AG - (I-SaaS) - Systems Infrastructure Software - Storage
AG Consultancy provides storage management software services supporting data protection, resilience, and performance for SAP and platforms. Services include backup, recovery, replication, archiving, migration, and software defined storage. These services support SAP HANA, SAP S/4HANA, and SAP BTP workloads, ensuring data availability, integrity, and compliance with retention and governance requirements.
Features
- Browser-based storage management platform with secure authenticated user access
- Centralised monitoring of storage capacity, performance and utilisation metrics
- Storage configuration management with controlled change capabilities
- Real-time alerts for capacity thresholds, performance issues and failures
- Role-based access controls supporting storage governance and segregation
- Encryption of storage management data at rest and in transit
- Audit logging of storage configuration changes and administrative actions
- Scalable multi-tenant architecture supporting multiple storage environments
- Integration capability with existing infrastructure and monitoring tools
- Built-in reporting supporting storage visibility, optimisation and compliance
Benefits
- Improve storage visibility through centralised capacity and performance monitoring
- Prevent storage shortages using proactive capacity planning and alerts
- Optimise storage utilisation to reduce waste and unnecessary infrastructure costs
- Improve storage performance by identifying bottlenecks and inefficiencies early
- Strengthen data governance through controlled access and configuration managemen
- Support compliance with audit-ready logging and traceable storage changes
- Reduce operational risk through proactive monitoring and controlled change
- Simplify storage operations using a single integrated management platform
- Enable informed decisions using clear storage analytics and reporting
- Scale storage management capabilities easily as organisational data volumes grow
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 6 4 4 0 0 0 3 8 8 9 8 3 3 9
Contact
AG CONSULTANCY & APPS LTD
Bindu Benjamin
Telephone: 07775452318
Email: bindu.benjamin@agcapps.com
About your service
- Service categories
-
Systems Infrastructure Software
Storage
Data replication and protection
- Data Protection Software
- Backup and Recovery Reporting Software
- Storage Replication Software
- Host or Hypervisor-Based Replication Software
- Systems and Data Migration Software
- Fabric and Appliance-Based Replication Software
- Array-Based Replication Software
- Replication Management Software
Archiving
- Email Archiving Software
- File and Other Archiving Software
Storage infrastructure and device management
- Storage Resource Management and Heterogeneous SAN Management Software
- Storage Device Management Software
- Virtualization and Federation Software
- Host-Based File Systems and Volume Management Software
- Storage Access and Path Management Software
- Automated Storage Tiering Software
- Storage Acceleration Software
- Other Storage Management and Infrastructure Software
Software defined storage controller
- Block-Based Software-Defined Storage Controller Software
- File-Based Software-Defined Storage Controller Software
- Object-Based Software-Defined Storage Controller Software
- Hyperconverged Software–Defined Storage Controller Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service extends to buyer-owned or third-party cloud software platforms, including SAP S/4HANA, SAP Business Technology Platform, SAP analytics, integration, automation and process optimisation. It supports enterprise application management, data and analytics, process mining, workflow automation and operational assurance across existing cloud environments, without providing or hosting the underlying software.
- Cloud deployment model
- Hybrid cloud
- Service constraints
- The service has no inherent technical constraints. Support is provided for buyer-owned or third-party cloud platforms. Planned maintenance, access arrangements and support hours are agreed with buyers in advance. The service does not provide or host infrastructure and is dependent on buyer-provided access to supported environments.
- System requirements
-
- Buyer owned cloud platforms with appropriate administrative access permissions enabled
- Valid software licences for supported enterprise applications and platforms used
- Secure network connectivity enabling remote access to cloud environments securely
- Identity and access management configured for role-based service access controls
- Logging and monitoring enabled within buyer cloud environments for support
- Supported operating systems and browsers for administrative access by staff
- Compliance with public sector security standards and policies as required
- Ability to provide secure remote support access when required operationally
- Change management processes in place within buyer organisations for coordination
- Agreed service hours and escalation contacts defined before service commencement
User support
- Email or online ticketing support
- Yes
- Support response times
- AG responds to questions during agreed service hours, typically within one business day. Response times and escalation arrangements are agreed with buyers during onboarding. Weekend and out-of-hours support can be provided where required, subject to prior agreement and defined service levels.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AAA
- Web chat accessibility testing
-
AG undertakes accessibility assurance for web chat and online support tools as part of service onboarding and ongoing service management. Where web chat functionality is used, testing focuses on ensuring compatibility with common assistive technologies and accessibility features supported by the underlying platform. This includes validation of keyboard-only navigation, screen reader compatibility, text resizing, colour contrast settings and focus indicators.
Testing is carried out using commonly available assistive technologies and accessibility tools, such as screen readers and browser-based accessibility testing utilities, to confirm that core web chat functionality remains usable without reliance on a mouse or visual-only cues. This helps ensure that users can raise, track and manage support requests effectively using assistive technologies.
Where third-party ticketing or web chat platforms are used, AG reviews supplier-provided accessibility conformance statements, including alignment to EN 301 549 and WCAG standards. AG works with buyers to ensure accessibility features are enabled and configured appropriately within the chosen platform and supports remediation activities where configuration changes are required.
Accessibility considerations are included within service documentation and operational procedures. Feedback is reviewed as part of continuous service improvement to identify and address any accessibility issues that arise during live service delivery. - Onsite support
- Yes
- Support levels
-
AG provides flexible, tiered support levels designed to align with buyer requirements and operating models. Support services are tailored during onboarding and documented within agreed service definitions and service level agreements.
Standard support provides access to cloud support engineers during agreed business hours for incident management, service queries, configuration support and operational advice.
Enhanced support includes extended service hours, prioritised response times, proactive service monitoring, and regular service review meetings. This level supports environments requiring higher availability, operational assurance and ongoing optimisation.
Optional out-of-hours and on-call support can be provided for critical services, planned activities or incident response, subject to advance agreement.
Support costs vary depending on the selected support level, service hours, response time requirements and scope of services. Pricing is transparent and defined within the service listing or agreed call-off contract, typically structured as a fixed monthly service charge or agreed time-and-materials rates for specialist activities.
AG CAPPS can provide a dedicated Technical Account Manager (TAM) or Cloud Support Engineer, depending on buyer preference. The TAM acts as the primary service contact, coordinating support activity, governance, reporting and continuous improvement. Cloud Support Engineers deliver hands-on technical support and assurance across supported cloud platforms. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
AG supports users to start using the service through a structured onboarding and mobilisation process tailored to buyer requirements. This ensures a smooth transition into live service and clear understanding of support arrangements from the outset.
During onboarding, AG works with nominated buyer representatives to confirm service scope, supported cloud platforms, access requirements, escalation routes and service hours. Service documentation is provided, including service descriptions, contact details, support processes and guidance on using the service interface for raising and managing requests.
Users are supported through online onboarding sessions and walkthroughs of the service interface, explaining how to submit requests, track progress and communicate with support teams. Where required, remote or onsite workshops can be delivered to support service adoption, particularly for key users or service owners. Training is focused on how to engage with the support service rather than changes to underlying software platforms.
Written user documentation and quick-reference guides are provided to support ongoing use. These materials are maintained and updated as part of service management. AG also offers ongoing support during early service operation, allowing users to ask questions and clarify processes as they become familiar with the service. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
AG supports buyers with end-of-contract data extraction through a structured and controlled offboarding process. As a cloud support service, AG does not host or own buyer data. Data remains within buyer-owned or third-party cloud platforms throughout the contract.
At contract end, AG works with authorised buyer representatives to confirm data extraction requirements, access arrangements and timelines. Where service data exists within support tools, such as ticketing systems, this typically includes service records, incident logs, change history and service documentation. These records can be exported using standard platform functionality in commonly used formats, such as CSV or PDF, subject to the capabilities of the underlying platform.
AG CAPPS provides guidance and assistance to help buyers extract relevant service data, including instructions on export processes and validation of extracted data where required. Access to support tools is maintained for an agreed period to allow buyers to complete data extraction activities.
Once extraction is complete, AG confirms closure of access in line with agreed offboarding procedures. Any AG CAPPS-held service artefacts are retained or securely disposed of in accordance with contractual and regulatory requirements. - End-of-contract process
-
AG follows a structured end-of-contract and service offboarding process to ensure a controlled and orderly conclusion to service delivery. This process is designed to minimise disruption and support continuity for buyers.
At contract end, AG works with nominated buyer representatives to confirm the end date, exit activities, data extraction requirements and handover arrangements. Access to the service interface and support tools is maintained for an agreed period to allow completion of offboarding activities. AG supports knowledge transfer, including handover of service documentation, operational information and agreed service artefacts.
As part of standard service delivery, the contract price includes exit planning support, coordination of offboarding activities, guidance on data extraction from support tools, and confirmation of access removal in line with agreed security procedures. These activities are proportionate to the scope of the service and ensure buyers can transition smoothly at contract end.
Additional costs may apply where buyers request extended support beyond the contract end date, bespoke data analysis or transformation, additional documentation production, or hands-on assistance with migration to a new supplier or operating model. Any such additional activities are agreed in advance through change control and priced transparently on a time-and-materials or fixed-price basis. - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The core functionality of the service is consistent across desktop and mobile devices, including access to online ticketing, service information and communication with support teams. On mobile devices, the interface is presented in a responsive format optimised for smaller screens and touch interaction. Some advanced administrative or configuration activities are typically performed on desktop devices where larger displays support detailed review and analysis. Mobile access is intended to support convenience and responsiveness, enabling users to raise and track requests while away from their desks, while full operational activities are best supported through desktop access.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- The service interface is a browser-based support and service management portal. Users can raise, track and manage support requests, view service updates, access documentation and communicate with support teams. The interface supports role-based access controls and is accessible from desktop and mobile devices. It is designed to be intuitive, accessible and consistent with public sector accessibility standards, enabling efficient interaction with cloud support services without requiring software installation.
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
-
AG undertakes accessibility assurance and interface testing activities as part of service onboarding and ongoing service management to support users of assistive technology. Testing focuses on validating that the service interface, including online ticketing and service management portals, is usable with commonly available assistive technologies and accessibility features supported by the underlying platform.
This includes testing interface functionality using keyboard-only navigation to ensure all core actions can be completed without a mouse, and validating compatibility with screen readers to confirm that interface elements, labels and status messages are announced clearly and in a logical order. Text resizing, colour contrast and focus indicators are also reviewed to ensure usability for users with visual impairments.
Where third-party service management or ticketing platforms are used, AG reviews supplier accessibility documentation and accessibility conformance statements, including alignment to EN 301 549 and relevant WCAG standards. Configuration settings are reviewed and adjusted where required to ensure accessibility features are enabled and operate as intended.
Feedback from users and buyers is encouraged and reviewed through service management processes. Any accessibility issues identified are logged, prioritised and addressed as part of continuous service improvement, ensuring the interface remains usable and accessible throughout the service lifecycle. - API
- Yes
- What users can and can't do using the API
-
AG provides a secure, authenticated API that allows authorised users to interact with selected functions of the network infrastructure software service. The API is designed to support integration, automation and operational efficiency while maintaining appropriate governance and security controls.
Users can use the API to set up the service by registering network assets, retrieving configuration templates, onboarding environments, and integrating the service with existing monitoring, reporting or security tools. Initial setup activities are typically performed by authorised administrators using API credentials issued during onboarding.
Through the API, users can make changes such as retrieving network status and performance data, updating configuration parameters within approved boundaries, triggering monitoring actions, and exporting operational and audit data. All API interactions are authenticated, logged and subject to role-based access controls to ensure accountability and traceability.
There are limitations on what can be performed through the API to protect service integrity and security. Critical administrative actions, changes with significant security or service impact, and global configuration changes are restricted or require approval through the service management interface and formal change management processes. The API does not allow users to bypass governance controls, disable security features or modify underlying platform infrastructure. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
AG's service can be customised through configurable service delivery and support arrangements agreed with buyers. Customisation focuses on how the service is delivered rather than changes to underlying software platforms.
What can be customised includes the scope of supported cloud platforms and applications, service hours, response and escalation priorities, reporting formats, governance arrangements, and the level of proactive support provided. Buyers may also choose whether to include a dedicated Technical Account Manager, named cloud support engineers, regular service reviews, or enhanced monitoring and assurance activities.
How users can customise the service is through service definition and onboarding activities. Requirements are discussed during mobilisation and documented within the call-off contract, service description and service level agreements. Adjustments can also be made during service delivery through agreed change management processes, ensuring changes are controlled and aligned with buyer needs.
Who can customise the service includes authorised buyer representatives such as contract managers, service owners or nominated technical leads. These individuals work with AG’s service management team to agree and approve changes. End users interact with the service through standard interfaces but do not directly alter service configuration.
Scaling
- Independence of resources
- AG CAPPS manages service demand through structured resource planning and service management processes. Support capacity is planned based on contracted service levels, expected demand and buyer priorities. Work is scheduled and prioritised to ensure one buyer’s demand does not adversely affect another’s service. Escalation and prioritisation processes are used to manage peak demand or critical incidents. Where required, additional resources can be allocated in line with agreed change control. This approach ensures predictable, reliable support and protects service quality across all customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
- AG provides service usage and performance metrics as part of service management and governance. Metrics typically include volume of support requests, incident and change trends, response and resolution times, service availability indicators, and backlog status. Where applicable, metrics also cover security-related events and service improvement actions. Metrics are presented through regular service reports and reviewed during service review meetings with authorised buyer representatives. Reporting formats and frequency are agreed during onboarding and can be tailored to buyer requirements, supporting transparency, operational oversight and continuous improvement throughout the service lifecycle.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users export their data using standard export functionality provided by the underlying support and service management platforms. This typically includes exporting service records, tickets, reports and documentation in commonly used formats such as CSV or PDF. AG CAPPS provides guidance and assistance to authorised buyer representatives to support data export activities. Data remains within buyer-owned or third-party platforms throughout the contract. Access is maintained for an agreed period to allow users to complete data exports before service closure, ensuring continuity and control over service information.
- Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
AG guarantees availability through defined service level agreements (SLAs) covering application availability and service access. The service is designed for high availability and is hosted on resilient cloud infrastructure operated by accredited third-party providers.
The standard SLA guarantees 99.5% monthly application availability, excluding scheduled maintenance. Availability is measured at the application level and reflects the ability for authorised users to access core service functionality. Planned maintenance is communicated in advance and scheduled outside core business hours wherever possible.
Service availability is monitored continuously using platform and service monitoring tools. Performance against availability targets is reviewed regularly and reported to buyers as part of service governance. Any unplanned service disruption is managed through defined incident management processes, with timely communication and escalation.
If guaranteed availability levels are not met, buyers are eligible for service credits or fee adjustments, as defined in the call-off contract. Remedies are proportionate to the level of service impact and applied as credits against future service charges rather than cash refunds. Root cause analysis and corrective actions are undertaken following any breach to prevent recurrence and improve service resilience. - Approach to resilience
-
AG designs its service to be resilient through people, process and supplier-aligned controls rather than reliance on owned infrastructure. As a cloud support service, AG does not host or operate datacentres. Resilience is therefore achieved by operating effectively across buyer-owned or third-party cloud environments.
Service resilience is supported through defined service management processes aligned to ITIL, including incident, problem and change management, escalation procedures and continuity planning. Support capacity is planned to manage peak demand, and service delivery is not dependent on single individuals. Where required, named or dedicated resources can be agreed to provide continuity and reduce operational risk.
AG’s service interfaces and support tools are accessed via secure, browser-based platforms designed for high availability and supported by third-party providers with resilient datacentre architectures. These providers typically operate multiple availability zones, redundancy, backup and disaster recovery arrangements in line with recognised industry standards. Detailed information on underlying datacentre resilience is available from the relevant platform providers and can be shared with buyers on request.
Operational resilience is further supported through regular service reviews, monitoring of service performance, and continuous improvement activities. Lessons learned from incidents or service disruptions are reviewed and incorporated into service processes - Outage reporting
-
AG reports service outages and service-impacting issues through defined service communication and incident management processes.
Outages affecting the service are communicated to authorised buyer contacts via direct email alerts, providing clear information on the issue, service impact, current status and expected next steps. Updates are issued at appropriate intervals until service restoration is confirmed.
Where applicable, outage status and incident updates are available through a secure service interface for logged-in users. In addition, an API is provided to enable programmatic access to service status and incident information, supporting integration with buyer monitoring, alerting or service management tools.
Following resolution of a significant outage, AG can provide an incident summary or post-incident report on request, outlining root cause, resolution actions and preventative measures implemented.
This approach ensures timely, transparent and controlled communication of outages, aligned with ITIL incident management practices and public sector service expectations.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- AG restricts access to management interfaces and support channels through role-based access controls and authenticated user accounts. Access is granted on the principle of least privilege and limited to authorised users approved by the buyer. User roles define permitted actions such as raising requests, viewing service information or accessing reports. Access rights are reviewed regularly and updated in response to role changes or leavers. Administrative access is restricted to authorised AG personnel and protected by additional controls. All access to management interfaces and support channels is logged and monitored to support auditability, accountability and incident investigation.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
AG operates a formal Information Security Management System (ISMS) accredited to ISO/IEC 27001 and holds Cyber Essentials Plus and SOC 2 Type II certifications. AG CAPPS complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 and is registered with the Information Commissioner’s Office (ICO).
Information security policies cover access control, data protection, incident management, asset management, supplier assurance, secure remote working and acceptable use. Policies are reviewed regularly to ensure continued compliance with legal, regulatory and contractual requirements.
Information security governance is embedded within AG CAPPS’ management structure. Senior management retains overall accountability for information security, with day-to-day responsibility delegated to nominated security and service management leads. Security risks, incidents and compliance matters are reported through established governance and management review processes.
Compliance is enforced through documented procedures, role-based access controls and technical safeguards validated through Cyber Essentials Plus testing and SOC 2 Type II independent assurance. All staff involved in service delivery receive mandatory security awareness training and are required to follow secure working practices.
Information security incidents are managed through defined incident management processes, including escalation, investigation, remediation and post-incident review. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
AG operates defined configuration and change management processes aligned to ITIL service management practices. Service components, including support tools, service interfaces and operational documentation, are recorded and tracked throughout their lifecycle using configuration records and service documentation.
Changes are requested, assessed and approved through controlled change management processes. Each change is reviewed for potential service, security and compliance impact, including risks to data protection and availability. Security considerations are assessed in line with ISO 27001 control objectives and SOC 2 requirements. Approved changes are implemented in a controlled manner and reviewed post-implementation to confirm outcomes and identify improvements. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- AG operates a defined vulnerability management process aligned to ISO 27001, SOC 2 Type II and Cyber Essentials Plus. Potential threats to the service are assessed through regular vulnerability scanning, review of security advisories and risk assessment activities. Information about emerging threats is obtained from trusted sources including vendor security bulletins, NCSC guidance and independent security providers. Identified vulnerabilities are prioritised based on risk and potential impact. Patches and mitigations are deployed in a timely manner in line with change management processes, with critical security updates applied as soon as practicable. Remediation actions are verified and tracked to completion.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- AG operates defined protective monitoring processes aligned to ISO 27001, SOC 2 Type II and Cyber Essentials Plus requirements. Potential compromises are identified through monitoring of service activity, security alerts, audit logs and incident reports provided by underlying platforms and support tools. Alerts and anomalies are assessed by authorised personnel to determine potential impact and severity. Where a potential compromise is identified, incident management procedures are initiated, including investigation, containment and escalation. Security incidents are responded to promptly in line with agreed priorities, with critical incidents addressed immediately and managed through formal incident response and communication processes.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- AG operates defined incident management processes aligned to recognised standards and ITIL practices. Pre-defined procedures exist for common service and security events, including incident classification, prioritisation, escalation and resolution. Users report incidents through the service interface, email or agreed support channels. Incidents are logged, tracked and managed in line with agreed service levels. Status updates are provided during incident resolution, and incident reports are shared with authorised buyer contacts. Where appropriate, post-incident reviews and root cause analyses are provided to support transparency, accountability and continuous service improvement.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- AG can offer a limited, no-cost trial focused on service onboarding and initial support engagement. The trial includes access to agreed support channels and guidance. It excludes formal SLAs, dedicated resources and out-of-hours support. Trial duration and scope are agreed in advance, typically for a short, defined period.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2.5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- INTERCERT
- ISO/IEC 27001 accreditation date
- Wednesday 19 March 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Sunday 18 February 2024
- What the ISO 9001 doesn’t cover
- Please note for the Cyber Essentials and Cyber Essentials + we have valid certificates but the portal will not allow me to input the certificate number (despite following instructions given in clarifications)
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
- SOC 2 TYPE II
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-