Skip to main content

Help us improve the Digital Marketplace - send your feedback

1XINTERNET LIMITED

Drupal-Optimised Managed Cloud Hosting Infrastructure

Fully managed cloud hosting infrastructure optimised for Drupal and web applications across public, private, and hybrid environments. Includes high-availability compute, storage, networking, and integrated management tools. Pre-configured for Drupal performance with automated scaling, security hardening, and built-in monitoring. Flexible infrastructure tailored to organisational requirements.

Features

  • High-Availability Architecture
  • Drupal-Optimised Configuration
  • Elastic Auto-Scaling Infrastructure
  • Multi-Tier Security Controls
  • Automated Backup Infrastructure
  • Content Delivery Network Integration
  • Database Clustering and Replication
  • Container and Orchestration Support
  • Multi-Cloud and Hybrid Compatibility
  • Infrastructure Management Portal

Benefits

  • Maximum Application Uptime through high-availability infrastructure
  • Superior Drupal Performance through purpose-built infrastructure
  • Cost-Effective Scalability through automatic scaling
  • Enterprise-Grade Security through multi-layered security and WAF
  • Business Continuity Protection through automated backups and disaster recovery
  • Operational Visibility through real-time infrastructure monitoring and analytics
  • Global Performance Delivery through CDN integration
  • Reduced Infrastructure Complexity through pre-integrated, managed infrastructure
  • Vendor Flexibility through multi-cloud capability

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at j.tillotson@1xinternet.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 2 4 4 2 2 9 0 8 6 7 0 8 8 4

Contact

1XINTERNET LIMITED James Tillotson
Telephone: +44 7745 545031
Email: j.tillotson@1xinternet.com

About your service

Service categories

Systems Infrastructure Software

System and service management

  • IT operations management
  • IT service management

IT automation and configuration management

  • Workload management
  • Datacentre system and application control
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Service delivery is subject to the constraints of the underlying infrastructure. Planned maintenance may be required to apply security updates and infrastructure patches, which is scheduled in advance where possible. Infrastructure is provided with supported versions of operating systems, database platforms, and core software only. Services do not extend to unsupported or end-of-life software, or to bespoke third-party systems outside the agreed scope of work.
System requirements
No specific buyer requirements

User support

Email or online ticketing support
Yes
Support response times
Response times are established within our Service Level Agreements (SLAs) and customised for each client’s needs. We conduct regular reviews to verify that all SLA services are being met.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
None
Onsite support
Yes, at extra cost
Support levels
1xINTERNET provides tiered support covering both Drupal application and hosting infrastructure. Support levels are customised to organisational requirements and defined within individual SLAs.
Standard tiers include: Basic (Monday-Friday, 9am-5pm), Extended (7 days/week, 9am-5pm), Premium (extended hours 8am-8pm), and Enterprise (24/7 coverage). Each tier encompasses incident response, troubleshooting, maintenance coordination, and technical guidance.
Pricing is tailored based on selected coverage hours, response time commitments, and service scope—detailed in customer-specific agreements.
For Enterprise-level engagements, we assign dedicated technical account managers who provide strategic guidance, proactive monitoring, and serve as primary points of contact for both operational and architectural matters.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We provide comprehensive onboarding support to ensure smooth service adoption. New customers receive a dedicated onboarding training..

Documentation and self-service resources include:
Detailed user guides and technical documentation covering all platform features
Step-by-step tutorials for common tasks and configurations
API documentation with code examples and integration guides
Knowledge base with troubleshooting articles and best practices

Training options:
Online training sessions tailored to user roles (administrators, developers, content editors)
Access to technical support team for questions during onboarding

Onsite training can be arranged subject to additional costs and is tailored to specific organisational requirements.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Customers receive complete access to extract all infrastructure components and data. This includes full database exports (SQL dumps), all stored files and media assets, application code repositories, configuration files, and backup archives in standard, portable formats. Data is delivered via secure transfer methods (SFTP, encrypted cloud storage, or direct download) ensuring integrity and accessibility.
For infrastructure-as-code deployments, we provide all configuration files, deployment scripts, infrastructure definitions (Terraform, Ansible, CloudFormation, etc.), and network topology documentation, enabling customers to recreate identical environments with alternative providers or on-premises infrastructure.
Extraction occurs without service disruption during agreed transition periods. All data remains in industry-standard formats ensuring compatibility with any infrastructure provider. Complete infrastructure documentation accompanies deliverables, including architecture diagrams, security configurations, and deployment specifications, facilitating seamless migration and eliminating technical lock-in.
End-of-contract process
At contract conclusion, we provide complimentary handover services including complete infrastructure backups, configuration exports, and comprehensive documentation of your hosting environment. For public cloud deployments, we can facilitate transfer of underlying cloud resources to your direct control or alternative management where technically feasible, at no additional cost.
A structured offboarding process ensures smooth transition with advance notice, flexible transition periods, technical handover sessions, and secure data deletion certification following agreed timescales. These deliverables ensure you retain full ownership and control of your infrastructure and digital assets.
Should you require additional transition support—such as migration assistance to alternative infrastructure, re-architecture consulting, or extended technical support during transition—these services are available at standard professional rates.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There is feature parity between the mobile and desktop service.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Web-based management portal accessible via standard browsers without client-side software installation. The interface provides a dashboard with real-time infrastructure metrics, resource utilisation, and service health monitoring. Users can provision and configure compute instances, storage, databases, and networking components, view performance analytics and logs, manage access controls and permissions, configure security policies, and track billing and usage. The portal includes API access for programmatic infrastructure management and automation integration. The interface is responsive, intuitive, and accessible 24/7 from any internet-connected device, enabling comprehensive infrastructure management and monitoring.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
None
API
Yes
What users can and can't do using the API
- Programmatically create, configure, modify, and delete infrastructure resources (compute instances, storage volumes, databases, networks)
- Retrieve resource metadata, status information, and performance metrics
- Automate deployment pipelines and infrastructure provisioning workflows
- Query and export logs and monitoring data
- Manage IAM policies, roles, and service accounts
- Configure auto-scaling policies and load balancers
- Perform backup and snapshot operations
- Integrate infrastructure management into CI/CD pipelines and automation tools

Limitations:
- Access resources or projects outside their authorised scope
- Override security policies or bypass authentication mechanisms
- Execute privileged operations beyond assigned IAM roles
- Access underlying physical infrastructure or hypervisor layers
- Exceed defined API rate limits and quota restrictions
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
What can be customised:
- Resource allocation (CPU, memory, storage capacity)
- Network configurations (VPCs, subnets, firewall rules within secure parameters)
- Backup schedules and retention policies
- Monitoring thresholds and alerting rules
- Scaling policies and triggers
- Domain configurations and SSL certificates
- User access permissions and role assignments

How users can customise:
- Through the web-based management portal with guided configuration workflows
- Via API for programmatic customisation and infrastructure-as-code deployments
- By submitting change requests to support team for infrastructure-level modifications requiring validation

Who can customise:
- Authorised users with appropriate IAM roles and permissions within the buyer's organisation
- Users can customise application and resource-level settings independently
- Infrastructure-level changes affecting security, networking architecture, or platform stability require approval and implementation by our technical team to ensure service integrity and compliance

Scaling

Independence of resources
Infrastructure employs multi-tenant architecture with robust resource isolation ensuring customers operate in logically separated environments. Each deployment utilises dedicated resource allocations with guaranteed CPU, memory, and storage capacity that cannot be oversubscribed by other tenants. Hypervisor-level isolation prevents resource contention, whilst network segmentation ensures traffic separation. Resource quotas and quality-of-service controls prevent any single tenant from impacting others. For customers requiring absolute isolation, dedicated infrastructure options are available. Performance monitoring continuously validates resource availability and isolation effectiveness, with automatic alerts if thresholds are approached, ensuring consistent performance regardless of platform-wide demand.

Analytics

Service usage metrics
Yes
Metrics types
Our Cloud Platform provides comprehensive monitoring capabilities across all infrastructure components. Cloud Monitoring delivers real-time insights into compute resource utilisation including CPU, memory, disk, and network performance. Load balancers expose request volumes, latency distributions, and error rates for traffic analysis. Managed services like Cloud SQL and Memorystore provide database-specific metrics covering query performance, connection pools, cache efficiency, and resource consumption. Autoscaling metrics track instance counts and scaling events. All metrics support custom dashboards, configurable alerting thresholds, and integration with Cloud Logging.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export data through multiple methods including self-service downloads via the management portal for databases, files, and backup archives, API-based programmatic export for automated workflows and bulk operations, and direct command-line access via SSH/SFTP for technical users requiring granular control. Support teams can prepare and deliver complete data packages upon request via secure encrypted channels. All export methods maintain data integrity and provide data in standard, portable formats compatible with alternative platforms. Users can perform incremental or full exports and retain continuous export access throughout the contract term without restrictions or additional charges.
Data export formats
  • CSV
  • Other
Other data export formats
  • SQL files
  • JSON
  • YAML
  • XML
Data import formats
  • CSV
  • Other
Other data import formats
  • SQL files
  • JSON
  • XML
  • YAML

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Availability SLA is 99.95%. Failure to meet agreed level of availability will result in service credits awarded to to the customer.
Approach to resilience
Our infrastructure is architected for high availability across multiple layers. The Platform's global network provides geographic redundancy, with resources distributed across multiple zones within a region to protect against single-point failures. Load balancers automatically detect and route traffic away from unhealthy instances, ensuring continuous service availability.
Compute Engine autoscaling groups maintain minimum instance counts and automatically replace failed VMs, providing self-healing capabilities. Application servers are stateless, enabling seamless failover without data loss.
Database resilience leverages Cloud SQL's high-availability configuration with automatic failover to standby replicas. Multi-zone deployment ensures database continuity even during zone outages, with synchronous replication maintaining data consistency. Read replicas distribute query load and provide additional redundancy. Automated backups with point-in-time recovery enable rapid restoration if needed.
Memorystore Redis utilizes standard tier deployment with automatic failover and data persistence, preventing cache loss during failures. Network-level redundancy through premium tier routing ensures reliable connectivity.
Regular disaster recovery testing validates our ability to maintain service continuity under various failure scenarios, ensuring minimal disruption to users.
Outage reporting
Cloud Platform monitoring triggers alerts on infrastructure anomalies including resource exhaustion, connectivity issues and performance degradation.
Our ELK stack aggregates application logs and triggers alerts on error thresholds or unusual patterns.
Our monitoring stack provides external monitoring from multiple global regions, performing HTTPS health checks, SSH connectivity tests and Playwright-based application workflow validation.
Incidents trigger immediate notifications via email, Slack, and phone calls to on-call personnel. Stakeholders can subscribe to relevant notification channels based on their requirements, providing transparent communication during incidents and displaying resolution progress.
We provide both public and/or protected status dashboards displaying real-time service availability. Public dashboards allow users to independently verify service status and view incident history. Protected dashboards offer detailed metrics for internal teams and authorized clients.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
Access restrictions in management interfaces and support channels
Access to management interfaces is controlled through Identity and Access Management (IAM) with role-based access control (RBAC). We implement least privilege principles, granting users only the permissions necessary for their specific roles.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We establish clear accountability and continuous oversight of our services and infrastructure. A designated security lead coordinates security policy implementation and compliance monitoring. We maintain documented security policies covering access control, data protection, incident response, and change management aligned with NCSC Cloud Security Principles.
Information security policies and processes
We maintain information security policies covering access management, data classification, encryption standards, vulnerability management, change control, and incident response.
Our DevOps team lead reports to senior management on security matters, ensuring executive visibility and accountability.
Policy compliance is enforced through technical controls including IAM policies, mandatory MFA, encrypted communications (TLS 1.2+), and automated security scanning in CI/CD pipelines. Audit Logs provide continuous monitoring of administrative actions and policy violations.
Regular internal reviews assess compliance, findings are documented and resolved. Security incidents trigger defined response procedures with post-incident reviews to improve processes. Team members receive security training and acknowledge policy requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Our infrastructure is managed through Infrastructure-as-Code (IaC), ensuring all configurations are version-controlled, auditable, and reproducible. Changes undergo peer review via merge requests before deployment.
All infrastructure components are tracked in Git repositories, providing complete change history and accountability.
Security impact assessments are integrated into our change approval process. Modifications to network configurations, IAM policies, or security controls require explicit security review. Validation of changes in non-production environments before production deployment. Change activities are logged via Cloud Audit Logs, enabling retrospective analysis and compliance verification. This systematic approach ensures security considerations are evaluated throughout the infrastructure lifecycle.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We employ continuous vulnerability assessment across all infrastructure layers. Cloud Security Command Center scans Compute Engine instances, containers, and configurations for known vulnerabilities. Application dependencies are monitored through automated scanning in our CI/CD pipelines.
Security patches are deployed based on severity: critical vulnerabilities within 12-24 hours, high-priority issues within 5 working days, following validation in pre-production environments. OS patches are applied via automated update mechanisms from respective OS repositories.
Threat intelligence is gathered from multiple sources including Cloud security bulletins, CVE databases, and vendor-specific advisories. Our WAF is automatically updated to defend against newly identified exploits.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our monitoring detects potential compromises through continuous analysis of logs and metrics. Cloud Audit Logs track all administrative actions and API calls. ELK stack analyses application logs for suspicious patterns including failed authentication attempts, unusual access patterns, and privilege escalations.
Security incidents trigger immediate alerts to on-call personnel via email, Slack, and phone. Our incident response process includes immediate containment, impact assessment, root cause analysis, and remediation. All incidents are documented with post-incident reviews to improve detection and response capabilities.
Incident management type
Supplier-defined controls
Incident management approach
We maintain documented incident response procedures with pre-defined playbooks for common scenarios including service outages, security breaches, and infrastructure failures.
Users report incidents via email, dedicated Slack channels, or direct contact with on-call personnel. Status pages display current service status and ongoing incidents.
Incident severity determines response timeline and communication frequency. Post-incident reports documenting root cause, impact, and preventive measures are shared with affected stakeholders within 48 hours of resolution, ensuring transparency and continuous improvement.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2.5%
Between £500,001 and £1,000,000
2.5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Bb6ec7d3-1c77-45f3-b4dc-708027898d8c
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Working conditions which promote an inclusive working environment and promote retention and progression

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at j.tillotson@1xinternet.com. Tell them what format you need. It will help if you say what assistive technology you use.