CloudBuy Plc


Secure application development framework based on content management system with smart forms extended by databases. Database to forms or forms to database. Advanced logic available via dot Net support for SQL, noSQL and cube data storage. ISO 27001, PCI/DSS and OFFICIAL Sensitive support including design, hosting and penetration testing.


  • PCI DSS Level 1, OFFICIAL Sensitive and ISO 27001 certified
  • Integration with existing EPR/finance systems
  • Single sign on
  • Supports document standards for orders, invoices, credit notes
  • Shopping basket
  • Discount engine
  • Promotional engine
  • Block based content management system with full revision history
  • Integration engine
  • Full HTML, CSS customisation


  • Rapid application development
  • Non-developers can create forms and build up user interface
  • Designers and developers can enhance
  • Most security issues removed by design
  • Extensively tested and accredited for OFFICIAL Sensitive
  • Highly scalable and available on cloud platform
  • Integrated into Oracle, SAP, and other major ERP/finance systems
  • Ensures adherence to contracts
  • Integrated into all major payment gateways and BACS network
  • Available on desktop, mobile and tablet


£2250 per instance per month

Service documents

G-Cloud 11


CloudBuy Plc

David Gibbon

0118 963 7000

Service scope

Service scope
Service constraints On occasion cloudBuy completes planned maintenance, this typically takes place out of core business hours or over weekends. Customers are informed of any planned maintenance well in advance through posts to our shared user forum which all customers are invited to free of charge
System requirements Network access

User support

User support
Email or online ticketing support Email or online ticketing
Support response times Our Support Team works Monday-Friday from 9am until 5pm UK time. Depending on the severity of the issue, the Support Team aims to respond to all queries within 30 minutes-2 business hours.
User can manage status and priority of support tickets Yes
Online ticketing support accessibility WCAG 2.1 AAA
Phone support Yes
Phone support availability 9 to 5 (UK time), Monday to Friday
Web chat support No
Onsite support No
Support levels You will be assigned a Solution Delivery Manager (SDM) who will be your port of call for any queries and support. Support via phone and email is included at no extra cost. It is provided during the office hours of Monday-Friday, 9am-5pm UK time. The severity of any issues reported affects the response time. If an issue has immediate priority, we aim to respond to you within 30 minutes and resolve the issue in two business hours. We have user guides to support your use of the system.
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started CloudBuy provides user guides and supportive documentation for each service. On site or online training can be provided through the purchase of Training module, cost of this is subject to the service purchased.
Service documentation Yes
Documentation formats PDF
End-of-contract data extraction Download functionality is available for customers to download data. cloudBuy will work with the customer to achieve the extract of additional data as part of the exit plan.
End-of-contract process CloudBuy will establish if the customer wishes to renew the service. If not, access to the service will be disabled for the customer at the contract end date. cloudBuy provides the data associated with the contract as part of its standard service at no additional charge. The customer can get a custom extract or a data conversion by cloudBuy into a different format for a charge that depends on the transformation required.

Using the service

Using the service
Web browser interface Yes
Using the web interface The web interface controls all aspects of the service including set up, changes and maintenance.
Web interface accessibility standard WCAG 2.1 AAA
Web interface accessibility testing We have health and social care user groups with different assistive technology requirements that test the system.
What users can and can't do using the API Applications can use the API to connect to the service and configure the service. cloudBuy supports multiple industry standard APIs including SAP, Oracle and open APIs and along with cloudBuy's own API. Each of the APIs has documentation and cloudBuy can assist with using the APIs. There are a large number of industry standard APIs in this area and cloudBuy supports all the major APIs and has an integration team that can quickly add on new APIs for integration with new systems.
API automation tools Terraform
API documentation Yes
API documentation formats PDF
Command line interface No


Scaling available Yes
Scaling type Automatic
Independence of resources Our service is available across multiple datacentres and is able to shift demand to data centres with guaranteed availability.
Usage notifications Yes
Usage reporting
  • Email
  • SMS


Infrastructure or application metrics Yes
Metrics types
  • CPU
  • Disk
  • HTTP request and response status
  • Memory
  • Network
  • Number of active instances
Reporting types Reports on request


Supplier type Not a reseller

Staff security

Staff security
Staff security clearance Other security clearance
Government security clearance Up to Developed Vetting (DV)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations United Kingdom
User control over data storage and processing locations Yes
Datacentre security standards Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency At least every 6 months
Penetration testing approach ‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process Yes
Data sanitisation type Explicit overwriting of storage before reallocation
Equipment disposal approach A third-party destruction service

Backup and recovery

Backup and recovery
Backup and recovery Yes
What’s backed up
  • All aspects of the service are backed up
  • Data is replicated in realtime to a 2nd datacentre
Backup controls Additional backups can be performed on top of the base line service which is redundant infrastructure and regular backups
Datacentre setup Multiple datacentres with disaster recovery
Scheduling backups Supplier controls the whole backup schedule
Backup recovery Users contact the support team

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network TLS (version 1.2 or above)

Availability and resilience

Availability and resilience
Guaranteed availability CloudBuy normally provides a 99.9% SLA and has a 100% track record of meeting this SLA. Customers that require a 100% uptime SLA can pay an additional amount based on the level of business loss as a result of down time. cloudBuy is normally providing ecommerce systems where the requirement is 100% availability 24 x7 x 365.
Approach to resilience CloudBuy has a N+2 redundancy standard covering firewalls, applications and storage systems spread over multiple datacentres. cloudBuy is normally providing ecommerce systems were the requirement is 100% availability 24 x7 x 365.
Outage reporting CloudBuy provides customers with access to the cloudBuy user forum which is used to update and inform customers of incidents, outages, planned maintenance and upgrades. Notifications are sent to customers as part of the user forum workflow.

Identity and authentication

Identity and authentication
User authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google apps)
  • Username or password
Access restrictions in management interfaces and support channels Private network and 2 factor authentication.
Access restriction testing frequency At least every 6 months
Management access authentication
  • 2-factor authentication
  • Username or password
Devices users manage the service through
  • Dedicated device on a segregated network (providers own provision)
  • Dedicated device on a government network (for example PSN)
  • Dedicated device over multiple services or networks
  • Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)

Audit information for users

Audit information for users
Access to user activity audit information Users have access to real-time audit information
How long user audit data is stored for Between 1 month and 6 months
Access to supplier activity audit information Users have access to real-time audit information
How long supplier audit data is stored for At least 12 months
How long system logs are stored for At least 12 months

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification Yes
Who accredited the ISO/IEC 27001 NQA
ISO/IEC 27001 accreditation date 12/06/2018
What the ISO/IEC 27001 doesn’t cover Nothing, everything related to customer data is covered.
ISO 28000:2007 certification No
CSA STAR certification No
PCI certification Yes
Who accredited the PCI DSS certification ComSec
PCI DSS accreditation date 31/07/2018
What the PCI DSS doesn’t cover No current exclusions (sometimes we need to exclude certain customer systems which do not meet the PCI standard, but we aim to have all systems up to standard, e.g. when we had Government customers that continued to use FTP after its use was prohibited by PCI)
Other security certifications Yes
Any other security certifications Cyber Essentials

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance certified Yes
Security governance standards ISO/IEC 27001
Information security policies and processes CloudBuy is certified ISO 27001 for information security. cloudBuy completes audits and we are re-certified annually. cloudBuy is also externally audited for PCI DSS compliance at Level 1.

Operational security

Operational security
Configuration and change management standard Supplier-defined controls
Configuration and change management approach There is a separation of duties and an automated process. After agreeing a business requirement, our developer(s) complete and review and then it is merged by another developer. Changes are regression tested and then passed to QA for testing. They are then deployed in an automated process without downtime. The core of the system is a secure, penetration tested framework to ensure security. Penetration testing is carried out regularly with addtional tests carried out when any changes have a potential security impact.
Vulnerability management type Supplier-defined controls
Vulnerability management approach CloudBuy's infrastructure is tested annually and after any major system alterations. Testing is performed by PCI and CHECK accredited testers, comprising checks of possible holes in our security. They identify high-risk vulnerabilities, including a combination of low-risk vulnerabilities applied in sequence or those that are not necessarily picked up during our own scans. We also carry out quarterly internal and external network scans by an accredited PCI scanner, as well as our own internal and external daily scans. Any vulnerabilities are imemdiately patched.
Protective monitoring type Supplier-defined controls
Protective monitoring approach We have a PCI accredited external monitoring company monitoring our logs for any attacks or compromises along with our SIEM and if we have an incident we respond immediately.
Incident management type Supplier-defined controls
Incident management approach Our incident management process covers immediate response to any serious incident along with proactive notification to any affected customers and regular updates to any affected customers. We regularly test incident response and look at how we can continuously improve our processes with pre-defined processes for potential major events. Incidents are not a common event. Users can report incidents through our applications, email or phone. We provide incident reports via our forums, and our ticketing system which we share with customers so that they can see the status of any ticket or indident.

Secure development

Secure development
Approach to secure software development best practice Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Separation between users

Separation between users
Virtualisation technology used to keep applications and users sharing the same infrastructure apart Yes
Who implements virtualisation Supplier
Virtualisation technologies used KVM hypervisor
How shared infrastructure is kept separate Depending on the security requirements a customer can either join the general pool, or can have a separate network and infrastructure. Normally customers have a development infrastructure and production infrastructure. The infrastructure is a complete set of firewalls, loadbalances, app servers and database servers in its own separate environment.

Energy efficiency

Energy efficiency
Energy-efficient datacentres Yes
Description of energy efficient datacentres We use highly Efficient carbon neutral datacentres.


Price £2250 per instance per month
Discount for educational organisations No
Free trial available No

Service documents

pdf document: Pricing document pdf document: Skills Framework for the Information Age rate card pdf document: Terms and conditions
Service documents
Return to top ↑