Arcus Global Limited

Arcus CloudCauseway

An award-winning managed service to resolve transport and security issues, route and manage HTTP and HTTPS traffic between private and public networks. It enables organisations to share data securely with internal systems and trusted external systems and platforms to help drive efficiencies and innovation through self-service portals, mobile-enablement, etc.


  • Robust & performant
  • Fully-managed
  • Cloud-enabled connectivity
  • Secure
  • DDoS-resilient solution
  • Securely connect with other internal systems and/or trusted external platforms


  • Employs best practice to keep your services running
  • Removes the overhead of managing multiple connections.
  • Routes traffic over numerous connectivity scenarios using secure proven techniques.
  • Employs best practice to keep your services secure.
  • Single point for managing all connections into your systems
  • Drive efficiencies through self-service portals


£710 per user per month

Service documents

G-Cloud 9


Arcus Global Limited

Karen Humphreys

+44 (0)1223 781254

Service scope

Service scope
Software add-on or extension No
Cloud deployment model Public cloud
Service constraints N/A
System requirements N/A

User support

User support
Email or online ticketing support Email or online ticketing
Support response times Response times depend on how critical the issue / question is: Critical <4 hrs, High <8 hrs, Medium <16 hrs, Low <40 hrs. These are intended for the purpose of guarantees related to Service Credits. The actual response time will generally be much faster.
User can manage status and priority of support tickets Yes
Online ticketing support accessibility None or don’t know
Phone support Yes
Phone support availability 9 to 5 (UK time), Monday to Friday
Web chat support No
Onsite support Onsite support
Support levels Second and third line support is included in the price of the proposal. Telephone Support, Email/Ticket Support (24 / 7 web based support call logging), Remote Access Support and On-site Support. Standard support includes: Perpetual bug-fixes, Software updates to support all legislative changes, Assistance with customisation and reporting.
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started Arcus work closely with the users, shadowing them early on, demoing the product and getting their feedback through User Tests. We will provide in depth training for the Product Owner on reports, templates and other advanced areas, who will then be able to set up training sessions tailored for users.
Service documentation Yes
Documentation formats Other
Other documentation formats N/A
End-of-contract data extraction Data can be extracted by the user or Arcus. If Arcus is commissioned to extract and deliver data, the project must clearly specify how and where data should be extracted, format required, and where it should be delivered. Arcus offers clients a fixed cost solution using published SFIA day rates.
End-of-contract process N/A

Using the service

Using the service
Web browser interface Yes
Supported browsers
  • Internet Explorer 10+
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari 9+
Application to install No
Designed for use on mobile devices Yes
Differences between the mobile and desktop service The salesforce1 app allows for users to access the platform from any mobile device enabling agile working practises to be achieved. The app is downloadable for free from various app stores. Limited off line capabilities are present allowing for data to be cached.
Accessibility standards WCAG 2.0 AA or EN 301 549
Accessibility testing N/A
What users can and can't do using the API N/A
API documentation Yes
API documentation formats Open API (also known as Swagger)
API sandbox or test environment Yes
Customisation available Yes
Description of customisation The Arcus solution enables virtually any kind of data rule to be defined and is customised through the system setup by various tools through the workflow functionality, and via formula fields.


Independence of resources The Arcus solution is built on the Salesforce platform which works to a target time for platform availability of 99.999%, measured 24/7/365. The number of users on this service does not effect it's availability or quality.


Service usage metrics Yes
Metrics types Arcus Software is built on the Salesforce platform and can take advantage of its standard reporting and dashboard functionality. This allows users to build their own individual reports that allow reports of different types to be built. Ranging from real-time snapshots through to yearly summaries.
Reporting types Regular reports


Supplier type Reseller providing extra support
Organisation whose services are being resold Yes - Arcus Software will require Salesforce Licenses

Staff security

Staff security
Staff security clearance Conforms to BS7858:2012
Government security clearance None

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations United Kingdom
User control over data storage and processing locations No
Datacentre security standards Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency At least every 6 months
Penetration testing approach Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Other
Other data at rest protection approach SalesForce are compliant with a number of standards which require protection of data at rest (ISO 27001/27018
SSAE 16/ISAE 3402 SOC-1
TRUSTe Certified Privacy Seal
Data sanitisation process Yes
Data sanitisation type Explicit overwriting of storage before reallocation
Equipment disposal approach Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data importing and exporting
Data export approach N/A
Data export formats CSV
Data import formats CSV

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks TLS (version 1.2 or above)
Data protection within supplier network TLS (version 1.2 or above)

Availability and resilience

Availability and resilience
Guaranteed availability Arcus solution is built upon Salesforce technology. Response times are published: there is guaranteed availability of 99.999% 24/7/365. Historically, Salesforce has had an excellent record of very high uptime. Salesforce have configured all networking components, SSL accelerators, load balancers, Web servers and application servers in a redundant configuration.
Approach to resilience Efficient RTO (Recovery Time Objective) and RPO (Recovery Point Objective) times. runs products from tier-4 data centres. Hosting structure: shared multi-tenant architecture, subdivided into nine hardware clusters called pods; made up of 35 multiprocessor Unix and Linux servers running the Oracle database. Pods are mirrored for high-availability and failover.
Outage reporting Arcus Solution is built on Salesforce platform. Salesforce provide current and historical (the preceding month) data on service availability for each of their instances at Each instance in the EMEA region (EUx) has had zero unscheduled outages, classified as a ‘Service Disruption’, in the last 30 days.

Identity and authentication

Identity and authentication
User authentication needed Yes
User authentication 2-factor authentication
Access restrictions in management interfaces and support channels Valid email is required which becomes the unique username, and a password reset email is sent to this address. This ensures that the email address is valid. User is then required to set a new password with a definable structure complexity - for example uppercase / lowercase plus a number.
Access restriction testing frequency At least once a year
Management access authentication 2-factor authentication

Audit information for users

Audit information for users
Access to user activity audit information Users have access to real-time audit information
How long user audit data is stored for User-defined
Access to supplier activity audit information Users have access to real-time audit information
How long supplier audit data is stored for User-defined
How long system logs are stored for User-defined

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification Yes
Who accredited the ISO/IEC 27001 Socotec
ISO/IEC 27001 accreditation date 19/10/2015
What the ISO/IEC 27001 doesn’t cover N/A
ISO 28000:2007 certification No
CSA STAR certification Yes
CSA STAR accreditation date 14/03/2017
CSA STAR certification level Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover N/A
PCI certification No
Other security accreditations No

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance accreditation No
Security governance approach N/A
Information security policies and processes N/A

Operational security

Operational security
Configuration and change management standard Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach Arcus will maintain a change log of environmental controls and operate releases through our release manager.
Vulnerability management type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach Multiple tiers of vulnerability management. The Product Security team ensures the security of the system, consults with R&D teams and partners, and protects customer data. Cloud Security experts specialise in security research and innovative tool development. A ‘Rapid response’ team reacts to emerging threats as the last line of defence.
Protective monitoring type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach Records all login attempts: originating IP address, time and success/fail against each user account. Information can be extracted for analysis against organisational policies. Configurable settings: enforce logins from an approved IP range and/or at certain times of day, maximum session length and automatic account locking after x failed login attempts.
Incident management type Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach Standard incident management ensures that all recorded incidents are triaged and routed to the appropriate resolver groups and, where necessary, escalated. In specific cases it may be necessary to escalate incidents directly to the provider. We have a standard hand off process to ensure that end-to-end communication is maintained.

Secure development

Secure development
Approach to secure software development best practice Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Public sector networks
Connection to public sector networks No


Price £710 per user per month
Discount for educational organisations No
Free trial available No


Pricing document View uploaded document
Skills Framework for the Information Age rate card View uploaded document
Service definition document View uploaded document
Terms and conditions document View uploaded document
Return to top ↑