Virtual Private Cloud (VPC)
eCloud VPC offers you the ability to leverage a Public Cloud experience whilst using a traditional VMware platform under the hood. This is a flexible, scalable and simple approach from a commercial and technical perspective. Assets are housed on a robust and reliable platform, ensuring services remain consistently available.
Features
- Scale up and down your virtual machines without restriction.
- Maximum network performance and reliability with dedicated Cisco Equipment
- Designed to meet standards equivalent to Tier 1 (OFFICIAL/OFFICIAL-SENSITIVE)
- Automated Virtual Machine (VM) backup backups.
- Multiple network connectivity offerings via Internet and HSCN
Benefits
- 100% UK-based and operated ISO-accredited datacentres with SC-cleared operational staff.
- Scalable to meet the changing demands.
- Fixed Pricing approach to ensure billing remains predictable
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 1 9 2 0 1 7 7 9 9 4 0 7 6 1
Contact
ANS GROUP LIMITED
Steve Carroll
Telephone: +44 (0) 1612271000
Email: tenders@ansgroup.co.uk
About your service
- Service categories
-
IaaS
IaaS Compute
- Bare metal
- Container and serverless engine compute
Virtualised x86
- General purpose
- Compute optimised
- Memory optimised
Accelerated
- GPUs
Service scope
- Service constraints
- All planned maintenance is covered by a mandatory 5 day notice period. We reserve the right to conduct unplanned emergency maintenance where necessary, but will always make reasonable efforts to inform impacted customers before work commences. Support is limited to services, hardware and applications provided by ANS and does not extend into the customer's application stack.
- System requirements
-
- Proof of license ownership for customer-provided Microsoft licenses
- Customers must adhere to fair use policy and ToS
- Cloud deployment model
- Private cloud
User support
- Email or online ticketing support
- Yes
- Support response times
- Calls are responded to within 6 rings. Service Ticket response time is dependent on the criticality: 1. Critical - Immediate Response 2. High - Response within 10 minutes 3. Medium - Response within 1 hour 4. Low - Response within 4 hours 5. Very Low - Response within 24 hours. The standard SLA response times are applicable from 09:00 to 17:00 Monday to Friday (excluding UK Bank Holidays). 365/24/7 Support is also available as a service at an additional cost.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Via online portal
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
-
All ANS customers have access to ticket and telephone-based support, unless they choose to take an unmanaged service.
Customers have access to a named Account Manager who takes overall responsibility for the customer's commercial, technical and support relationship with ANS.
Customers are assigned a support "pod" based on the type of solution they have with ANS. This ensures customers will always be supported by the same core team of support engineers who are technical experts in their particular solution.
Enterprise and public sector customers also have access to a named Service Manager in addition to their Account Manager. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- We offer services to enable seamless on-boarding and collaborate to design a bespoke solution to meet your requirements. An onboarding process would typically include - Discovery process / Timeline setting / Risk assessment / Implementation process / Quality Assurance
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract any customer data stored will only be extracted by ANS with the prior consent of the customer.
ANS shall purge and destroy (as defined in security accreditation for different ILs) customer data from any of its own equipment after the contract ends. - End-of-contract process
-
A similar process to on-boarding is provided for customers wishing to leave ANS. We provide full transitional services at an additional charge (please refer to the pricing document for more details). An example phased off-boarding process is as follows:
1. Discovery: ANS meets the customer’s new provider who will lead the project
2. Timelines: Timelines are agreed where possible and alternatives offered when needed
3. Risk: ANS identifies any risks that may not be apparent to the new provider or that are inherent to the ANS solution
4. Implementation: ANS assists the new provider if needed
5. Quality Assurance: ANS offers a debrief and review meeting if the new provider requires. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Accessible via request to Customer Success Manager or Architect
Using the service
- Web browser interface
- Yes
- Using the web interface
- Glass is the customer's web interface where they can manage all aspects of their solution - for example creating/managing/deleting/scaling virtual machines, managing reports and monitoring alerts, firewall configuration and more.
- Web interface accessibility standard
- None or don’t know
- How the web interface is accessible
- Accessibility via the internet via MFA protected, secure portal.
- Web interface accessibility testing
- Testing against WCAG has been performed to understand the requirements for Glass rebuild.
- API
- Yes
- What users can and can't do using the API
-
Create VMs
Manage VMs
Delete VMs
Scale VMs up / down
Power VM on / off
Clone VM
Create and manage templates
Manage nodes
Manage Datastores
Manage firewalls
Manage system resources
Manage VPC networks
Manage IP addressing
Manage load balancing - API automation tools
-
- Ansible
- Chef
- SaltStack
- Terraform
- Puppet
- Other
- Other API automation tools
- Any appropriate tool can be used
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Other
- Command line interface
- No
Scaling
- Independence of resources
- Platform wide monitoring and long term planning of key resource capacity requirements.
- Usage notifications
- Yes
- Usage reporting
-
- API
- SMS
- Optimising consumption
- Yes
- Automatic scaling
- No
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Other
- Other metrics
-
- Applications
- Services
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Backup and recovery
- What’s backed up
-
- Files
- Folders
- Virtual machines
- Databases
- Operating systems - Linux and Windows
- Microsoft Exchange servers
- Active Directory
- Backup controls
- ANS will agree and implement a robust and granular backup schedule on the customer's behalf
- Datacentre setup
- Multiple datacentres with disaster recovery
- Scheduling backups
- Users contact the support team to schedule backups
- Backup recovery
-
- Users can recover backups themselves, for example through a web interface
- Users contact the support team
- Backup and recovery
- Yes
- RPO/RTO
- Yes
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
ANS’ VPC platform is engineered to deliver high availability, resilience, and guaranteed performance through a combination of Highly available equipent and fully redundant datacentre architecture.
The platform can provide 1 hour RPO and RTO through Virtual Machine replication across two ANS UK datacentres, and continuous service even in the event of underlying hardware failure, maintaining service continuity. An uptime guarantee of 99.5% is provided for single components, whilst higher SLA's can be offered where more complex configurations are provided.
ANS provides 24x7 support for business‑critical P1 incidents, ensuring rapid response and minimal disruption, with defined SLAs for incident handling, patching, change management, and operational oversight.
This architecture and support framework together provide a robust, high‑availability environment designed to keep critical services continuously online, backed by ANS’ extensive cloud operations expertise and redundant UK datacentre infrastructure. - Approach to resilience
- ANS owns and operates a 5.52MW tier 3 1,000 rack data centre estate. This contains multiple physically separate buildings, connected by dedicated fibre. High voltage power connections are provided from separate primary sub-stations. All mission-critical services including Standby Generation, Cooling systems and UPS (uninterruptible power system) are provided at N+1 or greater across the whole facility. The complex has a power density of over 6KW per square foot, providing diverse A & B power to each data rack, and all eCloud service platforms are supported from quadruple power feeds. The data centre complex is supported by 9MW of standby generation with over 100,000 litres of fuel storage and eight hour fuel supply SLA. All critical services are supported by 4.6MW of UPS power and 4.9MW of data centre cooling. The public sector hosting suite has fully resilient networking, switches, carrier-redundant leased lines, power and backup generators, all separated from the rest of the ANS network and data centre complex.
- Outage reporting
- A public status page is available on the ANS website, which shows live status of our core network and infrastructure along with details of any incidents. Customer notifications are managed via our ticketing system accessible via Glass.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- In addition to the username and password, there is a range of options available for Multi Factor authentication which include hard and soft tokens, PKI certificates and 3rd party authentication apps.
- Access restrictions in management interfaces and support channels
- Separate accounts are required for Administrative Access, with authentication and authorisation controls applied to all Administrative functions. SSH access to the Virtual machines command line, and RDP sessions requires key-based authentication from a specified source location into a bastion host, which then requires further authentication and account escalation at each onward connection to the specific administrative services.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Other
- Description of management access authentication
- Management access is typically from dedicated OOB Management networks, external access is restricted by source address and requires key based auth to a bastion host server from which secondary logins and privilege escalation is required.
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Dedicated device on a government network (for example PSN)
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Security policies and procedures form part of the formal system accreditation by CyDR, Cabinet Office, Home Office, NCSC, NHS Digital.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- ANS operates a structured configuration and change management process. Configuration management maintains a controlled, accurate model of all customer configuration items (CIs) within the CMDB, ensuring traceability, compliance, and efficient impact analysis. ANS identifies, records, verifies and updates CIs through defined naming conventions, status tracking, and CSOC oversight. Change management requires all changes to be submitted via an RFC through the ANS Glass portal, evaluated by engineers, risk‑assessed, approved by SMEs/CAB, and implemented in line with the Managed Services Handbook. Emergency changes are only executed for P1 or major security incidents.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
ANS monitor threat sources, including CERT to gain information about potential threats. Vulnerabilities and Remediation activities are assessed to determine the priority, with patches being applied within the hour for critical security issues through to monthly patching for routine updates.
Though these are developed in line with ISO27001 and Cyber Essentials, the vulnerability management approach is dictated by the specific requirements of the Service and customer requirements. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- ANS employ protective monitoring services in compliance with Protective Monitoring for HMG ICT systems (formerly GPG-13).
- Incident management type
- Supplier-defined controls
- Incident management approach
- ANS operates a structured incident‑management process with predefined workflows for common events, aligned to priority levels (P1–P5). Users report incidents via the ANS Glass portal, phone, email, or service desk, with P1 issues requiring immediate phone escalation. All actions and updates are logged throughout the lifecycle, and customers receive periodic progress updates. After resolution—especially for major or P1 incidents—ANS provides incident reports and, where required, root‑cause analysis to support transparency and service improvement.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Supplier
- Virtualisation technologies used
- Other
- Other virtualisation technology used
- NSX
- How shared infrastructure is kept separate
- Customers are offered shared platform resources by default, however - dedicated hardware is separated out at the Vmware layer can be made available upon request. Independent NSX routers are offered to each customer and all virtual machines are housed behind their own dedicated firewalls. Finally, customers are offered their own storage partitions from a shared SAN.
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- ANS datacentres follow core principles of the EU Code of Conduct through a combination of renewable energy use, efficient infrastructure design, proactive monitoring, and environmentally responsible operations. All ANS datacentres run on 100% renewable electricity, directly supporting EU sustainability and carbon‑reduction expectations. Energy efficiency is optimised through regular energy‑use checks, proactive maintenance, and staff environmental‑awareness measures. Cooling systems use air‑cooled DX chillers in N+1 configuration alongside cold‑aisle containment, significantly improving airflow efficiency and reducing power consumption. ANS maintains strict configuration and equipment upkeep to ensure high operational efficiency and minimise unnecessary energy draw. Waste‑reduction practices include controlled recycling points, WEEE‑compliant disposal, and reuse or donation of electronic equipment. Broader framework standards adopted by ANS also mandate adherence to the 2024 Best Practice Guidelines for the EU Code of Conduct on Data Centre Energy Efficiency, reinforcing alignment with EU expectations for energy monitoring, performance reporting, and sustainability‑focused operations.
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Up to £1,000 of platform credits accessible for a single calendar month.
Discount
- Provide your minimum discount applicable to your baseline prices
- 0%
Formula for calculating price of your services
- Formula for calculating price of your services
-
Which of the core deployment models you intend to offer
Private CloudPrivate Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
- =
- Baseline Pricing
- Buyers can find our baseline pricing on G-Cloud Service lines for Private Cloud, Virtual Private Cloud, Sovereign Cloud and DRaaS.
- -
- Minimum Discounting
- 0%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- No additional sources of cost.
- -
- Additional sources of cost reduction
- No additional sources of cost reduction.
Mandatory certifications
- Mandatory certifications
-
Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure
ResellerCloud service suppliers you intend to resell with evidence
Organisation 1
Organisation name
MicrosoftWebsite address/upload for organisation
Website addressWebsite address
https://marketplace.microsoft.com/en-us/marketplace/partner-dir/3e60f945-19c7-48b2-b721-096ae586d0e5/overviewOrganisation 2
Organisation name
AWSWebsite address/upload for organisation
Website addressWebsite address
https://partners.amazonaws.com/partners/001E000000lZHGRIA4/ANS%20GroupISO 9001 certification
ProvidedISO 27001 certification
ProvidedISO 20000-1 certification
ProvidedAre you reliant on the Cloud Service Provider for some accreditations
NoISO 14001 certification
ProvidedISO 27017 certification
ProvidedAre you bidding to provide services under Lot 1b or both Lot 1a and Lot 1b?
No
Cyber Essentials
- Do you have a Cyber Essentials Plus certificate?
- Yes
- Cyber Essentials Plus certificate Number
- 9f752e61-ca81-49da-a1d0-5b982f14ce38
Non-mandatory Standards and certifications
- ISO 28000:2022 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- PCI Security Standards Council
- PCI DSS accreditation date
- Friday 8 August 2025
- What the PCI DSS doesn’t cover
-
No cardholder data in scope.
No insecure services, protocols, or daemons.
No wireless networks in scope.
ANS does not have access to any cardholder data.
ANS does not have access to any cardholder data.
All in-scope servers have Windows
Defender AV solution installed.
All removable media is disabled by default
No bespoke and custom software development
The only bespoke solution is TechDB
No public-facing web applications in scope.
No pre-production environment
No system development
No application and system accounts in scope.
No user access to query repositories of stored cardholder data.
No remote access to customer premises
No cardholder data or customer access in scope.
MFA system is not susceptible to replay attacks
No application and system accounts that can be used interactively.
No media with cardholder data.
No hard-copy materials with cardholder data.
No POI devices that capture payment card data in scope.
No CHD in scope.
ANS is not a multi-tenant provider.
No payment pages in scope.
No cryptographic suites or protocols in scope.
There are no TPSPs in scope.
There is no cardholder data in scope. - Other security certifications
- Yes
- Any other security certifications
-
- ISO27018: 2019 - information Security Systems
- ISO42001 - AI
- ISO27017: 2015 - Information Security Systems
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-