Last updated: 23 July 2026. View change log.
This Schedule is part of the Cloud Master Services Agreement between you and Cultrix Limited (“Cultrix”, “we”, “us”). It describes the scope, responsibilities and limits relating to Platform and Infrastructure.
It explains what we look after at the platform and data centre layer, what you control, and any important technical boundaries or limits.
1. Overview of the Cloud Platform
- The Cloud Platform is made up of:
- data centre facilities (power, cooling, physical security, connectivity);
- host servers and hypervisors (the virtualisation layer);
- shared or dedicated storage and, where applicable, local storage on host servers;
- core switching, routing and firewalls;
- remote access and management tools; and
- supporting services such as monitoring, alerting and backup infrastructure.
- We may deliver the Cloud Platform entirely ourselves, or through a combination of us and one or more upstream data centre or cloud infrastructure providers.
- We remain your primary point of contact for all in-scope Cloud Services delivered on the Cloud Platform.
2. Data centre and hosting environment
- We host the Cloud Platform in professionally managed data centres that provide:
- restricted physical access controls (for example access cards, biometric readers, visitor logging);
- redundant power feeds and UPS/generator backup;
- environmental controls (cooling, fire detection and suppression);
- 24/7 monitoring and security presence; and
- multiple network connections to upstream providers.
- Where we use a third-party data centre or cloud provider, that provider’s own standards govern the detailed design and tier level of the facility. We take reasonable steps to choose providers whose services suit small and medium-sized business workloads.
- We do not guarantee that your workloads will run in a specific data centre, region or facility unless your Order says so explicitly.
3. Host servers, virtualisation and storage
- We run host servers with supported hypervisors (for example VMware, Hyper-V or similar technologies) and provide virtualised compute resources (CPU and memory) to your virtual machines and remote desktop servers.
- We provide shared or dedicated storage platforms (for example SAN, NAS or virtual SAN), or local storage on host servers, as appropriate for the service.
- We:
- monitor host health, capacity and basic performance;
- apply vendor-recommended firmware and hypervisor updates during maintenance windows;
- manage resource allocation policies across the platform; and
- take reasonable steps to avoid resource contention between customers.
- Your Order or the Service Schedules define the resource allocation (for example vCPU, RAM and storage) for your workloads. We may use industry-standard techniques such as over-commit and resource pooling, provided we keep performance at a level suitable for the agreed workloads.
4. Networking and internet connectivity
- The Cloud Platform includes:
- internal switching and routing between hosts, storage and management networks;
- perimeter firewalls and, where applicable, VPN end-points;
- public IP address allocation and NAT where needed; and
- shared internet connectivity to external networks.
- We:
- design and maintain core network addressing, routing and firewall rules for the platform;
- put in place standard security baselines for inbound and outbound network traffic;
- apply changes in line with agreed change processes; and
- monitor core network availability and respond to alerts.
- Bandwidth is normally shared between customers unless you buy dedicated connectivity or a private link for your environment. We may apply reasonable traffic management or rate limiting to protect the platform from abuse or to keep it stable for all customers.
5. Firewalls and perimeter security
- We run perimeter firewalls to protect the Cloud Platform from unauthorised access. These may include:
- stateful packet inspection;
- access-control lists (ACLs) and security zones;
- VPN termination for site-to-site or remote-access VPNs where purchased; and
- basic intrusion-prevention or reputation-based blocking.
- We design and maintain the standard firewall rules. We will put in place custom rules for your workloads (for example publishing specific services to the internet, or exposing internal ports over VPN) on request, subject to security review.
- You:
- are responsible for any application-level access controls behind the firewall (for example authentication on web applications);
- must not attempt to bypass or weaken firewall controls; and
- must tell us promptly if you become aware of suspicious traffic or access patterns.
6. Monitoring, alerting and incident response
- We monitor key parts of the Cloud Platform during our standard monitoring window, including:
- host and storage availability;
- platform CPU, memory and storage utilisation;
- core network and firewall status; and
- backup infrastructure health.
- Where monitoring identifies a platform-level issue affecting your Cloud Services, we will:
- log an internal incident ticket;
- begin investigation and remediation in line with the priorities and targets in the SLA (Annex A); and
- keep you updated on significant incidents that affect your services.
- Monitoring of individual virtual machines (for example CPU spikes or disk usage inside the guest OS) is covered in other Schedules if you buy those services.
7. Platform maintenance and changes
- We carry out planned maintenance on the Cloud Platform from time to time, including:
- hypervisor and firmware updates;
- storage platform updates;
- firewall and network device updates; and
- capacity upgrades or restructuring work.
- Where maintenance is likely to affect your service, we will:
- schedule it outside Business Hours where reasonably practical; and
- give reasonable notice, unless the work is urgent for security or stability reasons.
- We may make emergency changes without prior notice if they are needed to address a critical security or stability risk. If you are affected, we will tell you as soon as reasonably possible afterwards.
8. Customer responsibilities at the platform layer
- You must:
- avoid making unplanned or unsupported changes directly to the Cloud Platform (for example host or hypervisor settings, storage configuration or firewall rules), unless we agree it explicitly;
- tell us about significant planned events that may affect platform load (for example large user onboarding, major application go-lives or batch processing runs); and
- follow any platform-related guidance we issue (for example supported operating system versions, reserved IP ranges or naming standards).
- If you, or a third party acting on your behalf, make changes to the Cloud Platform without our knowledge, and those changes cause instability or security issues, we may need to carry out remedial work on a time-and-materials basis to bring the environment back into a supported state.
9. Exclusions
- This Schedule does not include:
- application development or code changes;
- performance tuning of Customer Applications beyond reasonable platform-level adjustments;
- complex network or security architecture design (for example Zero Trust architectures);
- compliance or certification work (for example ISO, PCI or Cyber Essentials projects); or
- any work listed as out-of-scope or project-only in the Agreement or other Schedules.
- We are not responsible for the operation of the public internet, third-party networks or services outside our reasonable control.