Platform/Infrastructure Hosting as Service
Selcom provide a managed hosting platform for a range of web applications and servers based on LAMP and Windows technology. If your organisation utilises solutions such as ASP, .NET and SQL, or Linux based solutions including PHP, Python, Ruby and Perl, we have the hosting environment to support your applications.
Features
- 2-Factor Authentication
- Dedicated Server and Private Cloud segregated further by VLAN
- Site-to-site replication between our data centres for robust DR
- Unified Threat Management utilising WatchGuard firebox solutions
- Comprehensive infrastructure and network metrics
- Microsoft .NET Framework and SQL technologies application hosting environment
- Hosted Linux based solutions like PHP, Python, Ruby and Perl
- Microsoft Remote Desktop Services (RDP) and User Licensing
- Windows Server and SQL Hosting
Benefits
- 30+yrs experience implementing solutions for private and public sector
- Email and telephone support at no extra cost
- 99.9% availability, backed by service credits
- Unlimited off-site backups for secure audit accountability
- Automatic 24x7x365 system monitoring calling operations to action when necessary
- Hosting systems entirely within the UK
- Multiple environments: development, staging/UAT/pre-live, live
- Each customer has their own infrastructure, no shared services
- Automatic or ad hoc KPI and SLA performance reports
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 7 0 5 5 3 3 9 3 8 6 9 8 6 3
Contact
SELCOM SYSTEMS LIMITED
Stephanie Sellers
Telephone: 01904788181
Email: accounts@selcom.co.uk
About your service
- Service categories
-
IaaS
IaaS Compute
Virtualised x86
- General purpose
- Compute optimised
- Memory optimised
Service scope
- Service constraints
-
Any routine downtime required for system maintenance is scheduled outside of normal office hours.
A maximum of 1 hour per month maintenance window is provisionally allocated for system maintenance, if required. However, this can be adapted based on buyer requirement. - System requirements
- No specific requirements
- Cloud deployment model
- Private cloud
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 4 hours weekdays only. Out of hours support is agreed with customer on an ad hoc basis.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- Our support levels can be found in our SLA, detailed in our Service Definition Document
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- On-boarding for our hosting services are fully supported by a named, dedicated Service Manager who provides a point of contact for the customer throughout the entire service delivery. They will assist with anything that you might need, and will walk through any training required, where necessary.
- Service documentation
- No
- End-of-contract data extraction
-
Selcom will securely export data and metadata using industry standards that can be re-used, such as Tab-Delimitated and XML formats.
Selcom will cooperate with any new cloud provider and there are no additional costs when switching. We will only retain data after contract termination for the timescale specified by the customer. Selcom will undertake full deletion of the data on our cloud service infrastructure after the time specified by the client. - End-of-contract process
-
Selcom will provide an exit plan which ensures continuity of service. This will set out Selcom’s methodology to ensure continuity of service and an orderly transition to the replacement supplier. Selcom will work with the buyer to ensure that the exit plan is aligned with the buyers own exit plan and strategy.
When requested, Selcom will help the buyer migrate the services to a replacement supplier in line with the exit plan. This will be at Selcom’s own expense if the call-off contract ended before the expiry date due to supplier cause.
Using the service
- Web browser interface
- No
- API
- No
- Command line interface
- Yes
- Command line interface compatibility
-
- Linux or Unix
- Windows
- MacOS
- Using the command line interface
- There are no limitations regarding what users can set up or make changes through the command line
Scaling
- Independence of resources
- We can traffic shape based on user experience and usage patterns. We can also segment system resources to protect service levels
- Usage notifications
- No
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Backup and recovery
- What’s backed up
-
- Files
- Virtual Machines
- Databases
- Operating Systems
- Active Directory
- SQL Database
- Backup controls
- We offer fully customisable back up options which will be agreed before the Contract is taken out
- Datacentre setup
-
- Multiple datacentres with disaster recovery
- Single datacentre with multiple copies
- Scheduling backups
- Users contact the support team to schedule backups
- Backup recovery
- Users contact the support team
- Backup and recovery
- Yes
- RPO/RTO
- Yes
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- 99.9% application uptime as measured through 1-minute polls using ICMP echo-requests. 99.9% network connectivity uptime of the customer service as measured through 1-minute polls using ICMP echo-requests Users are refunded by negotiated settlement outlined in the SLA
- Approach to resilience
- Selcom do not want to make this information public. However, we are willing to share information with a specialist security expert on how we have designed our service to be resilient
- Outage reporting
- Our system issues email, text and telephone call alerts to named contacts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- IP and/or network level authentication
- Access restrictions in management interfaces and support channels
- All access to service interfaces and support channels are constrained to authenticated and authorised individuals with appropriate access privileges.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
- Devices users manage the service through
-
- Dedicated device over multiple services or networks
- Directly from any device which may also be used for normal business (for example web browsing or viewing external email)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Selcom have an Information Security Management System which incorporates all of the requirements of the ISO 27001 Standard including policies such as Access Contol, Asset Management, Communications Security, Cryptography, Information Classification and Handling, Incident Management, Physical and Equipment Security, Back Ups Procedure, amongst others.
These are audited every quarter through external and internal audits and management reviews, and during the audit evidence is seen and recorded to ensure compliance with the policies.
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Physical storage, internet bandwidth and operational systems are monitored with 24/7 automatic monitoring alerting when predefined thresholds are exceeded.
Changes are identified on the Change Request form and logged in the change Change Control log. The originator obtains sufficient information to complete the Change Request. The Internet Services Director then reviews and/or carries out a risk assessment identifying potential risks, security impacts and then identifies and costs the required controls in line with the Selcom's risk management framework. The Internet Services Director in consultation with the Managing Director is then responsible for authorising the change to go ahead. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Firewalls are configured 24/7 to alert in the event of significant intrusions or incidents occurring.
We use advanced monitoring and live detection defence systems to detect vulnerabilities Anti-Virus is configured to be patched automatically. Our automatic patch policy covers binary, executable source code modification, service pack and firmware patches. Technical services will then identify the priority for the update to be tested and deployed dependant on the nature of the treat and any known exploits.
Any patch deployment and software updates must comply with our defined change management process. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Systems are monitored 24/7 by RMM software and in-house systems, calling the operations team to action when necessary. The RMM notifies of: Warning Alerts, Critical Alerts, System Down and System Recovery Regular scanning using Vulnerability Manager tool finds vulnerabilities such as those on the OWASP Top 10, including SSL injection, cross-site scripting, and others. Any issues found will be imported into the Web Application Filter, which will automatically generate and apply mitigation rules. Servers are professionally managed and conform to guidelines under the Government's e-Government programme.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We have an Incident Management policy for our ISO 27001 certification, this works hand in hand with a Disaster Recovery plan, BCP plan and incident management plan which details the processes to take for common incidents.
Users report incidents either by email or telephone, and Selcom's staff reports these in our job system, this generates an incident report which staff fill out and use to report to clients as necessary. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Supplier
- Virtualisation technologies used
- Other
- Other virtualisation technology used
- VMWare and Proxmox
- How shared infrastructure is kept separate
- Separate VLANS and Firewalls are deployed therefore segmenting system resources ensuring different organisations sharing the same infrastructure are kept apart.
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
-
Our data centres implement energy-efficient cooling strategies in line with EU CoC best practice guidelines, including:
Optimised airflow management, using hot aisle and cold aisle containment to prevent air mixing and improve cooling efficiency.
Temperature and humidity set-points are maintained within ASHRAE-recommended ranges, reducing unnecessary cooling while maintaining equipment reliability.
High-efficiency cooling systems, including variable speed fans and intelligent cooling controls, are used to dynamically adjust cooling output based on real-time demand.
Continuous monitoring of environmental conditions, enabling proactive identification of inefficiencies and ensuring cooling performance is optimised at all times.
Energy-efficient server and storage platforms are procured, prioritising high performance per watt and vendor sustainability commitments.
Equipment is right-sized to workload requirements, avoiding over-provisioning and unnecessary energy use.
Server virtualisation and consolidation are used extensively to maximise utilisation of physical hardware and reduce the number of servers required.
Energy consumption and cooling efficiency metrics are regularly monitored and reviewed.
Improvement actions are identified and implemented in line with EU CoC best practice guidance.
Data centre staff are trained on energy-efficient operation and environmental responsibility.
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Available only on a secured shared hosted service for a limited time to test speed and performance
Discount
- Provide your minimum discount applicable to your baseline prices
- 5%
Formula for calculating price of your services
- Formula for calculating price of your services
-
Which of the core deployment models you intend to offer
Private CloudPrivate Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
- =
- Baseline Pricing
- Pricing Document avaliable on the GCloud Service
- -
- Minimum Discounting
- 5%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- Additional costs could include MFA or additional memory, however the most common costs are highlighted in our Pricing Document.
- -
- Additional sources of cost reduction
- There can be discounts for multiple servers, clients supplying own licences etc.
Mandatory certifications
- Mandatory certifications
-
Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure
Sole Control of the InfrastructureISO 9001 certification
ProvidedISO 14001 certification
ProvidedISO 27001 certification
ProvidedISO 20000-1 certification
ProvidedISO 27017 certification
ProvidedAre you bidding to provide services under Lot 1b or both Lot 1a and Lot 1b?
No
Cyber Essentials
- Do you have a Cyber Essentials Plus certificate?
- Yes
- Cyber Essentials Plus certificate Number
- F6666eae-19c0-4f32-9cd2-3c29f78653bb
Non-mandatory Standards and certifications
- ISO 28000:2022 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-