The implementation process for Aqua typically involves several key steps:
Assessment and Planning: This initial stage includes assessing the existing infrastructure and determining the security needs specific to the organization. This may involve meetings with stakeholders to align Aqua’s features with business objectives.
Installation and Configuration: Aqua can be installed on-premises or in the cloud. The installation process involves setting up the Aqua platform, which includes configuring the necessary components such as the Aqua server, database, and integration with CI/CD tools. Configuration is tailored to the organization's specific workflows and security policies.
Integration: Aqua integrates with popular CI/CD pipelines and orchestration platforms like Jenkins, GitLab, Docker, and Kubernetes. During this phase, the integration is configured to ensure automated vulnerability scanning and security checks are seamlessly embedded into the existing development processes.
Training and Onboarding: Aqua provides training sessions for users and administrators to ensure they can effectively utilize the platform’s features. This may include training on security best practices, use of the user interface, and understanding the reporting functionalities.
Testing and Go-Live: After configuration and training, the system undergoes testing to verify that all integrations and features are functioning as intended. Once tested, Aqua is fully deployed, and teams can start utilizing it for securing their applications.
Customisation
Aqua offers various customization options to fit specific business needs. Key areas of customization include:
Policy Enforcement: Organizations can create tailored security policies that align with their compliance requirements, such as GDPR, HIPAA, or industry-specific standards.
Integration Flexibility: Users can customize workflows to integrate Aqua with other tools in their development ecosystem, allowing for tailored security checks and balances.
User Roles and Permissions: The platform allows customization of user roles, ensuring that different team members have appropriate access to features and data based on their responsibilities.
Dashboards and Reporting: Organizations can customize dashboards to display metrics and alerts that are most relevant to their security posture and operational needs.
Additional Costs
Setup Fees: Some organizations may incur setup fees, especially for on-premises installations or if advanced custom configurations are required. These fees vary based on the complexity of the deployment.
Maintenance Costs: Ongoing maintenance is typically included in the subscription, but organizations may have to budget for additional services related to updates or enhancements beyond standard maintenance.
Support Charges: Aqua usually offers tiered support packages. Basic support is often included with the subscription; however, organizations requiring advanced support or dedicated account management may incur additional charges.
Training Costs: While Aqua provides initial training, ongoing training sessions or educational resources for new team members may require additional investment.
Training
Aqua offers comprehensive training and support for new users to ensure they can effectively leverage the platform's capabilities. Key components include:
Onboarding Sessions: New customers often receive onboarding sessions that introduce them to Aqua's features, interface, and best practices for implementation.
Documentation and Resources: Aqua provides extensive online documentation, including user manuals, quick-start guides, and FAQs, which are accessible through their knowledge base. Webinars and tutorial videos are also available to guide users through various functionalities.
Technical Support: Aqua offers tiered support plans, including initial support as part of the subscription. For critical or complex issues, premium support packages are available, providing quicker response times and dedicated account management.
Customized Training: Organizations can request tailored training sessions for specific teams or use cases, helping users fully understand how to implement security across their development pipelines.
Security Measures
Aqua employs several security measures to safeguard data within its platform, including:
Encryption: Data is encrypted both in transit and at rest, ensuring that sensitive information is protected from unauthorized access or breaches.
Access Controls: Role-based access controls (RBAC) allow organizations to define permissions based on user roles, ensuring that only authorized personnel can access specific data or functionalities.
Regular Audits: Aqua conducts regular security audits and assessments to identify and address potential vulnerabilities within the platform.
Compliance Standards: Aqua adheres to various industry compliance standards, such as GDPR, HIPAA, and ISO 27001, further enhancing its security framework.
Updates
Aqua typically releases updates regularly to enhance features, improve security, and fix bugs. The frequency of these updates can vary but is generally aligned with industry standards. Major updates are usually rolled out quarterly or biannually, while minor updates and patches may occur more frequently as needed.
These updates are managed through a streamlined process that minimizes downtime for users. Customers are notified of upcoming updates in advance, allowing them to prepare for any changes that may affect their environment. Aqua provides detailed release notes to inform users of new features, enhancements, and any issues resolved.
Data Ownership and Portability
Aqua maintains a clear policy regarding data ownership and portability. Organizations retain full ownership of their data, meaning that any data processed or stored by Aqua remains the property of the client. Aqua does not access, share, or sell customer data without explicit consent, ensuring privacy and compliance with data protection regulations.
In terms of portability, Aqua facilitates data export capabilities, allowing organizations to extract their data easily if they choose to migrate away from the platform. This process helps ensure that users have control over their data and can transition to other solutions without losing valuable information.
Scaling Up / Down
Aqua provides flexible terms for scaling its services up or down based on organizational needs. Key aspects include:
Modular Licensing: Organizations can adjust their subscription based on the number of hosts, containers, or applications they need to secure. This modular approach allows businesses to scale their usage according to their evolving requirements without undergoing a complete re-negotiation of contracts.
Adjustable Tiers: Aqua typically offers various pricing tiers that cater to different levels of usage. Organizations can move between these tiers, allowing for scalability that aligns with business growth or contraction.
Notification Period: Customers are usually required to provide a notice period when scaling down their services to prevent any unexpected charges. This period can vary but is typically around 30 to 60 days.
Usage-Based Pricing: In many cases, Aqua employs usage-based pricing models, allowing customers to pay for only what they use. This means organizations can scale down without incurring fixed costs that are typical of flat-rate models.
The terms & conditions for contract renewal and cancellation
Aqua's terms for contract renewal and cancellation generally include the following:
Contract Duration: Typically, Aqua contracts are annual and auto-renew unless the customer specifies otherwise. Organizations should review their contracts for specific terms regarding renewal.
Notice Period for Renewal: Customers are often required to give written notice (usually 30 to 90 days) prior to the end of the contract if they do not wish to renew. This allows Aqua to prepare accordingly and gives customers time to evaluate their needs.
Cancellation Terms: To cancel a contract, organizations typically must provide written notice, which may also require a designated notice period (usually 30 days). Some conditions might apply regarding any prepaid fees or obligations.
Refund Policy: Aqua's policy regarding refunds for unused services varies by contract and may not provide refunds for annual fees already paid if cancellation occurs mid-term.
Transition Support: Aqua often offers transition support for organizations that decide to cancel their service, assisting them in exporting their data and migrating to alternative solutions.
Compliance
Aqua meets various compliance standards, which are crucial for organizations operating in regulated industries. These standards include:
GDPR: Aqua complies with the General Data Protection Regulation, ensuring that organizations handling personal data of EU citizens can do so responsibly and lawfully.
HIPAA: For organizations in the healthcare sector, Aqua adheres to the Health Insurance Portability and Accountability Act, which mandates safeguarding sensitive patient data.
PCI DSS: Aqua meets Payment Card Industry Data Security Standard requirements, ensuring that organizations that handle credit card transactions maintain a secure environment.
ISO 27001: Aqua has achieved certification for ISO 27001, demonstrating its commitment to a comprehensive Information Security Management System (ISMS) to protect sensitive information.
NIST Cybersecurity Framework: Aqua aligns with the NIST framework, which provides guidelines for managing and reducing cybersecurity risk.
FedRAMP: For organizations in the U.S. federal government sector, Aqua complies with the Federal Risk and Authorization Management Program, allowing its use in U.S. government cloud environments.