Cloud Hosting Services
VE3 Cloud Platform brings together the right technology, process and culture to help Buyers leverage the efficiency and agility of Cloud. It is a portfolio of cloud services in a single management platform. Designed to support the crucial stages of every journey, from build and migration, application and infrastructure services.
Features
- Strong vendor relationships (Azure, AWS, Google Cloud Platform, UK Cloud)
- Advanced user portal. 24x7x365 cloud operations
- Support for IaaS, PaaS and SaaS solutions across Multi-Cloud
- Pre-built integrations for all major suppliers
- A catalog of support services
- Self-help videos and materials
- Container workload management
- Full security monitoring
- Public, Hybrid, and Private cloud solutions
- Cloud Governance – Cost Comparison and Control
Benefits
- Gain control of Multi-Cloud deployments
- Real-time dashboards across the estate
- Monitoring and Service Desk integration
- Cost Management & Optimisation
- On-shore and Off-shore Cloud Operations Centres
- Patching, Upgrades and Support of Operating environments
- Multi-Tenant or Dedicated modes
- Reliability, Privacy and Cyber Security
- Service Delivery Manager and Reporting
- Self-provisioning Service Catalogues
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 5 8 7 0 8 2 3 8 3 7 9 2 7 2
Contact
VE3 GLOBAL LTD
Nikhil Alex
Telephone: 02045520840
Email: prime@ve3.global
About your service
- Service categories
-
IaaS
IaaS Compute
Virtualised x86
- General purpose
Service scope
- Service constraints
- Quaterly upgrades, agreed scheduled downtime for updates. Customer are always on the latest version.
- System requirements
-
- Modern web browser to access the cloud management portal.
- Reliable internet connection for service access and management.
- Buyer-managed endpoint security on all connecting devices.
- SSH or RDP client for hosted VM access.
- Identity provider supporting SAML or OIDC authentication.
- Customer-owned OS or application licences where applicable.
- VPN or secure link for private/hybrid cloud connectivity.
- Defined IAM roles for administrative access control.
- API-capable tools for automation and provisioning.
- Minimum device security baseline per buyer’s policy.
- Cloud deployment model
- Public cloud
User support
- Email or online ticketing support
- Yes
- Support response times
- 24*7
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Standard (Bronze): Business-hours support (09:00–17:30 UK), incident and request handling, access to cloud support engineers, and monthly service reporting.
Enhanced (Silver): Extended-hours cover (07:00–20:00 UK), proactive monitoring, and improved response SLAs.
Premium (Gold): Full 24×7 support, continuous monitoring, priority P1/P2 incident handling, and scheduled service reviews.
Managed (Platinum): Comprehensive 24×7 managed service including optimisation, patching, release management, and lifecycle operations.
Support costs vary depending on the tier selected and service scope.
A dedicated Service Delivery Manager and Cloud Support Engineer/Technical Account Manager are provided for higher-tier services. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide a structured onboarding process that includes guided setup, access to user documentation and configuration templates, and an introduction to the management portal. Online training sessions and walkthroughs are available to help users deploy and manage their environments. Customers also receive support from cloud engineers during initial setup to ensure accounts, permissions, networks and resources are configured correctly. Onsite enablement can be provided if required.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- At contract end, users retain full ownership and control of their data and can extract it at any time before service termination. Data can be exported directly through the cloud providers’ native tools, including snapshot downloads, object storage exports, database backups, VM images, logs, and configuration files. Users may also extract data via APIs, CLI commands, bulk export utilities, or automated scripts. VE3 provides guidance on recommended export methods and ensures required access rights remain active during the offboarding period. If requested, we can supply a data-extraction checklist and support engineers to assist with large-scale transfers or migrations to another environment. No data is deleted until the buyer confirms successful extraction and sign-off.
- End-of-contract process
-
At the end of the contract, users are notified of the upcoming expiry and provided with a defined offboarding window to extract their data and transition workloads. During this period, access to the management portal, APIs and support channels remains available so users can export data, remove resources, or migrate services to another provider. Once the buyer confirms that all data has been successfully extracted, VE3 schedules the orderly shutdown and deletion of remaining environments in line with security and data-sanitisation policies.
The standard contract price includes offboarding guidance, continued access to the portal, maintenance of user permissions, and confirmation of secure data deletion. Additional costs apply only if buyers require extended support—for example, migration assistance, large-scale data transfers, custom export tooling, or project-managed transition services. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Using the web interface
-
All Lot 1a services include a secure, browser-based web interface that allows authorised users to provision, configure, monitor and manage cloud resources. Through the web console, users can set up services, deploy infrastructure components (compute, storage, networking and PaaS resources), configure security policies, review billing and usage, manage IAM roles and perform operational tasks such as scaling, backup configuration and health monitoring.
Users can make changes at any time through the interface, including modifying resource parameters, updating configurations, creating or deleting instances, integrating services or adjusting cost controls. Access is role-based, ensuring users only perform actions permitted by their assigned permissions.
Limitations vary by provider but typically include: some advanced automation functions requiring CLI/API/Terraform; certain enterprise integrations or custom deployments requiring backend or assisted configuration; and infrastructure-level restrictions based on buyer governance policies. The interface supports multi-factor authentication, audit trails and role-based access to maintain security and compliance. - Web interface accessibility standard
- WCAG 2.2 AA
- Web interface accessibility testing
- Cloud consoles provided by major vendors (Azure, AWS, Google Cloud, Oracle, VMware and SAP) undergo regular accessibility testing, including compatibility with screen readers (JAWS, NVDA), keyboard-only navigation, high-contrast modes and zoom tools. VE3 additionally validates key user workflows during onboarding to ensure compatibility for users relying on assistive technologies. No accessibility barriers have been identified for standard administrative operations.
- API
- Yes
- What users can and can't do using the API
-
Authorised users can use our REST/JSON APIs and the underlying cloud-provider APIs to provision, configure and manage environments. Typical operations include creating and updating compute, storage and networking resources; deploying and scaling PaaS components such as databases, integration services and data platforms; managing identities, tags, policies and cost controls; and retrieving monitoring, logging and billing data.
Users can set up services through the API by creating a tenant or subscription, defining resource groups or projects, and deploying parameterised templates or infrastructure definitions. Changes are made by updating resource definitions or calling configuration endpoints, and can be fully automated through CI/CD pipelines or infrastructure-as-code tools.
Limitations include role-based restrictions on destructive or security-sensitive operations, provider-imposed rate limits, and certain advanced features that may only be available through the management console or controlled change-management processes rather than through the public API. - API automation tools
-
- Ansible
- Chef
- Terraform
- Puppet
- Other
- Other API automation tools
-
- Google Deployment Manager
- AWS CloudFormation
- API documentation
- Yes
- API documentation formats
- Command line interface
- Yes
- Command line interface compatibility
-
- Linux or Unix
- Windows
- MacOS
- Using the command line interface
-
Users can use the CLI tools (Azure CLI, AWS CLI, gcloud CLI, and VE3-supported automation scripts) to provision and manage cloud resources programmatically. Through the command line, users can set up services by authenticating to their tenant or subscription, creating resource groups or projects, and deploying infrastructure templates or configuration files. They can also create, update or delete compute, storage and networking resources; manage identities and policies; trigger deployments; and integrate CLI commands into automation pipelines.
Users can make changes at any time through the CLI, including modifying configuration parameters, scaling environments, retrieving logs or metrics, exporting resource definitions and managing cost or tagging structures. CLI usage supports scripting, Infrastructure-as-Code workflows and CI/CD automation.
Limitations include: role-based access restrictions for sensitive or destructive operations; certain advanced or provider-specific features only being available through the web console; and provider-imposed rate limits or quotas. Some complex enterprise integrations may require API or console-level configuration rather than CLI-only setup.
Scaling
- Independence of resources
- Isolation is maintained through cloud-provider virtualisation, dedicated resource allocation models and strict multi-tenant separation. Compute, storage and networking resources are provisioned within each customer’s own subscription, project or account, ensuring workloads are isolated from other users. Capacity is monitored continuously and auto-scaling mechanisms ensure demand surges do not impact neighbouring environments. Network traffic is segmented using VPCs/VNETs and security groups, while storage performance tiers prevent noisy-neighbour effects. Role-based access controls and policy guardrails ensure configuration boundaries are maintained. VE3 monitors resource utilisation and applies optimisation or scaling actions as needed to preserve consistent performance for each tenant.
- Usage notifications
- Yes
- Usage reporting
-
- API
- SMS
- Optimising consumption
- Yes
- Automatic scaling
- Yes
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Google Cloud Platform services, Amazon Web Services, Microsoft Azure
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Backup and recovery
- What’s backed up
-
- Virtual machine backups including full images and incremental snapshots.
- Databases with point-in-time recovery and automated scheduled backups.
- File systems and shared storage volumes across cloud environments.
- Object storage buckets and versioned data repositories.
- Application configurations and environment settings for rapid restoration.
- Container workloads and persistent volumes in managed Kubernetes services.
- Network configurations such as firewalls, load balancers and routing tables.
- Identity and policy definitions for IAM and access controls.
- Logs, monitoring data and operational metrics retention backups.
- Infrastructure templates and deployment definitions for rebuild automation.
- Backup controls
- Users manage backups through the console, CLI or API. They can choose which resources to protect - VMs, databases, storage volumes or applications and assign different schedules, retention periods and backup types. Policies can be applied individually or across groups, and users can enable, disable or modify backup settings at any time. Tag-based rules allow automated backups for selected resources. Role-based access ensures only authorised users can change backup configurations or perform restores. VE3 provides default policy templates, but users retain full control over what is backed up and how frequently.
- Datacentre setup
- Multiple datacentres with disaster recovery
- Scheduling backups
- Users schedule backups through a web interface
- Backup recovery
- Users can recover backups themselves, for example through a web interface
- Backup and recovery
- Yes
- RPO/RTO
- Yes
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
-
Our guaranteed availability aligns with the underlying service-level commitments of the major cloud providers we support, typically ranging from 99.9% to 99.99% availability depending on the service type and deployment architecture. High-availability configurations such as multi-AZ or regionally redundant deployments for compute, storage, databases and networking—are designed to meet the upper end of these thresholds. VE3 continuously monitors service health, applies best-practice resilience patterns and advises customers on architectural choices that align with their required uptime targets.
Availability is measured monthly, and customers are automatically eligible for service credits if uptime falls below the guaranteed SLA. These credits are provided in accordance with the SLA policies of the respective cloud provider (AWS, Azure or Google Cloud), and VE3 passes them through directly to the customer. In addition, VE3 performs root-cause reviews for any material outage and provides remediation recommendations to prevent recurrence. This combined approach ensures customers receive consistent, predictable availability across their hosted environments. - Approach to resilience
-
Our service is designed with multi-layer resilience across infrastructure, platform and operations. Workloads are deployed on major cloud providers that offer multiple geographically separated datacentres (regions and availability zones), enabling automatic failover and continuity in the event of hardware or site issues. Core services such as compute, storage, networking and databases support multi-AZ configurations, regional redundancy and built-in fault tolerance. Data is replicated across zones to protect against localised failures, and optional cross-region replication is available for enhanced resilience.
Network architecture incorporates redundant routing, load balancing and health-based failover. Storage platforms provide durability through distributed replication, integrity checking and automated repair. VE3 continuously monitors resource health, applies resilience best practices, and enforces policies that ensure high-availability deployment patterns.
Operational resilience is supported through automated backups, infrastructure-as-code templates, version-controlled configuration, and disaster recovery options aligned to customer RTO/RPO requirements. Incident response processes, protective monitoring and regular testing ensure rapid recovery from disruptions. More detailed infrastructure resilience information can be provided to buyers on request. - Outage reporting
-
Our service provides comprehensive, multi-channel outage reporting to ensure customers receive timely and accurate visibility into any service disruption. Outage information is published through the major cloud providers’ public service-status dashboards, which present real-time updates on the availability of compute, storage, networking, and platform services across all regions and availability zones. These dashboards include incident details, impacted services, current status and progress toward resolution.
In addition to public dashboards, VE3 provides email alerts to designated customer contacts for both platform-wide incidents and customer-specific issues. Alerts include initial identification of the issue, severity, potential impact, and any required customer action. Updates are sent throughout the lifecycle of the incident until resolution, along with a final closure notification.
For customers requiring automated integration, cloud-provider status APIs can be consumed to feed real-time incident information into monitoring systems, ticketing platforms, or SIEM tools. VE3 also publishes incident notifications and updates through the support portal, where customers can track active issues, review historical outages and download post-incident reports.
Following any material outage, VE3 conducts a root-cause analysis and shares remediation actions to prevent recurrence, ensuring transparent and proactive communication throughout.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access control (RBAC), least-privilege principles, and multi-factor authentication (MFA). Administrative actions are limited to authorised personnel within defined roles, with segregation between support, operations and security teams. All access is logged, monitored and periodically reviewed. Customer environments are isolated within separate tenancies or subscriptions, preventing cross-tenant access. Support channels enforce identity verification before any change is made, and sensitive operations require elevated approval. Remote access uses secure channels (TLS/MFA/VPN), with Just-In-Time access available where supported to minimise exposure windows.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
- Devices users manage the service through
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We operate an information security management framework aligned to ISO 27001, Cyber Essentials Plus and the security controls of the underlying cloud providers. Our policies cover access control, change management, incident response, data protection, vulnerability management, secure development and supplier governance. Policies are reviewed annually or when significant changes occur, and are approved by our Board-level Security Lead (CISO).
Security governance follows a defined reporting structure: operational security teams report into the Security Manager, who reports to the Head of Security, with oversight from the CISO. Regular internal audits, automated compliance checks and continuous monitoring ensure policies are consistently followed across environments. Mandatory staff training, role-based access, segregation of duties and defined approval workflows help enforce security standards.
Incidents and policy deviations are logged, investigated and escalated through our incident management process, with corrective actions tracked to closure. VE3 also aligns its controls to the shared responsibility model of AWS, Azure and GCP, ensuring customer and provider responsibilities remain clearly defined.
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We follow a controlled, ITIL-aligned configuration and change management process. All components are defined and tracked using infrastructure-as-code templates stored in version control, creating a full audit trail and enabling consistent, repeatable deployments. Assets are registered in a configuration repository and tagged to track ownership, environment and lifecycle. Changes follow a formal workflow: request, assessment, approval, implementation and review. Each change is evaluated for security impact, including access, encryption, network exposure, dependency effects and compliance. High-risk changes require security or CAB approval. All updates are tested in non-production and logged to support audit and traceability.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We operate a continuous vulnerability management process aligned to ISO 27001 and cloud-provider best practices. Potential threats are assessed through automated scanning, configuration assessments, threat-intelligence feeds and monitoring alerts from AWS, Azure and Google Cloud. High-severity issues are prioritised and patched as soon as provider updates are released, typically within defined SLA windows. We source threat information from vendor advisories, CVE databases, CERT notifications and security monitoring tools. All remediation actions are tracked, documented and verified through follow-up scans.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We use continuous protective monitoring across cloud environments, combining cloud-native security tools, log analytics, SIEM alerts and behavioural analysis to identify potential compromises. Indicators such as unusual access patterns, privilege escalation, configuration drift, failed authentication attempts or anomalous network activity are automatically flagged for review. When a potential compromise is detected, it is triaged immediately, escalated to the security team and investigated using predefined incident-response playbooks. Containment actions are applied promptly, followed by remediation and root-cause analysis. High-severity security incidents receive rapid response, typically within minutes, in line with our security SLA.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a formal, ITIL-aligned incident management process with **pre-defined runbooks** for common events (service degradation, access issues, capacity problems, security alerts and backup/restore failures). Incidents can be reported by users via the **service desk portal, email or phone**, and high-severity events may also be raised automatically from monitoring and alerting tools. All incidents are logged, categorised and prioritised with agreed response and resolution targets. We keep users informed through status updates during investigation and resolution. For **major incidents**, we provide a written **incident report** detailing timeline, root cause, impact, corrective actions and preventive measures, typically within an agreed timeframe.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Third-party
- Third-party virtualisation provider
- Hyperscale cloud provider – Azure, AWS, Google Cloud, Oracle, VMware
- How shared infrastructure is kept separate
- We use the hyperscaler’s multi-tenant virtualisation and logical isolation controls to ensure complete separation between organisations. Each customer operates within a dedicated tenancy/subscription, isolated virtual networks and resource groups. The underlying platform enforces strong separation through hypervisor-based isolation, container sandboxing, kernel-level security, and memory, CPU and I/O separation that prevents cross-tenant access. Network segmentation, firewalls, security groups and identity boundaries further ensure workloads cannot interact unless explicitly configured. Storage is logically isolated with encrypted, tenant-scoped keys. The provider regularly validates isolation through independent audits, penetration testing and compliance certifications.
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- Our underlying hyperscale cloud providers (Microsoft Azure, AWS, Google Cloud, Oracle Cloud, VMware) operate datacentres that follow the EU Code of Conduct for Energy-Efficient Datacentres. They implement industry-leading efficiency measures including: advanced cooling technologies (free-air, liquid, evaporative cooling) energy-efficient power distribution and UPS systems server virtualisation and high-density compute to reduce energy per workload continuous monitoring of PUE (Power Usage Effectiveness) with targets typically ≤1.2 in modern sites renewable energy procurement and carbon-reduction programmes ongoing audits and lifecycle optimisation aligned to EU-CoC best practices
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount
- Provide your minimum discount applicable to your baseline prices
- 3%
Formula for calculating price of your services
- Formula for calculating price of your services
-
Which of the core deployment models you intend to offer
Public CloudPublic Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Public Cloud Deployment
- =
- Baseline Pricing
- Baseline pricing is usage-based and is determined from published unit rates for the Public Cloud components that make up the buyer’s requirement (for example compute, storage, networking, and managed platform services), plus any VE3 standard service charges that are explicitly priced as part of the service offering. Buyers identify the baseline by selecting the required service components (region, tier, instance/service size, storage class and expected usage volumes such as hours/GB/requests) and multiplying expected usage by the published unit rates shown in the service’s Pricing section. Where a service includes a VE3-managed or professional services element, the applicable unit/day-rate or fixed charge is also shown in the Pricing section of the relevant catalogue entry. Prices are stated in GBP and exclude VAT unless otherwise specified. The minimum discount (as stated in the ‘Discount’ question) is then applied to derive the discounted baseline before onboarding and any other cost factors are added.
- Baseline Pricing - Web link
- https://www.ve3.global
- -
- Minimum Discounting
- 3%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- Additional costs may arise where the buyer’s requirement increases scope or consumption beyond the baseline assumptions. Typical cost drivers include: higher-than-forecast public cloud consumption (for example increased compute hours, storage growth, managed database throughput, or API/request volumes); network and connectivity requirements (VPN/peering/private connectivity where applicable); high outbound data transfer (egress) volumes; enhanced security/compliance controls (for example WAF, SIEM/SOC integration, vulnerability scanning, encryption/HSM, additional audit requirements); backup and disaster recovery requirements (multi-region resilience, longer retention); increased logging/monitoring retention and observability tiers; additional environments (dev/test/stage/perf); premium support hours (24x7) and tighter incident SLAs; third-party software licensing/marketplace subscriptions; and change requests for non-standard configurations or accelerated delivery. Where underlying cloud services are priced in non-GBP currencies, exchange-rate movements may also affect pass-through consumption costs.
- -
- Additional sources of cost reduction
- Cost reductions may apply in addition to the stated minimum discount through: commitment-based discounts offered by public cloud providers (for example Reserved Instances/Savings Plans/Committed Use) and volume-based pricing where applicable; right-sizing and autoscaling to reduce unused capacity; scheduling and shutdown of non-production environments out of hours; use of spot/preemptible capacity where appropriate; storage lifecycle management (tiering to lower-cost storage/archival); consolidation of shared services (logging/monitoring/network components) across workloads; use of existing customer licences (BYOL) where permitted; and sector-specific discounts or service bundling where included in the service pricing. VE3 can also provide FinOps optimisation and continuous cost governance so that reductions identified are reflected in revised run-rate forecasts and monthly charges.
Mandatory certifications
- Mandatory certifications
-
Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure
ResellerCloud service suppliers you intend to resell with evidence
Organisation 1
Organisation name
MicrosoftWebsite address/upload for organisation
Website addressWebsite address
https://marketplace.microsoft.com/en-us/marketplace/partner-dir/a8f16248-ee13-4012-992e-7f59ac04718a/overviewOrganisation 2
Organisation name
SAPWebsite address/upload for organisation
Website addressWebsite address
https://partnerfinder.sap.com/profile/0002938305Organisation 3
Organisation name
GoogleWebsite address/upload for organisation
Website addressWebsite address
https://partners.amazonaws.com/partners/0018W00002FlNE5QAN/Organisation 4
Organisation name
AWSWebsite address/upload for organisation
Website addressWebsite address
https://partners.amazonaws.com/partners/0018W00002FlNE5QAN/Organisation 5
Organisation name
SalesforceWebsite address/upload for organisation
Website addressWebsite address
https://appexchange.salesforce.com/appxConsultingListingDetail?listingId=a0N3u00000RgZXnEANOrganisation 6
Organisation name
DatabricksWebsite address/upload for organisation
Website addressWebsite address
https://appexchange.salesforce.com/appxConsultingListingDetail?listingId=a0N3u00000RgZXnEANISO 9001 certification
ProvidedISO 27001 certification
ProvidedISO 20000-1 certification
ProvidedAre you reliant on the Cloud Service Provider for some accreditations
Yes
Cyber Essentials
- Do you have a Cyber Essentials Plus certificate?
- Yes
- Cyber Essentials Plus certificate Number
- F46b0858-b762-40d1-9775-dbf1fc93978b
Non-mandatory Standards and certifications
- ISO 28000:2022 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 27001
- ISO 14001
- ISO 22301
- ISO 9001
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-