Skip to main content

Help us improve the Digital Marketplace - send your feedback

Xerox (UK) Ltd

SaaS Backup and DR as a Service

The Xerox IT Services SaaS Backup and DR as a Service offers backups of SaaS platforms in a unified solution. This service is hosted in a Microsoft Azure ISO 27001 certified environment.

Features

  • Immutable design
  • Purpose built
  • Inverse chain technology
  • Exclusive cloud deletion defence
  • 100% recovery confidence
  • Deployment flexibility

Benefits

  • Fully managed service from the UK based IT Service desks
  • 24x7x365 Service Desk Operating Hours
  • High levels of data reliability
  • Fast recovery speed
  • Integrates with many other Managed Services

Pricing

£2.50 a user

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uxb.bidteam@xerox.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

8 4 5 5 3 2 6 1 1 3 7 8 9 0 6

Contact

Xerox (UK) Ltd Steve Young
Telephone: 01895251133
Email: uxb.bidteam@xerox.com

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
None
System requirements
  • Windows Server 2016 Onwards
  • Windows 10 & 11
  • Linux
  • MacOS

User support

Email or online ticketing support
Email or online ticketing
Support response times
P1 response times start from 1 hour on evenings or weekends depending on the service package included.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
The managed service can include on-site technical support for a fixed monthly fee with unlimited access or available per hourly fee.

All customers have an assigned Service Delivery Manager and Account Manager.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
A scoping meeting is arranged with the client, Solution Architect and Account Manager takes place in the first instance to confirm the backup solution and create an agreed Statement of Works.

Then a Project Manager & Solution Engineer will work with the customer to implement the service before the Service Delivery Manager then provides ongoing support on the backup service.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Data is exported in an agreed format at an agreed cost at the end of the contract through our established off boarding process.
End-of-contract process
Once the notice of termination has been provided the Service Delivery Manager will confirm the exact service end date and any early termination fees (if applicable). A final service end date is then agreed before any further tasks such as data export is undertaken.

Using the service

Web browser interface
No
Application to install
Yes
Compatible operating systems
  • Linux or Unix
  • MacOS
  • Windows
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Xerox IT Services manage the access to the service interface to run, restore, check backups etc. as part of the Managed Service.
Accessibility standards
None or don’t know
Description of accessibility
Xerox IT Services manage access to the backup systems on behalf of the customer as part of the Managed Service.
Accessibility testing
None.
API
No
Customisation available
No

Scaling

Independence of resources
The cloud environment is load balanced with Quality of Service rules in place to ensure the service is not saturated by one client.

The environment is also massively scalable and can be quickly scaled if required.

Analytics

Service usage metrics
Yes
Metrics types
Statistics on backup sizes, compression, dedupe, storage size remaining etc.
Reporting types
Regular reports

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Datto & Veeam

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with SSAE-16 / ISAE 3402
Data sanitisation process
Yes
Data sanitisation type
Explicit overwriting of storage before reallocation
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Xerox IT Services export the data on an agreed media device on behalf of the customer.
Data export formats
  • CSV
  • ODF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
An SLA of 99% uptime of the Cloud Environment uptime. Service credits are provided if the service does not meet the agreed SLA.
Approach to resilience
Provided on request.
Outage reporting
Client receive notification via email or phone in case of a P1 outage. Once resolved all impacted clients are provided an Incident Report.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Username or password
Access restrictions in management interfaces and support channels
Only authorised Xerox IT Services technicians will be able to access and manage the system.
Access restriction testing frequency
At least once a year
Management access authentication
  • 2-factor authentication
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
The Xerox Information Security Policy, Infosec001, is aligned to the ISO27001 key controls and the policy is supplemented by additional documents detailing specific requirements to meet the policy. Specific locations and services in Xerox are certified to ISO27001
Information security policies and processes
Xerox utilise a documented framework (Xerox InfoSec 001) for security governance both at a company level and specific to the service which is aligned to NCSC guidance and ISO27001. This provides assurance that reporting is completed and reviewed across all aspects of the service. The Xerox CEO has ultimate responsibility for security. Xerox’s commitment to Information Security is communicated throughout the organisation and its partners, and is evidenced by board level approval of the Xerox Information Security Policy. The Information Security-related responsibilities of the CEO include: • Overall control and management of Information Security for Xerox in the UK; • Overall information risk ownership; • Provision of adequate resources for Information Security; and, • Approval authority for Information Security policy. • Reporting compliance Reporting is subject to review by senior management. There are processes in place to review and understand any current legal and regulatory requirements and to review an implement any future changes. The Xerox Information Security team monitor various sources for changes to legislation and are currently on the UK Government CiSP which allows us to engage with Government on proposed changes.

Operational security

Configuration and change management standard
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach
Utilization of Industry standard Change management from beginning to end of contract life. All changes are validated against NIST standards and for any potential security risk or security impact.
Vulnerability management type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach
Utilization of real-time vulnerability scan and network analysis, all remediation is automated and responded to within in moments of identification. Critical security patches are deployed within 72 hours of notice of availability. System patches are applied within 14 days of availability for non-critical patches. Our resources for threats is derived from multiple sources including Threat management / remediation provider.
Protective monitoring type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach
We utilize a multi-pronged set of systems from Network traffic monitoring, heuristic behavior analysis, known threats, and Artifical Intelligence based system nominal state behavior tracking. A potential compromise is quarantined and analyzed immediately via Ai then escalated to personnel if unable to categorize. Most actions are completed within 15-30 minutes of identification.
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
We utilize a governed set of processes defined internally by the CISO and report via email / web portal. Reports are genereated post critical incident and root cause analysis

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

Fighting climate change

Fighting climate change

Xerox is committed to fighting climate change such that we play a role in the sustainability of our world’s natural resources. Xerox has identified four strategic commitment areas where we can make a significant impact on the environment:

• Reducing Energy Use and Protecting the Climate:
• Preserving Biodiversity and the World's Forests:
• Preserving Clean Air and Water:
• Preventing and Managing Waste:

We invest in technologies that reduce the carbon footprint of our operations and offer solutions to our customers that reduce energy use, cost and waste. Our Net Zero goal is 2040. In 2021, we also expanded our greenhouse gas (GHG) emissions reduction goal to cover scopes 1, 2 and 3. We plan to achieve net-zero emissions through projects that improve operational efficiency, create new technology innovations, and neutralise residual GHG emissions through carbon compensation mechanisms. Our approach to sustainability includes partnerships to accelerate progress. We have officially joined the UNFCCC’s Race to Zero and SBTi’s Business Ambition for 1.5°C campaigns, aligning our climate mitigation targets to what science dictates is necessary to reduce the destructive impacts of climate change on human society and nature.

We are a founding member of Defra’s e-Sustainability Alliance (DeSA), We are actively involved in the provision of best practices on the ways in which IT firms of all sizes can minimise their environmental impacts. We also support the Government Cloud Sustainability project, focusing on ‘Sustainable IT’ (e.g. achieving net-zero, modern slavery and other supply chain matters) and ‘IT for Sustainability’ – including the social pillar, “How to procure and measure performance on all things Cloud”. When selecting our technologies and services for G-Cloud 14, we have utilised this knowledge base and ensured that the services & technology used comply with Government guidance and carry accreditation from 3rd party bodies where appropriate.

Pricing

Price
£2.50 a user
Discount for educational organisations
Yes
Free trial available
No

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uxb.bidteam@xerox.com. Tell them what format you need. It will help if you say what assistive technology you use.