the products, services, and solutions through our extensive network of partners, to best suit the needs of our broad client base. We always consider and promote SMEs and local providers where appropriate, particularly for the products and services we offer via the G Cloud framework.
We remain dedicated to improving employability and educational awareness across schools, colleges, and universities to help break down the barriers to joining technology organisations.
We work collaboratively with many schools that are close in proximity to our offices, to ensure we are actively supporting the community as well as schools from lower socio-economic backgrounds.
We visit the schools to talk about the IT sector and the roles in our organisation, as well as promoting work-experience opportunities during the summer. In particular, we actively encourage students from diverse backgrounds to engage in work experience to appreciate the roles available in our sector.
For ambitious school and college leavers, a Softcat Apprenticeship is a great first step into the world of work, with 94% of our apprentices offered a permanent position at Softcat post apprenticeships, which goes to show the amazing opportunity available with us.
We were ranked 1st in IT & Consultancy, and 10th overall in by RateMyApprenticeship.com - Best 100 Apprenticeship Employers 2023-2024 list.
Softcat now also offer 12 month paid internships to University students looking to complete a year in industry as part of their undergraduate studies.Equal opportunity
Our approach to diversity and inclusion is introduced first during our induction training, as part of our Softcat values, outlining responsibility to uphold our principles. This message is reinforced by our process and policies, networks, Allyship Training and Inclusion Awareness campaigns.
Softcat supports diversity and inclusion through various networks including:
- Supporting Women in Business (SWIB)
- The Ethnic and Cultural Network
- The Pride Network
- The Family Network
- The Empowering Disability and Neurodiversity Network (EDN)
- The Faith at Work Network
- Armed Forces & Veterans Network
These networks aim to create a supportive and inclusive work environment for all employees, regardless of gender, ethnicity, sexual orientation, disability, or family commitments.
Our allyship programme, Stronger Together, is a mixture of event and workshop-based training available to all staff. Programme topics include, bias, power, privilege, and being a greater ally.
Inclusion Awareness campaigns include race, disability, sexual orientation, gender, faith, and caring responsibilities. These sessions highlight and celebrate minority groups, through panel sessions, Q&A sessions and training, providing an opportunity to discuss and understand ways to be more inclusive.
Our efforts to improve diversity and inclusion have been incredibly successful. Since 2020, the number of female employees below management level has increased to 35%, and the number of ethnic minority employees rose to 17%.Wellbeing
At Softcat, all employees are provided with access to our multidimensional wellbeing programme which includes flexible work arrangements, free nutritious breakfast, mental health support, employee benefits scheme, health and wellbeing week activities, and online workshops.
Giving back to the community is an innate part of who we are as a company. All Softcat employees are therefore given two volunteer days per year to support a charitable or community cause.
Each of our 10 regional offices also support local charities through fundraising, donations and events. For example, our Manchester office has raised over £30,000 for the WeLoveMCR charity. This funding has supported young, disadvantaged Manchester citizens in gaining qualifications to broaden their work opportunities and supporting local groups in delivering indispensable services that enable community cohesion.
Pricing
- Price
- £6,500 a unit a year
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Please speak to a representative