The Complete Enterprise Cloud Platform

Designed for your business needs today and tomorrow, the Tier 3 cloud platform is architected for the enterprise.
We are reliable, secure, robust and global.

Infrastructure as a Service

Virtual private cloud servers for scale and flexibility, along with the unique security, performance, and management companies require in their own data centers.

Cloud Management

The Tier 3 Control Portal allows you to automate daily server admin functions and expert-intensive processes, freeing up IT staff.

Platform as a Service

You can support the transformation to agile development and DevOps. With our enterprise-grade services fabric, you speed innovation to market.

Infrastructure

Tier 3 Infrastructure-as-a-Service (IaaS) offers on-demand provisioning of high-performing virtual machines with any combination of operating system, storage, and memory. Tier 3’s virtual servers rely on fully redundant enterprise-class hardware connected through private high-speed virtual LANs and leverage storage that delivers up to 20,000 IOPS.

Run a Variety of Modern
Operating Systems.

Provision servers that run Windows Server 2012/2008 R2/2003, CentOS 6/5, Debian 6, Red Hat Enterprise Linux 6, and Ubuntu 12/10.

Deploy to Carefully Constructed
Nodes in 9 Global Data Centers.

Each security-audited data center contains “Nodes” that are engineered to include fully redundant enterprise-class hardware from front-end firewalls to storage.

Choose the Memory, CPU, and
Storage for Each Server.

No pre-defined instance sizes here. Choose up to 128GB of RAM, 16 CPU cores and 4 TB of storage for a given virtual machine.

  • Firewalls
    Our nodes contain a series of full-featured firewalls that provide deep packet inspection and routing services.
  • Front End Switches
    These switches carry customer-facing traffic that occurs when customers access their VMs or when VMs access the public Internet.
  • Hypervisor Host Servers
    This expandable set of servers runs the hypervisor and enables the efficient multi-tenancy of a Foundational Node.
  • Back End Switches
    These high-performing switches are dedicated to traffic among servers and are optimized for transferring large amounts of data quickly.
  • Storage Systems
    Each node has a robust SAN storage system that leverages both SATA and SSD drives for optimal performance and reliability.
  • Management and Monitoring Servers
    There are dedicated servers for networking and usage monitoring, terminal services access and platform management.
  • Backup and Replication Servers
    High availability is a core part of the Tier 3 cloud offering, and we dedicate specific resources to capturing regular backups and replicating data to remote data centers.

High Performance

Run your application on a cloud platform built with enterprise-class hardware all the way from the firewalls to the virtual machine host servers. High-speed 10GB networking between application tiers prevents bottlenecks and hybrid SAN/spindle disks deliver a minimum of 2,500 IOPS and up to 20,000 IOPS.

  • New hardware, top performance.
    Each Tier 3 data center Node is made up of best-in-class, enterprise-grade hardware.
  • 70% max allocation to accommodate spikes.
    Each virtual machine host server is closely monitored to ensure that CPU and RAM never surpass 50-70% utilization to allow for enough headroom for spikes at peak traffic.
  • High speed networking throughout.
    Network speed between application tiers will never be an issue as we deliver up to 10Gbps per vNIC, employ load balancers that deliver up to 1Gbps, and leverage firewalls that delivery up to 6Gbps.
  • Low-latency, high-throughput storage.
    For all Tier 3 storage options, the I/O throughput will reach 6 Gbps, latency is less than 5ms, and storage performance has a maximum IOPS of 20,000.

Compliance

Cloud platform engineered to meet rigorous compliance standards. This includes role-based administration, the use of hardware with no removable media, support for data encryption in transit and at rest, destruction of data on failed drives, and hardware housed in secured physical cages (including ceiling).

  • Every data center is audited regularly.
    Our global data centers are SSAE 16 audited and available for customer audits upon request.
  • Data deletion on discarded drives.
    We protect your sensitive information through policies and procedures to wipe undamaged drives prior to discarding them.
  • Automatic data replication only to in-country data centers.
    Data replication is a critical part of a working disaster recovery strategy, and we only ship data backups to data centers within the same country.
  • Role-based system access.
    Users of the Tier 3 cloud are aligned with specific roles (e.g. Account Administrator, Server Administrator) that govern what they can do in the system, and more granular permissions can be added to individual server groups.
  • System and user audit logs.
    All activities against cloud servers are logged and stored indefinitely. This ensures that you can quickly identify who has performed what actions in the cloud.
  • Physical Security
    Tier 3 data centers enforce strict controls to secure access to the physical hardware. This includes fully-secured server cages and 24/7 monitoring.

Security

Cloud services built with an overarching focus on security and the defense-in-depth approach tackles platform security from multiple angles. From isolated customer VLANs to role-based access, the Tier 3 cloud platform is engineered to aggressively ward off unscrupulous traffic while enforcing a “least privilege” policy for its users.

  • Separation of physical assets.
    Servers in the Tier 3 cloud are assigned to specific roles (e.g. terminal access, backup storage) in order to reduce the attack surface and require each server to run with the fewest possible OS services and open ports. Customers have no access to physical hardware or hypervisor layer.
  • Zone-based firewalls.
    Creates customer-specific VLANs that don’t permit traffic to flow between networks (except if specifically authorized by the account holder).
  • VPN-only access to servers.
    By default, no Tier 3 server gets connected to the Internet, unless public ports are explicitly opened by the customer. Each customer uses a certificate-based VPN connection to securely log into cloud servers.
  • Role-based system access.
    Users are assigned area roles (such as “account” or “server”), resource type permissions (e.g. “blueprints”), and permissions to individual servers and groups. This lets customers assign users a minimal, but functional, set of permissions.
  • Robust network security controls.
    Intrusion Detection Systems (IDS) and Intrusion Detection and Prevention (IDP) are provided through our enterprise-class Juniper SRX firewall hardware. These products protect customer environments from harm using detection and prevention features (also called “screens”). These screens focus on specific - and common – types of attack traffic. For a complete list of screens deployed, visit this list from Juniper.net. In very unique and specific cases, deep content inspection services are available upon request. Read this KB article for more details on our capabilities in this area.

Network

The cutting-edge Tier 3 network relies on an ISP-neutral Internet connection and enterprise-grade Juniper SRX hardware to reliability deliver safe traffic to virtual machines. Customers integrate with the Tier 3 network through VPN tunnels and intra-data center direct connect.

Network Architecture

The network is engineered to be highly available, secure, and fast.

  • Multi-backbone peering
    Our ISP-neutral Internet connection provides high availability in the case of downtime for a given provider.
  • Carrier-class Juniper SRX hardware
    Tier 3 data centers rely on best-in-class, fully-redundant hardware for firewalls and switches on the perimeter as well as between customers/subnets. Interconnects within the data center use 100% 10GB networking.
  • Site-to-site VPN
    Data centers are connected through a site-to-site VPN that encrypts the data as it passes among any of our 10 global locations.
  • Secure and segregated networks
    Each customer gets their own VLAN(s) and an unlimited number of private subnets to further define security zones.

Customer Network Integration

The Tier 3 cloud should be a logical and physical extension of your own data center. Multiple options exist for connecting on-premises assets to the Tier 3 cloud.

  • Site to Site VPN
    Set up a secure IPSec point-to-point VPN tunnels or MPLS VPN tunnels between networks.
  • Client VPN
    Connect to the Tier 3 cloud from a client machine through software like OpenVPN.
  • Intra Data Center Direct Connect
    Using a Tier 3 co-location partner for your own data center? Connect to Tier 3 assets using Single Mode Fiber (SMF, 1310nm) 1Gbps (1000base-LX) or 10Gbps (10G-LR) fiber. Also use 1 Gbps copper if the cross connect is less than 100m in length.

Traffic Management

The network contains robust network traffic management technology as well as self-service firewall policies.

  • Built in IDP/IDS
    The Juniper SRX firewalls deployed in our global data centers provide intrusion detection services and protection by screening incoming traffic for potential attacks. A complete list of screens deployed is listed on Juniper.net. Read this KB article for more details.
  • Pervasive Load Balancing
    Web application load balancing with SSL offloading uses Citrix Netscaler.

Orchestration

Blueprints

Blueprints provide a way to model complex server environments and save those models as templates that can be used again and again. Learn more about Blueprints.

Growing Library of Existing Best Practices

Platform engineers and customers have offered best practice Blueprints that describe how to build multi-server environments to support Microsoft Exchange, Microsoft SharePoint, Basho Riak, and more.

Design Blueprints in multi-step wizard

Add servers and software to Blueprints. Configure servers with Tier 3-provided or user-uploaded software packages. Add Blueprint tasks including adding a public IP address to a server, installing SQL Server, joining an Active Directory domain, adding storage disks, and more. Also invoke one Blueprint from another to allow for highly modularized templates that can be easily reused.

Clone Existing Blueprints

Blueprints can be modified or copied entirely by users to meet specific needs.

Parallelized Build Engine Blueprint Deployments

Deploying a Blueprint involves adding its tasks to a build queue that is monitored by the highly parallelized build engine. View detailed build logs and have the option of resuming failed Blueprints from their offending step.

Software & Script Packages

System stores software and scripts for users to incorporate into Blueprints.

Browse a Library of Scripts & Software

Browse built-in Scripts and Software, or customer-specific. View and search across scripts and software that Tier 3 provides or that customers upload themselves.

Upload New Software and Scripts

Use FTP or web-based upload tool to share metadata and script/software to be included in customer library. Metadata describes supported operating systems, permissions, and parameters that are populated when deploying this script or software as part of a Blueprint.

Manage Package Lifecycle

Put uploaded packages into published or unpublished state and view packages that are awaiting Tier 3 approval.

Management

Platform engineered to surface significant management capability to customers. This includes the ability to orchestrate complex server environments with Blueprints, manage customer accounts, and programmatically administer the platform through an expansive API.

Account Management

Use parent and child accounts to define distinctive business units with an organization and detailed billing system to see both overall and specific charges. Add users to accounts and assign them specific Area (Account/Server) and Resource (blueprints/storage/group/server) permissions.

Sub-Accounts

Account holders may create sub-accounts which can be billed and managed separately from the parent. Blueprints are designed with a setting to allow “private shared” privacy which means that sub-accounts can see the Blueprints of a parent account.

Billing System

View detailed billing history for each account and sub-account. Within each invoice, see charges for Groups, Servers, storage, VPN, network bandwidth, external IP addresses, and more.

Single Sign-On (SSO)

Single Sign-On (SSO) is provided between a customer’s Identity Provider (IdP) and the Tier 3 Control Portal. Tier 3 supports service-provider-initiated SSO via SAML authentication. Customers access a specific URL that initiates a redirect to the customer’s IdP. The IdP authenticates the user and securely sends the authentication details to the Control Portal where the user is logged in without providing Tier 3-specific credentials.

Group Management

Deeply integrated group management. Use inherited settings to create and manage a practical structure for your cloud servers.

Group Monitoring

Create and customize monitors for CPU, Bandwidth, Disk, Memory, Drive, and PING. Additional monitors supported by contacting the Tier 3 NOC.

Group Power Actions

Power on, power off, reboot, pause, reset, and shutdown any or all servers in a group with a single command.

Group Software & Script Execution

Install a software package from the public or private library, or execute a script against the group’s servers.

Group Capacity and Server Defaults

Set the operating system, memory, CPU, and storage preference for any new servers in a group. Configure the maximum capacity that can be provisioned for a group.

Infrastructure Management

Aggressively using automation on cloud infrastructure is a way to ensure a safe, high-performing environment. Comprehensive self-service portal empowers users to intricately or broadly manage server groups, define sophisticated firewall policies, craft multi-tier environment templates, and closely monitor usage and performance.

Role-Based Access Policies

Accounts may contain a variety of users and the Tier 3 cloud platform encourages segmentation based on necessary permissions. All activities within the platform are checked against the active user’s area (i.e. “Server Administrator” or “Account Administrator”), resource type permissions (e.g. “Blueprints”, “Server”, “Cloud Storage”, “Group”, “Invoices”), and individual resource permissions. Only if the aggregate of their permissions allows access to a particular action will the platform allow it.

Robust Monitoring & Reporting

Define or inherit server monitors of interest and thresholds for alert. Default monitors include PING, CPU, memory, disk storage, secondary drive storage, and bandwidth. Include additional monitors by contacting the Tier 3 NOC. Monitoring is also provided through a partnership with thought-leader New Relic. Web Fabric users get a free New Relic account for web application monitoring, and Tier 3 infrastructure users can install New Relic agents on servers and apply their licenses to the cloud environment.

Access and Activity Logs Kept Forever

Platform records user access and activities in log files. All actions performed through the Control Portal – such as server provisioning, server reboot, blueprint deployment – are auditable.

Regular Patching

Tier 3 customers who use Microsoft Windows see automatic server patching at least twice per month. Customers can request specific release windows by contacting the Tier 3 NOC.

Run Repeatable Tasks on a Schedule

Scheduled tasks let users choose a time, frequency, and expiration date for a power command (“Pause”, “Power On”, “Reboot”, “Shutdown”) against a server or group of servers.

Self-service Networking

Create additional VLANs and define firewall rules. Firewall rules are created between VLANs and comprise a source IP address range, destination IP address range, and a list of ports to open.

API

Manage your cloud from afar through an industry-leading API offering. Manage servers, deploy blueprints, create accounts, view invoices, add a public IP address, and much more through a SOAP and HTTP API that supports both XML and JSON for all operations.

  • Provision and Administer Servers

    The API includes all of the operations necessary to create, modify, delete, snapshot, archive, restore, and issue power commands against a server.

  • Manage Server Groups

    Create, archive, delete, and issue power commands against groups of servers.

  • Deploy Complex Environments

    Use the API to retrieve and publish blueprints that make up self-contained server environments.

  • Read Network Details and Manage Public IP Addresses

    Get the details of a network including the gateway, network mask, list of IP addresses and host data center. Add or release a public IP.

  • Manage your Tier 3 Account(s) and Users

    Create, update, suspend, and delete accounts in the Tier 3 cloud platform. Also create, update, suspend, and delete individual users within an account.

  • Review Detailed Billing Information

    Lookup current server/group charges, estimated monthly charges, past invoices, and more in this easy-to-use billing API.

Services

Web Fabric

Use the Tier 3 Platform-as-a-Service (PaaS), Web Fabric, to host web applications to a dedicated environment optimized for .NET, Java, Ruby, Node.js, PHP and Python applications. Deploy applications in seconds to a Cloud Foundry-based PaaS that automatically takes care of load balancing, runtime updates, and infrastructure maintenance.

logos

Unlimited Options

Web Fabric supports many frameworks and services — choose the right technologies for your apps, including Spring, Ruby on Rails, and Node.js.

new relic

Part of the Complete Enterprise Cloud

Apps powered by Web Fabric are reliable and secure because they run on the Tier 3 cloud infrastructure.

graphic for features

Your Own Dedicated Stack

Web Fabric gives you your own, dedicated stack, thereby fulfilling common enterprise security and compliance requirements. You get your own secure, isolated environment, encapsulated in a private VLAN.

Open

Based on Cloud Foundry and the .NET-friendly fork called Iron Foundry. Cloud Foundry Core compatible, which means that you can confidently migrate applications from any other Cloud Foundry provider.

Multi-language Support

For ASP.NET, .NET, Python, Java, Ruby, PHP, Node.js, and Erlang.

Services Compatibility

Application services for MongoDB, NoSQL, Microsoft SQL, MySQL, Neo4j, PostgresSQL, RabbitMQ, and Redis.

Built-in Performance Monitoring

Automatically manages capacity provisioning and load balancing as well as application performance monitoring from New Relic.

Tailored

May be deployed in public, private, or hybrid environments.

Enterprise Grade

Enterprise-grade capabilities, with native support for high availability, high performance, and disaster recovery. Built and optimized for Tier 3’s enterprise cloud infrastructure.

Secure, Isolated Environment

Runs in a secure, isolated environment. Private VLANs ensure no risk of “shared” access from other customers, and support direct integration with other apps.

Portable

Supports applications deployed on your data centers, as well as those deployed on the Tier 3 cloud platform.

Tier 3 Considered "Visionary"

Tier 3 has been positioned by Gartner, Inc. as a Visionary in the 2012 Magic Quadrant for Public Cloud Infrastructure as a Service.

Get the Report

Customer Success Stories

We’ve helped businesses like yours be more successful in the cloud.



View Success Stories

Get a Quote

Ready to talk pricing? Tell us about your project, and let our cloud experts put a proposal together for you.


Request a Quote