Gaia Technologies Plc

Gaia Open edX Platform

The Open edX platform is a free--and open source--course management system (CMS) that was originally developed by edX. The Open edX platform is used all over the world to host Massive Open Online Courses (MOOCs) as well as smaller classes and training modules.

Features

  • Open edX Studio
  • The Open edX LMS (Learning Management System)
  • The capa_module XBlock (LON-CAPA problem types)
  • The ORA2 XBlock, which implements an open response assessment type
  • Discussion forum
  • Open edX Insights

Benefits

  • The Open edX platform is a free
  • The Open edX platform is open source
  • he Open edX platform is used all over the world
  • Host Massive Open Online Courses (MOOCs)

Pricing

£4000 per unit

  • Education pricing available
  • Free trial available

Service documents

G-Cloud 9

177904199889250

Gaia Technologies Plc

Ayad Mawla

01248675800

ayad@gaia-tech.com

Service scope

Service scope
Software add-on or extension No
Cloud deployment model Public cloud
Service constraints N/a
System requirements Internet Browser

User support

User support
Email or online ticketing support Email or online ticketing
Support response times P1: Critical - Response Time: 2hr
P2: Major - Response Time: 4hr
P3: Important - Response Time: 8hr
P4: Minor - Response Time: Varies on request
User can manage status and priority of support tickets Yes
Online ticketing support accessibility None or don’t know
Phone support Yes
Phone support availability 24 hours, 7 days a week
Web chat support Web chat
Web chat support availability 24 hours, 7 days a week
Web chat support accessibility standard WCAG 2.0 AA or EN 301 549 9: Web
Web chat accessibility testing N/a
Onsite support Yes, at extra cost
Support levels 1 - Light:
- Email/Skype (chats) Support.
- Guaranteed Response Time: 8h.
- Guaranteed Resolution Time: up to 48h
- Total Consultancy and Development time of 5h
- Bug fixing if an issue was found in our code (not in edX functionality)
- Website Monitoring and Alarm Notification

2- Standard
- Same as Light but with
- Guaranteed Response Time: 6h
- Guaranteed Resolution Time: 16h - 24h
- Total Consultancy and Development time of 10h

3- Strong
- Same as Standard but with
- Guaranteed Response Time: 4h
- Guaranteed Resolution Time: 8h - 16h
- Total Consultancy and Development time of 15h.

4- VIP
- Same as Strong but with
- Guaranteed Response Time: 2h and 30min*
- Guaranteed Resolution Time: 2h - 8h
- Total Consultancy and Development time of 20h.
- 24x7 emergency response
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started Community Discussions

Get questions answered by edX and the Open edX community via our community discussion resources, including mailing lists, chat and Twitter. All fall under our community discussion guidelines.

Mailing Lists

We strongly encourage joining one or more of the mailing lists to keep up with what's happening and participate in community discussions.

openedx-announce: announcements related to Open edX. This includes new releases, backwards-incompatible changes, public security fixes, and so on.
openedx-ops: everything related to running Open edX. This includes installation issues, server management, cost analysis, and so on.
openedx-translation: everything related to translating Open edX into other languages. This includes volunteer translators, our internationalization infrastructure, issues related to Transifex, and so on.
openedx-analytics: everything related to analytics in Open edX.
edx-code: anything else related to Open edX. This includes feature requests, idea proposals, refactorings, and so on.
Chat on Slack

Our real-time conversations are on Slack. You can request a Slack invitation automatically, then join our community Slack team.

A full public archive of the Open edX Slack team is also available.

Twitter

Follow the Open edX community on Twitter at @OpenedX
Service documentation Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats Visit docs.edx.org
End-of-contract data extraction At any point user can export data from Open edX.
End-of-contract process All data will be retained in storage containers paid for by the customer on AWS, Azure or Google Cloud. Gaia does will not control customer

Using the service

Using the service
Web browser interface Yes
Supported browsers
  • Internet Explorer 10+
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari 9+
Application to install No
Designed for use on mobile devices Yes
Differences between the mobile and desktop service Dynamics 365 allows access and functionality to be provided via mobile devices with via a web browser or mobile application. The solution supports a model that only requires configuration to be carried once regardless of how the solution is accessed.
Accessibility standards WCAG 2.0 AA or EN 301 549
Accessibility testing N/a
API Yes
What users can and can't do using the API The Open edX Platform ReST APIs are a rapidly growing and evolving set of capabilities that enable you to build web, desktop, and mobile applications that work with your Open edX instance.

All Open edX Platform ReST APIs are described in the edX Platform API documentation. See: http://edx.readthedocs.org/projects/edx-platform-api/en/latest/

Currently the Open edX Platform includes the following APIs.

Enrollment API

Use the Enrollment API to view user and course enrollment information and to enroll a user in a course.

User API

Use the User API to view and update user account and preferences information.

Data Analytics API

Use the Data Analytics API to view and analyze student activity in your course.
API documentation Yes
API documentation formats HTML
API sandbox or test environment No
Customisation available Yes
Description of customisation Have a question about Open edX? The Open edX team is dedicated to enabling the community to host, extend, and contribute to the edX platform to deliver world-class educational experiences. There are a number of different ways for you to get help and find the resources you need.

Online Resources

Technical Documentation

Our technical documentation is designed to help the community deploy, extend, and contribute to Open edX. Documentation is also available to help course teams build courses using our technology, and help learners engage with those courses. Our docs.edx.org website includes guides to the features and functionality in the most recent Open edX release, and another set of guides to the latest, most up-to-date Open edX software.

Open edX Release Notes
Installing, Configuring, and Running the Open edX Platform
Building and Running an Open edX Course
Open edX Learner's Guide
Open edX Developer's Guide
Open edX XBlock Tutorial
Visit docs.edx.org, or click on the Documentation link at the top navigation of this portal.

Courses (or, "MOOCs about MOOCs")

The edx.org website offers several self-paced MOOCs to help course teams get started with Studio and use the LMS to improve educational outcomes.

Scaling

Scaling
Independence of resources Gaia can deploy the service in AWS, Azure or Google Cloud where the service operates multiple scale groups in each data centre and automatically provisions new customers into a scale group. The architecture of scale groups is designed to meet the many needs of operating a service at scale, including security, scalability, performance, tenant isolation, serviceability, and monitoring. Each customer has their own individual database, separate from other customers’ databases. Data processing is logically segregated through capabilities specifically developed to help build, manage, and secure multitenant environments.

Analytics

Analytics
Service usage metrics Yes
Metrics types EdX Insights makes information about courses available to course team members who have the Staff or Admin role. EdX Insights provides these course team members with data about learner activity, background, and performance throughout the course. Using edX Insights can help you monitor how learners are doing, and validate the choices you made in designing your course. It can also help you re-evaluate choices and inform efforts to improve your course and the experience of your learners.

Please see http://edx.readthedocs.io/projects/edx-insights/en/latest/Overview.html for more information
Reporting types
  • API access
  • Real-time dashboards

Resellers

Resellers
Supplier type Reseller providing extra features and support
Organisation whose services are being resold Open edX Platform

Staff security

Staff security
Staff security clearance Other security clearance
Government security clearance Up to Developed Vetting (DV)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations Yes
Datacentre security standards Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency At least once a year
Penetration testing approach ‘IT Health Check’ performed by a Tigerscheme qualified provider or a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v3.0
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Other
Other data at rest protection approach The above refers to data hosting on Public Cloud providers such as Microsoft Azure, AWS, or Google Cloud. where your organization’s files are distributed across multiple Azure Storage containers, each with separate credentials, rather than storing them in a single database.
Data sanitisation process Yes
Data sanitisation type Deleted data can’t be directly accessed
Equipment disposal approach Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data importing and exporting
Data export approach Data can be exported from edX through the Export to Excel feature and using web service APIs documented http://docs.edx.org/
Data export formats
  • CSV
  • ODF
Data import formats
  • CSV
  • Other
Other data import formats
  • SCORM
  • Tincan API
  • Documents (Excel, Word, JPG, HTML5, etc)

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks For data in transit, all customer-facing servers negotiate a secure session by using TLS/SSL with client machines to secure the customer data. This applies to protocols on any device used by clients, such as Skype for Business Online, Outlook, and Outlook on the web. See also http://aka.ms/Office365CE
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Availability and resilience
Guaranteed availability The services is hosted on AWS, Google or Azure Cloud and directly benefit from their availability and resilience.
Approach to resilience Please see https://docs.microsoft.com/en-us/azure/architecture/resiliency/ for resilience on Azure network
Outage reporting Microsoft Azure reports outages via the service status portal

https://azure.microsoft.com/en-gb/status/

Alert or Mobile Application

Identity and authentication

Identity and authentication
User authentication needed Yes
User authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication Modern authentication Modern authentication brings Active Directory Authentication Library (ADAL)-based sign-in to Office client apps across platforms, enabling sign-in features such as Multi-Factor Authentication (MFA), SAML-based third-party identity providers with Office client applications, and smart card and certificate-based authentication.

Cloud identity authentication - Users with cloud identities are authenticated using traditional challenge/response.

Federated identity authentication - Users with federated identities are authenticated using Active Directory Federation Services 2.0 or other Security Token Services.

MFA for Office 365 - users are required to acknowledge a phone call, text, or an app notification on their smartphone after correctly entering their password.

https://technet.microsoft.com/en-us/library/office-365-user-account-management.aspx
Access restrictions in management interfaces and support channels The service comes with a set of administrator roles that you can assign to users in your organization. Each admin role maps to common business functions, and gives those people permissions to do specific tasks the the service admin center.

https://support.office.com/en-gb/article/About-Office-365-admin-roles-da585eea-f576-4f55-a1e0-87090b6aaa9d?ui=en-US&rs=en-GB&ad=GB

https://support.office.com/en-gb/article/Assign-admin-roles-in-Office-365-eac4d046-1afd-4f1a-85fc-8219c79e1504?ui=en-US&rs=en-GB&ad=GB
Access restriction testing frequency At least once a year
Management access authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Audit information for users
Access to user activity audit information Users have access to real-time audit information
How long user audit data is stored for Between 6 months and 12 months
Access to supplier activity audit information Users receive audit information on a regular basis
How long supplier audit data is stored for Between 6 months and 12 months
How long system logs are stored for Between 6 months and 12 months

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification Yes
Who accredited the ISO/IEC 27001 BSI
ISO/IEC 27001 accreditation date 11/09/2016
What the ISO/IEC 27001 doesn’t cover None
ISO 28000:2007 certification No
CSA STAR certification Yes
CSA STAR accreditation date 29/4/2016
CSA STAR certification level Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover None
PCI certification No
Other security accreditations Yes
Any other security accreditations
  • HIPAA/HITECH,
  • EU Model Clauses,
  • EU-U.S. Privacy Shield,
  • ISO 27001,
  • ISO 27018,
  • SOC 1, SOC 2
  • FIPS 140-2,

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance accreditation Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards Above and below refer to Microsoft Azure.

FISMA/FedRamp,
EU Model Clauses,
HIPAA/HITECH,
ISB 1596,
ISO 27018,
SASE16 SOC1 & SOC 2
Information security policies and processes The Microsoft Cloud Security Policy is available via the Service Trust Platform aka.ms/stp

Operational security

Operational security
Configuration and change management standard Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach The service employs sophisticated software-defined service instrumentation and monitoring that integrates at the component or server level, the datacenter edge, our network backbone, Internet exchange sites, and at the real or simulated user level, providing visibility when a service disruption is occurring and pinpointing its cause.

Proactive monitoring continuously measures the performance of key subsystems of the the service services platform against the established boundaries for acceptable service performance and availability. When a threshold is reached or an irregular event occurs, the monitoring system generates warnings so that operations staff can address the threshold or event.
Vulnerability management type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach In support of the Information Security Policy, the service runs multiple layers of antivirus software to ensure protection from common malicious software. Servers within the the service environment run anti-virus software that scans files uploaded and downloaded from the service for viruses or other malware. Additionally, all mails coming into the service run through the Exchange Online Protection engine, which uses multiple antivirus and antispam engines to capture known and new threats against the system. Microsoft has its own Security Response Center (MSRC) that also supplies information to all our customers covering the whole range Microsoft products.
Protective monitoring type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach The service employs sophisticated software-defined service instrumentation and monitoring that integrates at the component or server level, the datacenter edge, our network backbone, Internet exchange sites, and at the real or simulated user level, providing visibility when a service disruption is occurring and pinpointing its cause.

Proactive monitoring continuously measures the performance of key subsystems of the the service services platform against the established boundaries for acceptable service performance and availability. When a threshold is reached or an irregular event occurs, the monitoring system generates warnings so that operations staff can address the threshold or event.
Incident management type Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach Please see http://aka.ms/Office365SIM

Secure development

Secure development
Approach to secure software development best practice Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Public sector networks
Connection to public sector networks No

Pricing

Pricing
Price £4000 per unit
Discount for educational organisations Yes
Free trial available Yes
Description of free trial 30 Day Trial of the Service for 10 users

Documents

Documents
Pricing document View uploaded document
Skills Framework for the Information Age rate card View uploaded document
Service definition document View uploaded document
Terms and conditions document View uploaded document
Return to top ↑