Ascensio System SIA

ONLYOFFICE Workspace

A self-hosted office suite with collaborative online editors for documents, spreadsheets and presentations, document management system, CRM, project management features, mail, calendars and corporate communication hub. ONLYOFFICE Enterprise Edition offers advanced security and monitoring features and is complemented with free ONLYOFFICE Desktop Editors and mobile applications for iOS and Android.

Features

  • set of professional document editing and formatting tools
  • two co-editing modes (real-time and paragraph-locking)
  • real-time collaboration with comments, chat, change tracking and versions
  • advanced document permissions: commenting, reviewing, filling forms
  • productivity tools to manage documents, emails, contacts, events
  • communication hub with blogs, forums, wiki, bookmarks, chat
  • advanced security options: LDAP, 2FA, E2EE, data logging and monitoring
  • free connectable desktop editors for Windows, Linux and Mac
  • mobile office for iOS and Android, mobile project management (iOS)
  • Private Rooms feature for document encryption and encrypted collaboration

Benefits

  • all-in-one business solution
  • highest MS Office format compatibility
  • integration with third-party services
  • total control over data
  • GDPR and HIPAA compliance
  • branding options
  • scalability
  • multitenancy
  • intuitive control panel
  • regular updates and professional tech support

Pricing

£953.53 a licence a year

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@onlyoffice.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 12

Service ID

5 1 3 3 2 9 5 9 6 9 7 1 2 3 6

Contact

Ascensio System SIA Konstantin Maistrenko
Telephone: +44 20 3287 1086
Email: sales@onlyoffice.com

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
No
System requirements
  • Linux or Windows server (specs listed in the documentation)
  • Mono (for Linux server)
  • MySQL (for Linux server)
  • NGINX (for Linux server)
  • MySQL Server (for Windows server)
  • Web browser

User support

Email or online ticketing support
Email or online ticketing
Support response times
Within 1-2 days, excluding weekends
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
Web chat
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.1 AA or EN 301 549
Web chat accessibility testing
We haven't done any web chat testing with assistive technology users ourselves.
Onsite support
No
Support levels
Level 1: functionality consultation, minor bug reporting, general questions, pre-sale assistance
Level 2: major bugs that require specific knowledge and the assistance of the developer team

Both levels are included in the price of the solutions.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide technical assistance by our Professional Services team, private demonstrations on request, complete user documentation available in our Help Center, and a variety of resources including our blog, video tutorials and webinars (live and on-demand).
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Customers have access to their data and right to retrieve most of the data and request a digital copy of the data which ONLYOFFICE has access to (e.g. sales-related) in a structured, commonly used and machine-readable format.

Retrieving the data stored within ONLYOFFICE solution ( e.g. for the purpose of migration or termination) can be achieved by using data backup options.

Only a customer organization has access to the user data and has an opportunity to provide these data to the users.
End-of-contract process
Upon the expiry of the license, the customer loses access to the updates and the full support service. However, ONLYOFFICE Enterprise Edition is provided with a lifetime license and the access to the solution remains full until the customer decides to erase the software from their infrastructure.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari 9+
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile web version supports all the features of the collaboration platform and mostly supports all features of the online editors.

There are also additional mobile applications for the office suite (with document management) for iOS and Android and the project management app for iOS.
Service interface
Yes
Description of service interface
The service has a web interface, typical for each module's category (e.g. online office suite, CRM, document management system, etc.)

The interface is organized through toolbars, buttons, fields, and texts. Different components of the interface can be used via separate browser tabs.
Accessibility standards
None or don’t know
Description of accessibility
Of the EN 301 549 9 criteria for web, ONLYOFFICE supports the following items:
Non-text content
Use of color
Audio control
Contrast
Images of text
Keyboard
Page titled
Link purpose
Multiple ways
Headings and labels
Focus
Language
On focus
On input
Consistent navigation
Consistent identification
Error identification
Labels or instructions
Error suggestion
Error prevention
Parsing
Name, role, value

All other criteria stated in the chapter is not applicable.
Accessibility testing
We have not done any testing with users of assistive technology.
API
Yes
What users can and can't do using the API
Users can customize ONLYOFFICE and integrate and configure the supported third-party software using the API.

More information: https://api.onlyoffice.com/
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Admins of the ONLYOFFICE portals can customize the interface appearance and change the set of components available to users and groups.

More information: https://helpcenter.onlyoffice.com/gettingstarted/configuration.aspx

Scaling

Independence of resources
ONLYOFFICE Enterprise Edition is self-hosted

Analytics

Service usage metrics
Yes
Metrics types
Portal creation date;
the number of active users registered on your portal;
the storage space allowed for the selected pricing plan;
the total storage space used;
the storage space used by each portal module or tool;
the total number of visits per day;
audit trail data;
login history and online status.
Reporting types
Real-time dashboards

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2012
Government security clearance
Up to Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
No
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
Less than once a year
Penetration testing approach
In-house
Protecting data at rest
Other
Other data at rest protection approach
Data protection at rest is defined by a customer's infrastructure
Data sanitisation process
No
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
Users can export their data using the backup functionality
Data export formats
Other
Other data export formats
.TAR.GZ
Data import formats
Other
Other data import formats
TAR.GZ

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
ONLYOFFICE Enterprise Edition is self-hosted and completely independent
Data protection within supplier network
Other
Other protection within supplier network
Not applicable

Availability and resilience

Guaranteed availability
Data availability is defined by a customer's infrastructure
Approach to resilience
Resilience is defined by a customer's infrastructure
Outage reporting
ONLYOFFICE cannot detect, observe and report outages happening on customer's infrastructure because ONLYOFICE Enterprise Edition is self-hosted.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
LDAP
Access restrictions in management interfaces and support channels
Through the settings, the portal users with owner and admin rights can filter authentication using the following criteria:
- Trusted mail domains;
- IP restriction;
- Password length (on registration);
- Cookie lifetime (automatic logout).

2FA and Single Sign-On options can be chosen to additionally manage the authentication security. It is also possible to enable the authentication via LDAP Server (OpenLDAP Server or Microsoft Active Directory).
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
LDAP

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
No audit information available
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
ONLYOFFICE Security Policy is based on the following principles:
ONLYOFFICE Enterprise Edition is self hosted and completely independent.
Authentication filtering and monitoring tools are implemented to give the customers control over their portal activity.
The solutions are built with access management and data leak prevention measures.
Regular security testing is made to spot possible vulnerabilities in the new releases and eliminate them within a reasonable time period.
Information security policies and processes
ONLYOFFICE sticks to data minimalism and transparency of all procedures with user data. ONLYOFFICE undergoes regular security testing and provides all necessary information about the status of possible vulnerabilities.

ONLYOFFICE Enterprise Edition is self-hosted. Data security at rest and in transit is warranted by a customer organization.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We run mandatory tests in-house by a QA Department when preparing each version of the software/component to the final release. Upon discovery of any possible bug, we assure the timely fix. This approach includes both proactive and reactive responses.
Vulnerability management type
Undisclosed
Vulnerability management approach
We assess potential threats via a variety of in-house testing activities. The patches are released within a period from 1 working day to one month, depending on the nature of the discovered issues. This class of issues is given a top priority under any circumstances.

The information about potential threats is obtained from both the known practice and routine testing procedures.
Protective monitoring type
Undisclosed
Protective monitoring approach
We offer convenient ways of reporting any potential compromises to assure that the issue is discovered and tackled in a timely manner. ONLYOFFICE does not have access to the activity of the portals, so there is no way to audit the potential compromises directly. We assure immediate response to the issues via communicating through the problem with the technical team of each customer.
Incident management type
Undisclosed
Incident management approach
The existing support system is the main means of directly reporting the incidents to the ONLYOFFICE Professional Services team.

ONLYOFFICE has a pre-defined process for dealing with common issues and the events related to the possible expected behavior.

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Price
£953.53 a licence a year
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
The free 30-day trial is done through a cloud service (no installation). It includes:
- All features except for Control Panel;
- Up to 50 active users;
- Unlimited number of guests;
- 20 GB disk space;
- Technical support and onboarding.
Link to free trial
https://www.onlyoffice.com/saas.aspx

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@onlyoffice.com. Tell them what format you need. It will help if you say what assistive technology you use.