Drupal-Optimised Managed Cloud Hosting Infrastructure
Fully managed cloud hosting infrastructure optimised for Drupal and web applications across public, private, and hybrid environments. Includes high-availability compute, storage, networking, and integrated management tools. Pre-configured for Drupal performance with automated scaling, security hardening, and built-in monitoring. Flexible infrastructure tailored to organisational requirements.
Features
- High-Availability Architecture
- Drupal-Optimised Configuration
- Elastic Auto-Scaling Infrastructure
- Multi-Tier Security Controls
- Automated Backup Infrastructure
- Content Delivery Network Integration
- Database Clustering and Replication
- Container and Orchestration Support
- Multi-Cloud and Hybrid Compatibility
- Infrastructure Management Portal
Benefits
- Maximum Application Uptime through high-availability infrastructure
- Superior Drupal Performance through purpose-built infrastructure
- Cost-Effective Scalability through automatic scaling
- Enterprise-Grade Security through multi-layered security and WAF
- Business Continuity Protection through automated backups and disaster recovery
- Operational Visibility through real-time infrastructure monitoring and analytics
- Global Performance Delivery through CDN integration
- Reduced Infrastructure Complexity through pre-integrated, managed infrastructure
- Vendor Flexibility through multi-cloud capability
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 2 4 4 2 2 9 0 8 6 7 0 8 8 4
Contact
1XINTERNET LIMITED
James Tillotson
Telephone: +44 7745 545031
Email: j.tillotson@1xinternet.com
About your service
- Service categories
-
Systems Infrastructure Software
System and service management
- IT operations management
- IT service management
IT automation and configuration management
- Workload management
- Datacentre system and application control
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Service delivery is subject to the constraints of the underlying infrastructure. Planned maintenance may be required to apply security updates and infrastructure patches, which is scheduled in advance where possible. Infrastructure is provided with supported versions of operating systems, database platforms, and core software only. Services do not extend to unsupported or end-of-life software, or to bespoke third-party systems outside the agreed scope of work.
- System requirements
- No specific buyer requirements
User support
- Email or online ticketing support
- Yes
- Support response times
- Response times are established within our Service Level Agreements (SLAs) and customised for each client’s needs. We conduct regular reviews to verify that all SLA services are being met.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
-
1xINTERNET provides tiered support covering both Drupal application and hosting infrastructure. Support levels are customised to organisational requirements and defined within individual SLAs.
Standard tiers include: Basic (Monday-Friday, 9am-5pm), Extended (7 days/week, 9am-5pm), Premium (extended hours 8am-8pm), and Enterprise (24/7 coverage). Each tier encompasses incident response, troubleshooting, maintenance coordination, and technical guidance.
Pricing is tailored based on selected coverage hours, response time commitments, and service scope—detailed in customer-specific agreements.
For Enterprise-level engagements, we assign dedicated technical account managers who provide strategic guidance, proactive monitoring, and serve as primary points of contact for both operational and architectural matters. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We provide comprehensive onboarding support to ensure smooth service adoption. New customers receive a dedicated onboarding training..
Documentation and self-service resources include:
Detailed user guides and technical documentation covering all platform features
Step-by-step tutorials for common tasks and configurations
API documentation with code examples and integration guides
Knowledge base with troubleshooting articles and best practices
Training options:
Online training sessions tailored to user roles (administrators, developers, content editors)
Access to technical support team for questions during onboarding
Onsite training can be arranged subject to additional costs and is tailored to specific organisational requirements. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Customers receive complete access to extract all infrastructure components and data. This includes full database exports (SQL dumps), all stored files and media assets, application code repositories, configuration files, and backup archives in standard, portable formats. Data is delivered via secure transfer methods (SFTP, encrypted cloud storage, or direct download) ensuring integrity and accessibility.
For infrastructure-as-code deployments, we provide all configuration files, deployment scripts, infrastructure definitions (Terraform, Ansible, CloudFormation, etc.), and network topology documentation, enabling customers to recreate identical environments with alternative providers or on-premises infrastructure.
Extraction occurs without service disruption during agreed transition periods. All data remains in industry-standard formats ensuring compatibility with any infrastructure provider. Complete infrastructure documentation accompanies deliverables, including architecture diagrams, security configurations, and deployment specifications, facilitating seamless migration and eliminating technical lock-in. - End-of-contract process
-
At contract conclusion, we provide complimentary handover services including complete infrastructure backups, configuration exports, and comprehensive documentation of your hosting environment. For public cloud deployments, we can facilitate transfer of underlying cloud resources to your direct control or alternative management where technically feasible, at no additional cost.
A structured offboarding process ensures smooth transition with advance notice, flexible transition periods, technical handover sessions, and secure data deletion certification following agreed timescales. These deliverables ensure you retain full ownership and control of your infrastructure and digital assets.
Should you require additional transition support—such as migration assistance to alternative infrastructure, re-architecture consulting, or extended technical support during transition—these services are available at standard professional rates. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There is feature parity between the mobile and desktop service.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Web-based management portal accessible via standard browsers without client-side software installation. The interface provides a dashboard with real-time infrastructure metrics, resource utilisation, and service health monitoring. Users can provision and configure compute instances, storage, databases, and networking components, view performance analytics and logs, manage access controls and permissions, configure security policies, and track billing and usage. The portal includes API access for programmatic infrastructure management and automation integration. The interface is responsive, intuitive, and accessible 24/7 from any internet-connected device, enabling comprehensive infrastructure management and monitoring.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
-
- Programmatically create, configure, modify, and delete infrastructure resources (compute instances, storage volumes, databases, networks)
- Retrieve resource metadata, status information, and performance metrics
- Automate deployment pipelines and infrastructure provisioning workflows
- Query and export logs and monitoring data
- Manage IAM policies, roles, and service accounts
- Configure auto-scaling policies and load balancers
- Perform backup and snapshot operations
- Integrate infrastructure management into CI/CD pipelines and automation tools
Limitations:
- Access resources or projects outside their authorised scope
- Override security policies or bypass authentication mechanisms
- Execute privileged operations beyond assigned IAM roles
- Access underlying physical infrastructure or hypervisor layers
- Exceed defined API rate limits and quota restrictions - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
What can be customised:
- Resource allocation (CPU, memory, storage capacity)
- Network configurations (VPCs, subnets, firewall rules within secure parameters)
- Backup schedules and retention policies
- Monitoring thresholds and alerting rules
- Scaling policies and triggers
- Domain configurations and SSL certificates
- User access permissions and role assignments
How users can customise:
- Through the web-based management portal with guided configuration workflows
- Via API for programmatic customisation and infrastructure-as-code deployments
- By submitting change requests to support team for infrastructure-level modifications requiring validation
Who can customise:
- Authorised users with appropriate IAM roles and permissions within the buyer's organisation
- Users can customise application and resource-level settings independently
- Infrastructure-level changes affecting security, networking architecture, or platform stability require approval and implementation by our technical team to ensure service integrity and compliance
Scaling
- Independence of resources
- Infrastructure employs multi-tenant architecture with robust resource isolation ensuring customers operate in logically separated environments. Each deployment utilises dedicated resource allocations with guaranteed CPU, memory, and storage capacity that cannot be oversubscribed by other tenants. Hypervisor-level isolation prevents resource contention, whilst network segmentation ensures traffic separation. Resource quotas and quality-of-service controls prevent any single tenant from impacting others. For customers requiring absolute isolation, dedicated infrastructure options are available. Performance monitoring continuously validates resource availability and isolation effectiveness, with automatic alerts if thresholds are approached, ensuring consistent performance regardless of platform-wide demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Our Cloud Platform provides comprehensive monitoring capabilities across all infrastructure components. Cloud Monitoring delivers real-time insights into compute resource utilisation including CPU, memory, disk, and network performance. Load balancers expose request volumes, latency distributions, and error rates for traffic analysis. Managed services like Cloud SQL and Memorystore provide database-specific metrics covering query performance, connection pools, cache efficiency, and resource consumption. Autoscaling metrics track instance counts and scaling events. All metrics support custom dashboards, configurable alerting thresholds, and integration with Cloud Logging.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export data through multiple methods including self-service downloads via the management portal for databases, files, and backup archives, API-based programmatic export for automated workflows and bulk operations, and direct command-line access via SSH/SFTP for technical users requiring granular control. Support teams can prepare and deliver complete data packages upon request via secure encrypted channels. All export methods maintain data integrity and provide data in standard, portable formats compatible with alternative platforms. Users can perform incremental or full exports and retain continuous export access throughout the contract term without restrictions or additional charges.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- SQL files
- JSON
- YAML
- XML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- SQL files
- JSON
- XML
- YAML
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Availability SLA is 99.95%. Failure to meet agreed level of availability will result in service credits awarded to to the customer.
- Approach to resilience
-
Our infrastructure is architected for high availability across multiple layers. The Platform's global network provides geographic redundancy, with resources distributed across multiple zones within a region to protect against single-point failures. Load balancers automatically detect and route traffic away from unhealthy instances, ensuring continuous service availability.
Compute Engine autoscaling groups maintain minimum instance counts and automatically replace failed VMs, providing self-healing capabilities. Application servers are stateless, enabling seamless failover without data loss.
Database resilience leverages Cloud SQL's high-availability configuration with automatic failover to standby replicas. Multi-zone deployment ensures database continuity even during zone outages, with synchronous replication maintaining data consistency. Read replicas distribute query load and provide additional redundancy. Automated backups with point-in-time recovery enable rapid restoration if needed.
Memorystore Redis utilizes standard tier deployment with automatic failover and data persistence, preventing cache loss during failures. Network-level redundancy through premium tier routing ensures reliable connectivity.
Regular disaster recovery testing validates our ability to maintain service continuity under various failure scenarios, ensuring minimal disruption to users. - Outage reporting
-
Cloud Platform monitoring triggers alerts on infrastructure anomalies including resource exhaustion, connectivity issues and performance degradation.
Our ELK stack aggregates application logs and triggers alerts on error thresholds or unusual patterns.
Our monitoring stack provides external monitoring from multiple global regions, performing HTTPS health checks, SSH connectivity tests and Playwright-based application workflow validation.
Incidents trigger immediate notifications via email, Slack, and phone calls to on-call personnel. Stakeholders can subscribe to relevant notification channels based on their requirements, providing transparent communication during incidents and displaying resolution progress.
We provide both public and/or protected status dashboards displaying real-time service availability. Public dashboards allow users to independently verify service status and view incident history. Protected dashboards offer detailed metrics for internal teams and authorized clients.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Access restrictions in management interfaces and support channels
- Access to management interfaces is controlled through Identity and Access Management (IAM) with role-based access control (RBAC). We implement least privilege principles, granting users only the permissions necessary for their specific roles.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We establish clear accountability and continuous oversight of our services and infrastructure. A designated security lead coordinates security policy implementation and compliance monitoring. We maintain documented security policies covering access control, data protection, incident response, and change management aligned with NCSC Cloud Security Principles.
- Information security policies and processes
-
We maintain information security policies covering access management, data classification, encryption standards, vulnerability management, change control, and incident response.
Our DevOps team lead reports to senior management on security matters, ensuring executive visibility and accountability.
Policy compliance is enforced through technical controls including IAM policies, mandatory MFA, encrypted communications (TLS 1.2+), and automated security scanning in CI/CD pipelines. Audit Logs provide continuous monitoring of administrative actions and policy violations.
Regular internal reviews assess compliance, findings are documented and resolved. Security incidents trigger defined response procedures with post-incident reviews to improve processes. Team members receive security training and acknowledge policy requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Our infrastructure is managed through Infrastructure-as-Code (IaC), ensuring all configurations are version-controlled, auditable, and reproducible. Changes undergo peer review via merge requests before deployment.
All infrastructure components are tracked in Git repositories, providing complete change history and accountability.
Security impact assessments are integrated into our change approval process. Modifications to network configurations, IAM policies, or security controls require explicit security review. Validation of changes in non-production environments before production deployment. Change activities are logged via Cloud Audit Logs, enabling retrospective analysis and compliance verification. This systematic approach ensures security considerations are evaluated throughout the infrastructure lifecycle. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We employ continuous vulnerability assessment across all infrastructure layers. Cloud Security Command Center scans Compute Engine instances, containers, and configurations for known vulnerabilities. Application dependencies are monitored through automated scanning in our CI/CD pipelines.
Security patches are deployed based on severity: critical vulnerabilities within 12-24 hours, high-priority issues within 5 working days, following validation in pre-production environments. OS patches are applied via automated update mechanisms from respective OS repositories.
Threat intelligence is gathered from multiple sources including Cloud security bulletins, CVE databases, and vendor-specific advisories. Our WAF is automatically updated to defend against newly identified exploits. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Our monitoring detects potential compromises through continuous analysis of logs and metrics. Cloud Audit Logs track all administrative actions and API calls. ELK stack analyses application logs for suspicious patterns including failed authentication attempts, unusual access patterns, and privilege escalations.
Security incidents trigger immediate alerts to on-call personnel via email, Slack, and phone. Our incident response process includes immediate containment, impact assessment, root cause analysis, and remediation. All incidents are documented with post-incident reviews to improve detection and response capabilities. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We maintain documented incident response procedures with pre-defined playbooks for common scenarios including service outages, security breaches, and infrastructure failures.
Users report incidents via email, dedicated Slack channels, or direct contact with on-call personnel. Status pages display current service status and ongoing incidents.
Incident severity determines response timeline and communication frequency. Post-incident reports documenting root cause, impact, and preventive measures are shared with affected stakeholders within 48 hours of resolution, ensuring transparency and continuous improvement. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 2.5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Bb6ec7d3-1c77-45f3-b4dc-708027898d8c
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Working conditions which promote an inclusive working environment and promote retention and progression
-