IaaS (Infrastructure as a Service)
Infrastructure as a Service is a subscription-based cloud service providing the infrastructure resource required to manage your key business systems. Hosted in the IOM or UK.
Features
- Subscription Based Scalable Cloud Infrastructure
- Hosted within Tier 3 Data Centre UK or IOM
- High Availability and Resilience
- Robust Security - ISO Accreditation
- Global Network Connectivity and Low Latency
- Hybrid and Bespoke Cloud Options
- Data Protection Cloud - 24x7 Support
- Disaster Recovery and Business Continuity Options
- Cost Efficient, Operational Savings. Low or No Capex Outlay Available
- Tailored Expertise with Enterprise Cloud Technologies
Benefits
- Reduces capital expenditure through a pay-as-you-go
- Rapid scalability to meet changing demand and seasonal usage patterns
- Improved resilience and uptime for critical public services
- Simplified IT operations with optional fully managed infrastructure
- Enhanced security and compliance compared to on-premise environments
- Faster deployment of digital services and applications
- Supports legacy system modernisation and cloud migration strategies
- Managed service available with 24x7 support and DR
- Data centres certified to ISO/IEC 27001
- Data hosted within secure, enterprise-grade facilities
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 5 0 4 7 4 4 9 0 5 5 0 1 8 1
Contact
SYNAPSE CONSULTANTS LIMITED
Sales Team
Telephone: 03306600001
Email: sales@synapse360.com
About your service
- Service categories
-
IaaS
IaaS Compute
- Container and serverless engine compute
- Other non-x86 instances
Virtualised x86
- General purpose
- Compute optimised
- Memory optimised
Accelerated
- GPUs
- APUs
Service scope
- Service constraints
- Hosting IOM (Isle of Man) or UK
- System requirements
-
- Effective Change Control - Inclusion for Security Products
- Supported Operating Systems
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
User support
- Email or online ticketing support
- Yes
- Support response times
- SLA's in place. P1 - P5. 24x7. But Standard support is Monday to Friday 9-5. Questions typically within 24 hours or less. Quicker if Business Critical. Please see SLA service guide for details.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
We have undertaken web chat testing with assistive technology users as part of our ongoing commitment to accessibility and inclusive design. Testing has included users who rely on screen readers (such as NVDA and JAWS), keyboard-only navigation, screen magnification, and voice input tools. These tests focused on common web chat journeys including initiating a chat, interacting with automated responses, escalating to a human agent, and ending a session.
Where Salesforce web chat and Salesforce AI Agent capabilities are used, we validate that AI-generated responses are compatible with assistive technologies, use clear and concise language, and avoid unnecessary complexity. We also test focus order, ARIA labelling, contrast, and error handling to ensure the chat interface remains usable throughout the interaction.
Feedback from testing is used to refine conversation flows, improve response clarity, and ensure the AI Agent supports, rather than hinders, accessible customer journeys. Testing is repeated following significant changes or upgrades. - Onsite support
- Yes, at extra cost
- Support levels
-
Incident Priority Summary - Standard
Priority Impact Summary Vendor Response Time Support Hours
1 – Critical Infrastructure down or severe disruption. No access to virtual machines; high user and operational impact. 2 hours Monday–Friday, 9:00am–5:00pm
2 – High Infrastructure degraded or major disruption. Loss of redundancy or critically low capacity (<5%). 4 hours Monday–Friday, 9:00am–5:00pm
3 – Medium Remediation required but no immediate risk. Reduced capacity (<10%) or management access issues. Next Business Day (NBD) Monday–Friday, 9:00am–5:00pm.
Incident Priority Summary (24/7 & Scheduled Services) Business Critical
Priority Impact Summary Vendor Response Time Support Hours
1 – Critical Infrastructure down or severe disruption. No access to virtual machines; high user and operational impact. 2 hours 24/7
2 – High Infrastructure degraded or major disruption. Loss of redundancy or critically low capacity (<5%). 4 hours 24/7
3 – Medium Remediation required with no immediate risk. Reduced capacity (<10%) or management access issues. Next Business Day (NBD) Mon–Fri, 8:00am–6:00pm
4 – Low (Planned) Manufacturer-recommended software or hardware patches or replacements (excluding major upgrades). Within 1 calendar month Patch & scheduled
5 – Planned Activity Annual assisted Disaster Recovery testing, including managed failover for business continuity testing. Scheduled 1 month in advance Mon–Fri, 8:00am–6:00pm - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Getting started is simple and supported at every stage:
Initial engagement: We work with you to understand requirements, workloads, security needs and outcomes.
Design & planning: Our specialists design an appropriate IaaS architecture aligned to your performance, resilience and compliance needs.
Onboarding & provisioning: Infrastructure is provisioned quickly using standardised, proven platforms.
Migration support: We assist with migrating data and workloads from on‑premise or other cloud environments.
Go‑live & optimisation: Services are validated, monitored and optimised, with ongoing support available 24/7.
Onsite training is available subject to cost. remote and online training available.
User documentation available also. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Exit Management and Offboarding summary
Customers may exit the service in line with contractual notice periods.
Secure return or deletion of data upon termination.
Migration support available where required. - End-of-contract process
-
The service includes a clear, structured end-of-contract and exit management process designed to minimise disruption and avoid supplier lock-in.
Notice and planning: Upon contract termination or notice, we work with the customer to agree an exit plan, timelines and responsibilities.
Data return: Customer data can be securely exported in industry-standard formats to support migration to another provider or on‑premise environment.
Migration support: Optional technical assistance is available to support data and workload migration during the exit period.
Secure data deletion: Once data has been successfully transferred and confirmed, all remaining customer data is securely erased in line with recognised data destruction standards.
Access removal: Customer access credentials and connectivity are revoked in a controlled manner to maintain security.
Documentation and handover: Relevant configuration and service information can be provided to support continuity with a new supplier.
This process ensures customers retain full ownership and control of their data throughout the contract lifecycle. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Using the web interface
- Experience Cloud. To raise tickets to Log and receive updates to tickets
- Web interface accessibility standard
- WCAG 2.2 AA
- Web interface accessibility testing
- Salesforce full integration for Service Cloud
- API
- Yes
- What users can and can't do using the API
- Subject to request and SOW review. Standard service does have integration.
- API automation tools
-
- OpenStack
- Terraform
- API documentation
- Yes
- API documentation formats
-
- HTML
- Command line interface
- Yes
- Command line interface compatibility
-
- Linux or Unix
- Windows
- Using the command line interface
-
Users can interact with the service using a secure command line interface (CLI) to automate setup, configuration, and ongoing management tasks. The CLI enables users to deploy core service components, configure environments, manage users and permissions, and integrate the service into existing workflows using scripts or infrastructure-as-code tools.
Through the command line, users can make changes such as updating configuration settings, scaling resources, managing access controls, and triggering operational actions. These changes can be applied consistently across environments and are suitable for repeatable and automated processes.
Some limitations apply when using the CLI. Certain advanced configuration options, reporting features, or visual management functions may only be available through the web-based management interface or require elevated permissions. The CLI operates within defined security controls and governance policies, meaning users can only perform actions they are authorised for, and some changes may require validation or approval.
Comprehensive documentation and support are provided to help users safely and effectively use the CLI.
Scaling
- Independence of resources
-
The service is designed to ensure customer workloads remain independent and protected from the impact of other users, while demand is actively managed to maintain performance and availability.
Dedicated resource allocation: Customer environments are logically isolated with allocated compute, storage and network resources to prevent contention.
Capacity planning: Infrastructure capacity is proactively monitored and planned to ensure sufficient headroom for growth and peak demand.
Scalable architecture: Resources can be increased or decreased as required, supporting fluctuating demand without service degradation.
Monitoring and controls: Continuous monitoring identifies utilisation trends and potential bottlenecks before they impact service.
Fair usage and governance: - Usage notifications
- Yes
- Usage reporting
-
- API
- SMS
- Other
- Other usage reporting
- Direct engagement to technical personnel via Telecommunication methods etc
- Optimising consumption
- Yes
- Automatic scaling
- Yes
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Backup and recovery
- What’s backed up
-
- Scheduled backups of virtual machines and data, configurable
- Secure backup storage separated from primary production systems
- Retention policies aligned to business, regulatory or public sector requirements
- Point-in-time recovery options to restore systems or data following incidents.
- Protection against data loss caused by system failure, corruption, accidental
- Backup controls
- Subject to SOW and definitions. Standard terms apply otherwise.
- Datacentre setup
- Multiple datacentres with disaster recovery
- Scheduling backups
- Users contact the support team to schedule backups
- Backup recovery
- Users contact the support team
- Backup and recovery
- Yes
- RPO/RTO
- Yes
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
The service is designed to deliver high availability and reliability suitable for public sector workloads.
Infrastructure availability: Core IaaS infrastructure is delivered from Tier 3 data centres with resilient power, cooling and network connectivity.
Service uptime targets: The service operates to defined availability targets aligned to industry-standard SLAs, ensuring consistent access to hosted infrastructure.
Redundancy by design: N+1 redundancy is built into critical components to minimise the risk of service disruption.
Monitoring and incident response: Services are monitored 24/7, with incidents managed according to defined response and escalation procedures.
Service credits: Where availability targets are not met, service credits may apply in line with contractual terms.
Availability commitments and SLA details are clearly defined in the service agreement provided at contract award. - Approach to resilience
-
The service is designed with resilience at its core to ensure continuity of public sector services and minimise the impact of failures or incidents.
Resilient data centre design: Infrastructure is hosted in Tier 3 data centres with N+1 redundancy across power, cooling and critical systems.
Redundant connectivity: Multiple network paths and carriers are used to reduce the risk of connectivity failure.
High availability architecture: Virtualised platforms and clustered infrastructure reduce single points of failure.
Proactive monitoring: 24/7 monitoring enables early detection and response to potential issues before they impact service.
Disaster recovery options: Optional replication, failover and recovery services provide additional resilience where required.
Operational resilience: Documented incident, change and continuity processes support rapid recovery and service stability. - Outage reporting
- Dashboard, API, E-Mail alerts. Support staff
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls and least-privilege principles. Only authorised personnel are granted access based on job role and operational need. Strong authentication methods, including multi-factor authentication where appropriate, are enforced. Access rights are reviewed regularly and promptly revoked when no longer required. Administrative activities are logged and monitored to support security oversight and auditing.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Dedicated device on a government network (for example PSN)
- Dedicated device over multiple services or networks
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
The service is delivered in accordance with recognised information security standards and best practices to protect customer data and systems.
Information Security Policies and Processes
The following information security policies and processes are followed as part of service delivery:
Information Security Management: An established Information Security Management System (ISMS) aligned to ISO/IEC 27001, covering people, processes and technology.
Access control: Role-based access controls, least-privilege principles and multi-factor authentication where appropriate to restrict access to systems and data.
Physical security: Secure data centre facilities with controlled access, monitoring, CCTV and security procedures.
Network security: Segmented networks, firewalls and intrusion protection to prevent unauthorised access.
Vulnerability and patch management: Regular vulnerability assessments and timely patching of underlying infrastructure.
Incident management: Documented security incident response procedures, including detection, escalation, investigation and resolution.
Change management: Controlled change processes to minimise risk and maintain service stability.
Supplier and third-party management: Security controls applied to suppliers and partners involved in service delivery.
Data protection: Policies aligned to UK GDPR principles, ensuring confidentiality, integrity and availability of data.
Audit and assurance: Regular reviews, audits and compliance checks to ensure ongoing effectiveness of security controls.
Security responsibilities operate under a shared responsibility model, defining supplier and customer obligations.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management follow controlled, documented processes designed to maintain service stability and security. All infrastructure components are managed using standard configurations and version-controlled templates where applicable. Changes are assessed for risk and impact, approved through defined governance, and implemented in a planned manner. Emergency changes follow expedited but controlled procedures. Changes are communicated appropriately, monitored post-implementation, and reviewed to ensure successful outcomes and minimise disruption to customer services.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is delivered through a structured, risk-based approach. The underlying infrastructure is regularly assessed for vulnerabilities using industry-standard tools and threat intelligence. Identified vulnerabilities are prioritised based on severity and potential impact, with remediation actions scheduled accordingly. Security patches and updates are applied in line with defined maintenance processes. Vulnerability management activities are monitored and reviewed to ensure risks are reduced and the security posture is continuously improved.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Proactive monitoring is in place to ensure the availability, performance and security of the service. Infrastructure and core services are monitored 24/7 using automated monitoring tools to detect faults, performance degradation and capacity thresholds. Alerts are generated in real time and handled by experienced engineers following defined incident and escalation procedures. Monitoring trends are reviewed to identify potential issues early and support capacity planning and continuous service improvement.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management follows a structured, ITIL-aligned process to restore service as quickly as possible. Incidents are logged, categorised and prioritised based on impact and urgency. Automated alerts and monitoring enable rapid detection, with incidents escalated to appropriate technical teams. Progress is communicated to customers as required, and incidents are resolved using documented procedures. Post-incident reviews are conducted where appropriate to identify root causes and implement preventative improvements.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Supplier
- Virtualisation technologies used
- VMware
- How shared infrastructure is kept separate
- By separate instances that are secured. So, it depends on whether shared or a dedicated instance. Clear security controls and governance in situ
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- Our data centres are operated in alignment with the principles of the EU Code of Conduct for Energy Efficient Data Centres, demonstrating a commitment to reducing energy consumption and environmental impact. Energy efficiency is embedded into data centre design and operations, including the use of efficient cooling systems, resilient power infrastructure, and continuous monitoring of energy usage. Capacity planning and consolidation practices are used to avoid over-provisioning and unnecessary power consumption. Environmental controls are optimised to balance performance, resilience and efficiency, while regular reviews help identify opportunities for improvement. Operational procedures promote responsible energy use across facilities, supporting sustainable service delivery and compliance with recognised best-practice standards expected by public sector customers. We green energy supply only within our own data centres.
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- A limited, time-bound free trial is available, providing access to a restricted IaaS environment to evaluate core functionality, performance and management capabilities before committing to a full service.
- Link to free trial
- https://www.synapse360.com/post/can-i-get-a-free-consultation-or-trial-of-your-services
Discount
- Provide your minimum discount applicable to your baseline prices
- 5%
Formula for calculating price of your services
- Formula for calculating price of your services
-
Which of the core deployment models you intend to offer
Private CloudPrivate Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
- =
- Baseline Pricing
- Please review the price sheet guide available via G-Cloud or please contact sales@synapse360.com for further details or for a full SoW. Given the service maybe tailored, then we can provide clear and transparent quotes on request. But our guide is included for reference also.
- -
- Minimum Discounting
- 5%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- Any additional sources or costs refer to charges that are not included in the core service price and may be incurred where a Buyer chooses optional services or third-party components, such as hyperscaler consumption, software licences, connectivity, or enhanced support. All such costs are clearly identified, transparent, and optional, and are communicated to the Buyer in advance. No hidden or unexpected charges are applied, ensuring Buyers have full visibility of the total cost of ownership in line with G-Cloud 15 requirements.
- -
- Additional sources of cost reduction
- We support Buyers in reducing costs by optimising service usage through rightsizing, elastic scaling, automation, and efficient service configurations. Regular usage reviews and transparent reporting help identify opportunities to remove unnecessary consumption and select lower-cost options where appropriate. These measures enable Buyers to control expenditure, improve value for money, and maintain required service performance in line with G-Cloud 15 expectations.
Mandatory certifications
- Mandatory certifications
-
Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure
ResellerCloud service suppliers you intend to resell with evidence
Organisation 1
Organisation name
Dell TechnologiesWebsite address/upload for organisation
Website addressWebsite address
https://dell.my.site.com/FindAPartner/s/partnerdetails?language=en_US&country=gb&partnerType=findareseller&partnerTrackId=a9n1B000000giypQAAISO 9001 certification
ProvidedISO 27001 certification
ProvidedISO 20000-1 certification
ProvidedAre you reliant on the Cloud Service Provider for some accreditations
Yes
Cyber Essentials
- Do you have a Cyber Essentials Plus certificate?
- No
- Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies, by the date of framework award.
Non-mandatory Standards and certifications
- ISO 28000:2022 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Other security certifications
- Yes
- Any other security certifications
- Cyber Essentials
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
-