Skip to main content

Help us improve the Digital Marketplace - send your feedback

WM Promus

Aqua Software - The Complete Cloud Native Security Platform

Protect cloud native applications by minimizing their attack surface, detecting vulnerabilities, embedded secrets, and other security issues. Gain insight into your vulnerability posture and prioritize remediation and mitigation according to contextual risk. Accelerate development, enforce compliance, gain real-time visibility and control over your security posture and protect applications.

Features

  • Cloud Native Posture Management (CSPM)
  • Vulnerability Scanning
  • Dynamic Threat Analysis
  • Container, Kubernetes, Cloud VM & Serverless Security
  • Identity-Based Segmentation
  • Regulatory Compliance
  • Multi-Application RBAC
  • Platform and Integrations
  • Standalone on premise available also

Benefits

  • Remove application security vulnerabilities
  • Cloud agnostic
  • Single pane of glass for security management
  • “Shift left” security into the CI/CD pipeline
  • Full visibility into the security posture of your pipeline
  • Monitor, detect, and automatically remediate configuration issues
  • Coverage for all clouds and platforms
  • Integrating with your existing infrastructure and the cloud native ecosystem
  • Unify security across VMs, containers, and serverless
  • Leverage micro-services concepts to enforce immutability and micro-segmentation

Pricing

£650 to £1,300 an instance a year

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ewong@wmpromus.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

9 3 7 2 1 7 5 0 2 8 9 8 5 0 0

Contact

WM Promus Emma Wong
Telephone: 44 (0) 203 946 6226
Email: ewong@wmpromus.com

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
No service constraints
System requirements
  • Cloud native - system requirements doc provided
  • Refer to https://docs.aquasec.com/

User support

Email or online ticketing support
Yes, at extra cost
Support response times
We provide comprehensive support for cloud-based and on premise services. This includes helping you choose the right cloud platform, migrating your applications, and ongoing maintenance. We also offer expert guidance on security, scalability, and performance optimization. Our goal is to ensure your cloud environment runs smoothly so you can focus on your core business. We offer a service where we act as a conduit between clients and vendors or hosting providers in addition to being the first point of contact should an incident occur. We operate a world-class servicedesk and follow ITIL best practice to deliver the service support.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
The software is supported by the vendor - Aqua Security. See aquasec.com. WM Promus can also provide support for a fee - We provide comprehensive support for cloud-based and on premise services. This includes helping you choose the right cloud platform, migrating your applications, and ongoing maintenance. We also offer expert guidance on security, scalability, and performance optimization. Our goal is to ensure your cloud environment runs smoothly so you can focus on your core business. We offer a service where we act as a conduit between clients and vendors or hosting providers in addition to being the first point of contact should an incident occur. We operate a world-class servicedesk and follow ITIL best practice to deliver the service support.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
WM Promus Aqua Security accredited engineers can design and implement any customisations required. WM Promus also provides training and healthchecks related to Aqua s/w. There is also extensive Aqua documentation available on the Aqua website and a customer success portal to aid clients. Contact info@wmpromus.com
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
  • Website
  • Customer Success portal
  • Training
  • Cloud native wiki
End-of-contract data extraction
User policy data, vulnerability data and system settings data can be exported if hosted on premise. Cloud deployments can have an extraction of same or choose to have data deleted at the end of the contract.
End-of-contract process
This is agreed on a per client basis.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • Windows Phone
  • Other
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
No service disparity
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Aqua Security software interacts with users and external systems primarily through its web-based management console. This console provides a graphical interface for users to manage security policies, view security posture, and investigate threats.
Accessibility standards
None or don’t know
Description of accessibility
Aqua software includes a range of software features and the accessibility features might differ. Please email info@wmpromus.com for further details.
Accessibility testing
Aqua software includes a range of software features and the accessibility features might differ. Please email info@wmpromus.com for further details.
API
Yes
What users can and can't do using the API
Full accessibility of Aqua s/w via API including but not limited to scanning data, policy management, and audit information.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Client security requirements specific to each client can be implemented: policies etc. WM Promus provide DevSecOps consultancy services that assist with Aqua set up, configuration and management.

Scaling

Independence of resources
If it is an on-premise service, the client runs the solution on their own cluster.
For a SaaS-based arrangement, the client has a client-tenant provided.

Analytics

Service usage metrics
Yes
Metrics types
Metrics on use of repositories, number of enforcers deployed, number of scans, number of images.
Provide the metrics via Rest API and Real-time dashboards
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Aqua

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Users can export data directly from the Postgres database
Data export formats
  • CSV
  • Other
Other data export formats
  • Zip
  • Json
Data import formats
Other
Other data import formats
Json

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Our cloud service will be available as per the availability of the underlying cloud (e.g. Azure, GCP or AWS).
Approach to resilience
On premise solutions can embed resilience through distributed clusters and managing load balancing via pods or containers in addition to other configuration choices. For SaaS solutions, resilience is provided through a distributed infrastructure, built in redundancy, and the system is designed for error handling and recovery. Aqua Platform SaaS Edition is deployed in multiple regions around the world. Each region operates as an independent instance of Aqua Platform, with all customer data remaining physically in that region.

Each region offers the same services (powered by AWS compute services).
Each region offers the same SLA (service-level agreement).
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Username or password
Access restrictions in management interfaces and support channels
These settings are for the customer discretion. We recommend connecting to customer’s SSO/SAML provider. Role based access control can be enabled to control access.
Access restriction testing frequency
At least once a year
Management access authentication
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
WM Promus have a named board-level person responsible for service security. WM Promus conducts annual reviews of its policies around the delivery of SAAS, and all services and undertakes a 3rd party annual cybersecurity assessment in accordance with the government national cybersecurity program, thus WM Promus maintains cybersecurity essentials certification. WM Promus regularly re-evaluates and updates its information and physical security program as the industry evolves, new technologies emerge or new threats are identified.
Information security policies and processes
WM Promus have in place security policies related to: Acceptable Encryption and Key Management Policy Acceptable Use Policy Clean Desk Policy Data Breach Response Policy Disaster Recovery Plan Policy Personnel Security Policy Data Backup Policy User Identification, Authentication, and Authorization Policy Incident Response Policy End User Encryption Key Protection Policy Risk Assessment Standards and Procedures Remote Access Policy Secure Systems Management Policy Monitoring and Logging Policy Change Management Policy In addition, WM Promus have a named board-level person responsible for service security.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
WM Promus conduct a structured approach (supported by version control tools) to releases. There is a rigorous testing process prior to all releases (supported by tools such as vulnerability scanners within version control tools) to ensure mitigation of security risks. WM Promus adopt industry best practice (ITIL) in addition to DevOps & DevSecOps best practices relating to configuration and change management. Aqua (the SaaS provider) has ISO 27001 and SOC 2 Type II certified with best-practice configuration and change management processes in place (ITIL compliant).
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
WM Promus conduct a structured approach (supported by version control tools) to releases. There is a rigorous testing process prior to all releases (supported by tools such as vulnerability scanners within version control tools) to ensure mitigation of security risks. WM Promus adopt industry best practice (ITIL) in addition to DevOps & DevSecOps best practices relating to configuration and change management. Aqua (the SaaS provider) has ISO 27001 and SOC 2 Type II certified with best-practice configuration and change management processes in place (ITIL compliant)
Protective monitoring type
Undisclosed
Protective monitoring approach
WM Promus conduct a structured approach (supported by version control tools) to releases. There is a rigorous testing process prior to all releases (supported by tools such as vulnerability scanners within version control tools) to ensure mitigation of security risks. Scanning tools feedback ensures that WM Promus respond immediately upon vulnerability awareness. WM Promus adopt industry best practice (ITIL) in addition to DevOps & DevSecOps best practices relating to configuration and change management. Aqua (the SaaS provider) has ISO 27001 and SOC 2 Type II certified with best-practice configuration and change management processes in place (ITIL compliant)
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
WM Promus adhere to industry best practice (ITIL) for Incident Management. In terms of communication, WM Promus can be contacted by telephone and email. Escalations and communications including updates are accessible via email and phone.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
Yes
Connected networks
  • Public Services Network (PSN)
  • Police National Network (PNN)
  • NHS Network (N3)
  • Joint Academic Network (JANET)
  • Scottish Wide Area Network (SWAN)
  • Health and Social Care Network (HSCN)
  • Other
Other public sector networks
Possible to deploy to any network permission allowing

Social Value

Social Value

Social Value

  • Fighting climate change
  • Covid-19 recovery
  • Tackling economic inequality
  • Equal opportunity
  • Wellbeing

Fighting climate change

Aqua Software is part of a Digital transformation mindset, which will improve business processes and offerings through leveraging new technologies and forms a vital part of the way we cut emissions and reduce waste. In terms of climate change, many of our Aqua Software solutions and services are delivered in conjunction with a move to cloud technology with a cloud-based model being a more energy efficient approach than traditional on premise. All Aqua Software services include a discovery phase. As part of this, we assess client data requirements. We encourage clients to actively consider minimising storage; redundant, obsolete or trivial data incurs energy costs and is counter-productive in terms of delivering on a commitment to climate change. Not only does the discovery phase focus on planning what to automate, it looks at making configuration management, development and the collaboration between employees more efficient – including energy efficient; reducing carbon footprints though unnecessary print jobs, underutilised resources and poor configuration.

Covid-19 recovery

Our Aqua Software solutions and services were instrumental in supporting clients since the impact of Covid-19 hit UK businesses in early 2020. Through our Aqua Software solutions and services, we continue to enable new ways of working and strengthened service resilience by automating processes that proved challenging due to a reduced workforce because of COVID-19. For some clients, our Aqua Software solutions are critical where the increased demand on personnel cannot be met by the current workforce. Critically, WM Promus provide pricing that offers substantial discounts to public sector organisations. In addition, we enable remote work; our services empower organizations to increase remote work capabilities. This promotes social distancing and reduces the risk of transmission while ensuring business continuity. Boosting Collaboration: Features like video conferencing, secure file sharing, and real-time communication tools within our services and project delivery approaches foster collaboration across dispersed teams.

Tackling economic inequality

Tackling economic inequality - WM Promus create opportunities for entrepreneurship and help new organisations to grow, tackling economic inequality, supporting economic growth and business creation. WM Promus provides free TED talks about technology advances and how they can help start-up businesses and SME’s to scale up and grow. We host these onsite (and virtually) at our serviced offices where there is a large community of SMEs. These TED talks are free to attend (either in person or virtually). For example, our TED talk “Curious about Artificial Intelligence - Will it help you or replace you?” provided answers to questions such as “What AI solutions can I use to help me in my current role?“ . The feedback on these sessions is that they significantly benefit SMEs who attend with valuable insights into AI tools (that are free) and can be leveraged for innovation and efficiency. WM Promus offer opportunities for work experience or similar activities. WM Promus provides quality secondary-school work-experience placements designed to provide students with practical, hands-on experience in the field of IT consultancy. The school with whom we engage has over two thirds of pupils from minority ethnic backgrounds, over half of the pupils eligible for pupil premium, and a pupil’s attainment at entry level significantly below the national average. Our placements aim to allow students to develop technical skills, gain exposure to professional work environments, and explore potential career paths within the IT sector.

Equal opportunity

Equal opportunity - WM Promus have a robust Equality, Diversity, and Inclusion (EDI) Policy. The applications we resell and deliver services against are accessible to users with disabilities by incorporating features like keyboard navigation and screen reader compatibility, user interface elements that cater to diverse visual needs and so on. In addition, they offer multilingual support aligned with our inclusion policy. Our diverse workforce informs training materials and support services offered alongside our solutions.

Wellbeing

Wellbeing- WM Promus promote Work-Life Balance and facilitate flexible work for employees. Our services and solutions also do this for clients through asynchronous communication tools (allowing for responses outside core working hours), mobile access for remote work and flexible schedules (thus helping client engineers achieve a better work-life balance by offering them more control over their workload and schedule). Our services and solutions also reduce work stress through automated and streamlined workflows. Automating repetitive tasks frees up users' time and reduce stress associated with manual, time-consuming processes. Our services and solution embed easy-to-use and intuitive interfaces minimizing frustration and cognitive load for users, contributing to a more positive work experience. The Data Privacy and Security features within our offerings demonstrate a commitment to user wellbeing by protecting sensitive information and reducing stress related to potential data breaches.

Pricing

Price
£650 to £1,300 an instance a year
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Time limited trials are available. Assistance with use of the service during the trial is available.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ewong@wmpromus.com. Tell them what format you need. It will help if you say what assistive technology you use.