OVHcloud

Disaster Recovery as a Service (DRaaS) for Hosted Private Cloud

Disaster Recovery as a Service (DRaaS) using Zerto combined with Private Cloud/Software-Defined Datacentre, using VMware software suite provides access to a 100% dedicated infrastructure with "Software-Defined" technologies in order to enhance the performance and security of customer’s infrastructure, but also to facilitate infrastructure management
and increase productivity.

Features

  • Fast, automated deployment
  • vSphere as a service (6.7 or higher)
  • Anti-DDoS
  • VMware Enterprise plus licensing
  • On demand compute & storage
  • NSX-V license included
  • On demand (RIPE) Public IP blocks
  • Faulty host replacement within 15 minutes.
  • Host connectivity redundancy
  • 4094 vLANs

Benefits

  • Saves time provisioning hardware & software
  • Enabling SPLA licensing to save administration
  • Free monitoring software (vScope)
  • Free, unmetered private network (vRack)
  • Free, unmetered Ingress & Egress
  • Opex model

Pricing

£29.09 a virtual machine a month

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at publicsector@ovhcloud.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 12

Service ID

5 1 9 9 6 9 2 3 8 9 4 8 8 5 0

Contact

OVHcloud Hiren Parekh
Telephone: 03333700425
Email: publicsector@ovhcloud.com

Service scope

Service constraints
OVHcloud are in control of the management layer. This means there are some limitations for the customer when it comes to vCenter and NSX Controllers/Manager.

Some virtual firewalls that intergrate with vCenter cannot be deployed. However, this is a small minority.
System requirements
OVHcloud SDDC operates based on VMware limits.

User support

Email or online ticketing support
Email or online ticketing
Support response times
***Add detail about basic support***

24x7 incident management is available for customers with enhanced support: Business & Enterprise.

Business: Intial response time to emails: 30 minutes
Enterprise: Initial response time to emails: 15 minutes
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
STANDARD
Standard support is the support that is provided for every customer when they buy from OVHcloud. Online content provided in the form of Guides, FAQ's and a chatbot, provided during business hours. Initial response time: 8 hours.

PREMIUM
For customers who require enhanced support and advice in the deployment and operation of their solutions. Advice and incident management included. Prioritized treatment. Initial response time: 2 hours.

BUSINESS
For companies that have their own commitments, provided is 24/7 access to OVHcloud team of experts. Initial response time: 30 minutes.

ENTERPRISE
Matches BUSINESS support, OVHcloud also provide visibility on their uses and what is coming in future months. Initial response time: 15 minutes.
Support available to third parties
No

Onboarding and offboarding

Getting started
OVHcloud provide online guides, FAQ and OVH community.

Regular OVHcloud acadamies.

Partner Acadamies.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
There is no set method. VMDK file extension is agnostic and not constrained to OVHcloud.

Users may use their own preferred extraction methods.
End-of-contract process
Services cease and hardware is wiped and reprovisioned for usage.

There are no costs or hidden activities.

Using the service

Web browser interface
Yes
Using the web interface
Users may manage their infrastructure through vSphere as a service (VSaaS) interface, which is provided via SSL gateway.

Users may use the ovhcloud website in order to activate and provision Private cloud SDDC, additional hosts, datastores and IP addresses.
Web interface accessibility standard
None or don’t know
How the web interface is accessible
Hrough the private cloud SSL gateway, users are able to manage their private cloud SDDC infrastructure.

OVHcloud have built a plug-in for the vSphere client which allows on demand ordering of hosts and datastores.

Within this plug-in it is also possible to see available public IP address ranges and which of these have been assigned.

Users may access the ovhmanager via the ovhcloud website in order to manage users with some control over granuality.
Web interface accessibility testing
None
API
Yes
What users can and can't do using the API
OVHcloud provides access to the Application Programming Interface (API), which includes all possible actions from the client space (Manager OVH). Based on a RESTful standardized architecture, these interfaces enable: Consult all the services you have subscribed (Private Cloud, vRack, etc.), Interact directly with these services (status, add options, vRack association, etc.), Order new services (calculation resources, public IP, etc.), View its billing information or payment status.

These interfaces can be used through a web interface (https://api.ovh.com) or directly through a web call within the scripts of our clients. The OVHcloud API is available at https://api.ovh.com

OVHcloud APIs are used securely for the web interface via OVHcloud client identifiers and for use in third-party applications/scripts using 3 elements: Application Key, Secret Application, Consumer Key

The Consumer Key determines the application/script permissions.

Each call to APIs is signed and timestamped.

To allow the integration of OVHcloud APIs into software, OVHcloud provides code elements to consume APIs in different programming languages:
Java, Swift, Golang, Python, JSnode, PHP, C#, Crystal.

With OVHcloud's Private Cloud solution, access to the VMware API is provided. This is the vSphere API provided by VMware with the following characteristics: XML/SOAP/WSDL

Documentation on this API is available here:

https://www.vmware.com/support/developer/vc-sdk/
API automation tools
  • Ansible
  • Chef
  • Terraform
  • Puppet
  • Other
Other API automation tools
Private cloud is running VMware API
API documentation
Yes
API documentation formats
HTML
Command line interface
Yes
Command line interface compatibility
Other
Using the command line interface
Using VMware PowerCLI it is possible to connect to the vSphere HTTPS.

There is no set limit on user connectivty, but there will be some limitation on certain commands because the management layer is handled by OVHcloud, the list of commands is too extensive to list but administration of the platform can be peformed by those connecting assuming the correct permissions are in place.

Scaling

Scaling available
Yes
Scaling type
Manual
Independence of resources
OVHcloud SDDC is based upon dedicated physical hosts, meaning there is no CPU or RAM contention.
Usage notifications
No

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • CPU
  • Disk
  • Memory
  • Network
Reporting types
  • API access
  • Real-time dashboards

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v3.0
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Physical access control, complying with another standard
Data sanitisation process
Yes
Data sanitisation type
  • Deleted data can’t be directly accessed
  • Hardware containing data is completely destroyed
Equipment disposal approach
In-house destruction process

Backup and recovery

Backup and recovery
Yes
What’s backed up
Virtual Machines
Backup controls
Using a single pane manager, it is possible to enable Backup for Virtual Machines.

There are three backup options per SDDC, STANDARD, ADVANCED & PREMIUM.

Price is per Virtual Machine based on its disk provisioned size. STANDARD provides 14 resport points (2 of which are full backups). ADVANCED and PREMIUM offer 35 restore points (of which 5 are full backups). Premium offer also provides long term retention.

Behind the scenes, data is replicated to two OVHcloud datacentres.
Datacentre setup
  • Multiple datacentres with disaster recovery
  • Multiple datacentres
  • Single datacentre with multiple copies
  • Single datacentre
Scheduling backups
Users schedule backups through a web interface
Backup recovery
Users can recover backups themselves, for example through a web interface

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Bonded fibre optic connections
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Service Component Availability Commitment:
- Host Server : 99,99% : Replacement of defective Host Server within 15 minutes. If it cannot be replaced within 15 minutes, 100% of the price paid by the Customer for the Host Server will be reimbursed.
- Storage Space : 100% : Reimbursement of 5% of the price paid by the Customer for the Storage Space per ten-minute period of unavailability, up to 100% of the price paid by the Customer in respect of the Storage Space in any month.
- Network : 100% : Reimbursement of 5% of the total monthly invoice price per ten-minute period of unavailability, up to 100% of the amount of the monthly invoice.
-Connectivity : 99,95% : Reimbursement of 5% of the total amount of the next monthly invoice per hour of unavailability, up to 100% of the amount of that invoice.
-Virtualisation Interface : 99,9% : Reimbursement of 10% of the price of the infrastructure management pack per hour of unavailability, up to 100% of the price paid by the Customer for the infrastructure management pack.
Approach to resilience
OVHcloud has implemented redundancy mechanisms to ensure compliance with regulatory, statutory and contractual obligations. OVHcloud maintains a framework that is consistent with industry best practices for the Business Continuity and Disaster Recovery Program at all levels.

OVHcloud provides customers multiple datacenters for Geo redundancy, system functionality allows customers to capture and restore virtual machine images at any time to support their resiliency needs.

ESXi hosts have RAID configured for disk redunancy, ESXi host Network cards are configured in pairs for redundancy. vCenter backups are taken daily. Datacentres are stocked with replacement parts and have a repair workshop. Systematic dual power supply: Every datacentre is supplied by two separate power sources. In the event of failure, generators are on standby to take over. Datacentres have a minimum of 2 incoming network feeds; inside, 2 twin network rooms which can take over from one another.
Outage reporting
OVHcloud provide different levels of services with specific means of communication to customers.
At a basic level, Communication with OVHcloud is through Customer Advocate, who is the unique point of contact with customers.
-Customers open tickets to get assistance.
-Incident or Event communication : Website http://travaux.ovh.com is communication canal used for our customers

In case of the subscription to the Professional Services support, communication with OVHcloud is through Technical Account Manager (direct call /mail).

Identity and authentication

User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
OVH access control policy based on the principles of least privilege and segregation of duties. Customer solutions reside on their own dedicated VLAN.
Implement role-based access controls and require authorized users privileges via group membership. Administration access is managed through Bastions Servers with limited access to the specific IP address ranges.
A regular review of access is carried out as part of the monitoring and review activities implemented by OVH.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Dedicated link (for example VPN)
  • Username or password
Devices users manage the service through
  • Dedicated device on a segregated network (providers own provision)
  • Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
KPMG Audit plc
ISO/IEC 27001 accreditation date
08/11/2019
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2007 certification
No
CSA STAR certification
Yes
CSA STAR accreditation date
05/06/2018
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
N/A
PCI certification
Yes
Who accredited the PCI DSS certification
XMCO
PCI DSS accreditation date
04/04/2019
What the PCI DSS doesn’t cover
N/A
Other security certifications
Yes
Any other security certifications
  • ISO 27017
  • ISO 27018
  • SOC 1 (SSAE18/ISAE 3402)
  • SOC 2
  • CISPE code of conduct

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
OVHcloud management put in place an (ISMS) Information Security Management System according to ISO 27001: 2013. Policies and processes are documented and available via intranet to the employees.

The scope of the Information Security Management System covers providing and operating OVHcloud's Private cloud computing infrastructure.
The Information Security Management System includes all the following processes: host and datastore management, maintenance, customer virtual machine environment, core business scripts, availability indicators, sales offers and virtual machine backup.

On an annual basis OVHcloud is auditec by third-party auditors, to obtain an independent attestation of compliance with our policies and procedures for ISO 27001:2013 & ISO27017, SOC1 & SOC2 Type II, and OVHcloud Healthcare.

Operational security

Configuration and change management standard
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach
Changes in the servers, including applications are managed with the Technical analysis method and in dedicated environments. Security is an integral part of this method from the start and throughout the project life cycle.
We create a technical analysis when:
-if the network architecture changes permanently ;
-if the flow diagrams changes permanently ;
-If you add / remove a feature (server, network equipment);
-if modified, create a new organizational process.
Vulnerability management type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach
OVH has set up a monitoring process for managing vulnerabilities, analyzing, evaluating exposure to these vulnerabilities, documented and take appropriate measures to cover the associated risks.
OVH complies with ISO 27002 to ensure good information security management practices and ISO 27005 standards for risk assessment and risk handling.
The vulnerability scans are performed periodically by an approved entity.
Protective monitoring type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach
The OVH SOC (Security Operations center) team monitors 24/7 the security issues (suspicious and unusual activities) and triggers the protection procedures.
Several monitoring mechanisms are in place depending on service level and segment. Customer is notify depending on the nature of the problem.
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
An incident escalation process is implemented, to facilitate a response to security events which includes identification, analysis (scope and impact ), solutions, and lessons learned in alignment With ISO 27001 standard.
- Formal procedures are implemented for feedback and reporting of events related to information security.
- OVH notifies the appropriate parties to remediate any identified vulnerabilities.
- A knowledge base of incidents is fed to limit a new occurrence of the incident.
-Security events and incidents are reviewed by the risk manager to update the risk assessment.

Secure development

Approach to secure software development best practice
Supplier-defined process

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Supplier
Virtualisation technologies used
VMware
How shared infrastructure is kept separate
The network layer is shared between our customers. A segmentation of customer infrastructures is realized through our "vRack" solution enabling our customers to interconnect Level 2 machines across our backbone in a secure manner.

Energy efficiency

Energy-efficient datacentres
Yes
Description of energy efficient datacentres
OVHcloud is a responsible global hyperscale cloud provider, which is highly committed to energy efficiency as part of environmentally sustainable digital services. With a vertically-integrated value chain, OVHcloud manufactures its servers, and designs its own datacentres. This enables maximum efficiencies and inclusion of ongoing innovations, able to achieve a leading Power Usage Effectiveness (PUE) ratio of 1.09.

OVHcloud has pioneered water cooling systems for greener technology since 2003, and since 2013 our energy procurement policy has focussed only on green power and 100% renewable energy sources. Water Usage Effectiveness is extremely low (~0.29) because the cooling technology is based on closed loops using very little water. And carbon footprint is 50g CO2/MWh. Continuity planning is considered in the design, monitoring and management of datacentres using added isolation and backup energy systems.

Through designing our data centres to run without air conditioning and recycling our components for secondary markets to prolong their life cycles we maintain an environmentally friendly approach in all our design, manufacturing and operational processes. In recognition of this Francois Sterin, OVHcloud Chief Insdustrial Officer, was named in The Data Economy Climate 50, a list of the world’s most influential climate sustainability leaders in data centres and cloud.

Pricing

Price
£29.09 a virtual machine a month
Discount for educational organisations
No
Free trial available
Yes
Description of free trial
SDDC Private cloud PREMIER 64 comprising 2x hosts each with 64Gb RAM and 12 cores.

2 x 2TB datastores.
10Gbps Internet.
Anti-DDoS.
Private Network vRack with 4000 vLAN.
VMware Enterprise Plus SDDC vCenter vSphere 6.7.
Software Defined Network NSX.
vRealize Operations

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at publicsector@ovhcloud.com. Tell them what format you need. It will help if you say what assistive technology you use.