Skip to main content

Help us improve the Digital Marketplace - send your feedback

STONESTHRO LTD

Agger Labs - Ransomware Protection Platform

Agger Labs provides endpoint ransomware protection that detects and terminates threats in milliseconds, including zero-day attacks. The solution operates locally on endpoints without signatures, AI, or cloud connectivity, works alongside existing EDR tools, and supports legacy Windows systems from Server 2000 onwards.

Features

  • Anti-Ransomware
  • Endpoint Protection
  • Legacy OS Support
  • EDR integration
  • API Driven Architecture
  • Rapid Deployment via existing deployment tools
  • Local-only processing
  • SE Labs AAA Certification

Benefits

  • Protects against Zero-Day Ransomware
  • No performance impact for Servers and Workstations
  • Enhance existing Security
  • Rapid installation
  • Millisecond Mitigation
  • No disruption to existing security stack
  • Zero configuration needed
  • No training period requirement

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andy.bates@stonesthro.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 3 2 8 0 7 5 8 7 6 1 4 0 7 2

Contact

STONESTHRO LTD Andy Bates
Telephone: 07880783166
Email: andy.bates@stonesthro.co.uk

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
EDR, DLP, Anti-Virus and Malware Prevention solutions
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
None
System requirements
  • Windows 7 and above
  • Linux

User support

Email or online ticketing support
Yes
Support response times
Within 1 business day
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Agger Labs provides a single, enterprise-grade support level included with the Ransomware Protection Platform subscription.

Support requests are submitted via email at support@agger-labs.com. Technical support is available 24/7 by email. Requests are prioritised by severity.

Critical issues, such as service unavailability or major security impact, receive an initial response within one hour, 24/7.

High-severity issues target an initial response within four hours.

Medium-severity issues are typically responded to within eight UK business hours, and low-severity requests within one UK business day.

Initial response times refer to acknowledgement and start of investigation; resolution times vary by issue complexity.

Agger Labs does not provide a dedicated Technical Account Manager or cloud support engineer as standard.

Customers work directly with Agger Labs’ engineering and security team for support and incident response. Enhanced support arrangements can be agreed contractually if required.
Support available to third parties
No

Onboarding and offboarding

Getting started
Simple online video
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
N/A as no data is part of any contract
End-of-contract process
License becomes inactive - no other measures needed
Documentation accessibility standard
None or don’t know
How the documentation is accessible
N/A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • Linux or Unix
  • Windows
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Web User Interface and Dashboard
Accessibility standards
None or don’t know
Description of accessibility
Via Web Portal
Accessibility testing
Not Applicable
API
Yes
What users can and can't do using the API
The Agger Labs API provides programmatic access to the same core functionality available through the web management console. It is a RESTful API secured using OAuth2 client credentials.

Using the API, customers can set up and manage their service by registering API credentials and obtaining an access token.

Once authenticated, users can manage endpoints, retrieve endpoint status, query incidents, security events, and alerts, and integrate Agger data into external SIEM, SOC, or reporting systems.

Routine operational changes, monitoring, and reporting can all be performed via the API rather than the web interface.

Access to API functionality is permission-based and scoped to the customer’s account.

Full endpoint definitions, supported operations, and required permissions are documented in the Agger API documentation and Swagger interface.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
Auto-scaling in place with Cloud Providers

Analytics

Service usage metrics
Yes
Metrics types
Endpoint information which includes items such as Protection Status, Detections, Patch Levels, and Applications installed
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Agger Labs

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
No
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Users can export reporting data via the API, there is no PII data stored anywhere
Data export formats
Other
Other data export formats
JSON
Data import formats
Other
Other data import formats
Not Applicable

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
All data is encrypted between the endpoint and the cloud using modern encryption standards
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
All data is encrypted with modern encryption standards

Availability and resilience

Guaranteed availability
Agger Labs guarantees a monthly uptime availability of 99.99% for the core functionalities of the Agger Ransomware Protection Platform Cloud component, as defined in the Service Level Agreement (SLA).

This includes availability of the management console, receipt and processing of telemetry from endpoint agents, and delivery of threat intelligence updates.

Planned maintenance is communicated in advance and excluded from downtime calculations. Emergency maintenance required to preserve service security or stability is also excluded where applicable. The endpoint agent is designed to continue providing baseline ransomware protection locally, even if temporary connectivity to the cloud platform is unavailable.

If Agger Labs fails to meet the guaranteed uptime commitment in a given calendar month, customers may be eligible for service credits.

Where monthly uptime falls below 99.9%, a 10% service credit applies. Where uptime falls below 99.0%, a 25% service credit applies, capped at 50% of the monthly service fee. Service credits are applied to future invoices and represent the sole and exclusive remedy for availability failures.
Approach to resilience
Available on request
Outage reporting
Outages are reported via the Agger Dashboard, API and email alerts

Identity and authentication

User authentication needed
No
Access restrictions in management interfaces and support channels
Standard MFA is used
Access restriction testing frequency
At least every 6 months
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Agger Labs operates a pragmatic security governance model appropriate to the size and nature of the business. Security decisions are led by senior technical leadership and embedded into product design, development, and operations. Governance focuses on risk assessment, least-privilege access, secure software development practices, change control, vulnerability management, and incident response. Security is reviewed regularly and adapted as the threat landscape, customer requirements, and platform architecture evolve. While Agger Labs is not formally certified to an external security governance standard at this time, security governance is treated as a core operational responsibility.
Information security policies and processes
Andy B to fill in
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All change control is tracked and governed through the internal change management process. Every change is then fully tested through a holistic testing regime before its released
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Constant checking of all known and new threats are tested against the platform. Given the platform stops all Ransomware (known and unknown) and the team are SME's in hacking, this process is always live
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
The Agger Ransomware Protection platform stops Ransomware in milliseconds. Given the nature of the service, and the claims made (and independently tested by SE Labs), our protective monitoring is constant. We have SLA's with response times for any other compromises outside of Ransomware
Incident management type
Supplier-defined controls
Incident management approach
We provide up to date information to customers via Slack (or other means if not) to ensure all reports are timely.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Full trial version for up to 10 endpoints for a period of 2 weeks

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7.5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
18%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Eda8b040-5636-4501-8dfd-375f408288e3
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • HIPAA via Zadara as primary cloud provider
  • ISO27017 of our primary supplier Zadara
  • SOC1 via Zadara primary cloud supplier
  • SOC2 via Zadara primary cloud supplier
  • ISO27018 via Zadara primary cloud supplier
  • IRAP via Zadara primary cloud supplier

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andy.bates@stonesthro.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.