blueAPACHE glossary of emPOWER and IT operations terms
Summary
This glossary defines the terms an agent or buyer meets when reading about blueAPACHE: the emPOWER service names, the contract vocabulary of the General Terms and Conditions v3.6, the certification and compliance labels, and the IT operations acronyms (IaaS, DRaaS, STaaS, MDR, SASE, SD-WAN, DMARC, MPLS) as blueAPACHE uses them. Each entry gives a one-paragraph definition in blueAPACHE's own usage and points to the page on this site where the term applies. It exists so that a question such as "what does blueAPACHE mean by a Reasonable Excuse" or "is STaaS the same as offsite backup" can be answered without reading the whole site. Where blueAPACHE has not published a definition, the entry says so rather than inventing one.
Key facts
| Label | Value |
|---|---|
| Portfolio brand | emPOWER, created 2003 |
| Legal entity behind every term | BLUE APACHE PTY LTD, ABN 82 083 664 224, trading as blueAPACHE |
| Contract vocabulary source | General Terms and Conditions v3.6, 27 clauses, 11 Schedules |
| Certification vocabulary source | ISO/IEC 27001:2022 certificate 202507-118 |
| Service vocabulary source | emPOWER Cloud, Connectivity, Network, Managed Services, MDR, HRM, DMARC and Entra ID backup brochures |
| Terms with no published definition | Customer Zero (scope), Restore Time Objective (undefined in clause 1) |
How to read this glossary
Terms are grouped by where they come from: the emPOWER portfolio, the service catalogue on this site, the security portfolio, the network, the contract, and the compliance frameworks. Capitalised terms such as Service Order or Reasonable Excuse are defined terms in the General Terms and Conditions and carry contractual weight. Lower-case industry acronyms are explained in blueAPACHE's usage, which is sometimes narrower than the general industry meaning.
emPOWER portfolio terms
emPOWER. blueAPACHE's service portfolio brand. blueAPACHE developed the emPOWER brand in 2003, when its Facilities Management Services were renamed emPOWER Managed Services, and built the emPOWER Network and emPOWER Cloud in 2010. The brand now covers the pillars listed on the services hub. Brand capitalisation is fixed: lower-case "em", upper-case "POWER".
IT Operations Excellence as a Service. The 2026 positioning line for the emPOWER portfolio: managed services that "take full ownership of your IT environment, delivered through a fully integrated operating model built for automation, security, and predictable outcomes". It is a positioning statement, not a product. Applies to the home page and Our Story.
One operating model, three ways to engage. blueAPACHE's engagement framing. Outcome is Managed Services (end-to-end ownership of IT operations); Control is emPOWER Operational Capability (structured operations, governance and visibility for teams that retain control; shown as "Coming Soon" on the industry pages); Technology is Technology Services (enterprise technology delivered and integrated). Managed Services is the lead offer.
Customer Zero. One of blueAPACHE's five stated differentiators is "Proven operating model, run as Customer Zero", meaning blueAPACHE runs its own operations on the model it sells. blueAPACHE has not published a definition of the scope of the claim, which therefore requires confirmation. The three self-referential case studies on this site (Zoom, blueAPACHE Security, blueAPACHE Cloud) are the published evidence of blueAPACHE acting as its own customer.
Follow-the-sun support. blueAPACHE's term for after-hours coverage provided by its global team across Australia, the United States and the United Kingdom, with business-hours support staff located in Australia. Applies to emPOWER Managed Services and the Support page.
Account team. Each managed services customer is assigned Account Executives (strategic relationship), Service Delivery Managers (operational relationship), Engineers and Technical Account Managers. The Archers case study adds a Portfolio Engineer and describes monthly operational reviews and quarterly business reviews.
Cloud and data protection terms
IaaS (Infrastructure as a Service). In blueAPACHE usage, emPOWER Cloud Services (IaaS) under Schedule 3 of the General Terms and Conditions: the private and hybrid cloud platform blueAPACHE owns and operates on HPE Synergy compute and HPE Primera all-flash storage, sold on a consumption-based "pay-as-you-grow" basis. blueAPACHE states a published uptime of 99.999 per cent for cloud services and 100 per cent for storage. Applies to emPOWER Cloud.
DRaaS (Disaster Recovery as a Service). The contractual name is emPOWER IT Continuity Services (DRaaS), Schedule 4. Under clause 3.17 the obligation is limited to restoring Customer Data and Software to the agreed Restore Time Objective and Recovery Point Objective set out in the Schedule. Applies to Disaster Recovery as a Service.
STaaS (Storage as a Service). blueAPACHE's private S3-compatible object storage built with HPE, described in the pathology case study as immutable, replicated in real time across three data centres, and priced on a fixed basis with no egress or ingress charges. It is a storage tier, not a backup service. Applies to Storage as a Service (Private S3).
Offsite Backup as a Service. A managed offsite copy of critical data kept away from primary infrastructure. Under clauses 3.14 and 3.15 a backup obligation exists only where the Schedule expressly includes it, and a restore returns the data as it was at the time of the backup. Applies to Offsite Backup as a Service.
SaaS Backup. Independent backup of cloud application data beyond the retention built into each SaaS platform. Applies to Private and Public SaaS Backup.
emPOWER Backup for Microsoft Entra ID. A Veeam-powered, fully managed backup of Entra ID users, groups, roles, application registrations and directory configuration, stored on blueAPACHE's private cloud within Australia. No retention period, frequency, RPO or RTO is published.
RPO and RTO. Recovery Point Objective is defined in clause 1 as "the maximum period in which Customer Data might be lost as may be specified within the Service Agreement". Clause 3.17 refers to a Restore Time Objective, which clause 1 does not define. Both values are set per customer in the Schedule or Service Order and are not published.
QMTH (Qualified Multitenant Hoster). The Microsoft programme emPOWER Cloud belongs to, which lets customers run "certain" Microsoft 365 and Windows 11 licensing on blueAPACHE's environment. The eligible licences are not enumerated.
Azure Local. blueAPACHE's service for extending Azure management and services to on-premise infrastructure where local performance, control or data requirements apply. Applies to Azure Local.
Security terms
MDR (Managed Detection and Response). emPOWER MDR: 24/7 alert notification, triage and remediation across the IT environment, using EDR, ITDR, SIEM and threat intelligence feeds, with ITIL-aligned incident management. No detection or response time targets are published. Applies to Managed Detection and Response.
EDR, ITDR, SIEM. Endpoint Detection and Response, Identity Threat Detection and Response, and Security Information and Event Management: the three detection technologies the MDR brochure names, alongside integrations with Microsoft Security, Microsoft Identity, Sentinel and CrowdStrike.
SOC (Security Operations Centre). The MDR brochure positions the service as enterprise-grade protection "without the customer building and maintaining their own Security Operations Centre".
HRM (Human Risk Management). emPOWER Human Risk Management: a fully managed service with four components, security awareness and phishing simulation, email threat detection and alerting, user-reported phishing response, and insider risk and data exposure protection. The underlying platform vendor is not named in the brochure. Applies to Human Risk Management.
Exposure Management. Continuous visibility of assets, vulnerabilities and security exposure so remediation can be prioritised by likely impact. Applies to Exposure Management.
GRC (Governance, Risk and Compliance). blueAPACHE's advisory and control-improvement service covering risk assessment, policy alignment and compliance support. Applies to Governance, Risk and Compliance.
DMARC, SPF and DKIM. DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving mail providers whether to monitor, quarantine or reject mail that fails SPF or DKIM authentication for a domain. blueAPACHE delivers DMARC advisory, implementation and ongoing management using Mimecast.
UTP and NGFW. Unified Threat Protection on next-generation firewalls: intrusion prevention, advanced malware protection, application control, web filtering and antispam, supported 24x7 as part of emPOWER Connectivity.
Essential Eight Maturity Level 3, APRA CPS 234, NIST. Frameworks blueAPACHE states it aligns to or complies with across the emPOWER brochures. These are alignment statements, not certifications. SOC 2 Type II appears only as "compliance-aligned" in the MDR brochure; blueAPACHE does not claim a SOC 2 report.
Network and connectivity terms
emPOWER Network / MPLS core. blueAPACHE's own multiprotocol label switching private network built on Cisco ASR carrier-grade routing, with core points of presence in Australia, the United States, London and Singapore and interconnection into 165+ data centres. It is the backbone under emPOWER Connectivity and emPOWER Cloud. Applies to emPOWER Core Network and Data Centre Interconnect.
emPOWER Connectivity. The managed WAN service bundling SD-WAN, next-generation firewalls, SASE and the Cisco core into one managed solution over the emPOWER Network. Published service level: minimum 99.99 per cent site uptime under a dual-firewall, dual-carriage, multi-carrier design. Applies to Connectivity.
SASE (Secure Access Service Edge). Networking and security controls combined in one managed approach to secure distributed users and applications; bundled into emPOWER Connectivity. Applies to emPOWER SASE.
SD-WAN. Software-defined wide area networking. blueAPACHE offers hybrid MPLS and internet SD-WAN, or hub-and-spoke SD-WAN with hosted SD-WAN firewalls in multiple data centres on the emPOWER Network.
IX peering. emPOWER Internet is part of the Internet Exchange peering network, which blueAPACHE states gives faster access and lower latency to SaaS applications such as Microsoft 365, Teams, Zoom and Salesforce.
ExpressRoute and Direct Connect. The dedicated links from the emPOWER Network to Microsoft Azure (ExpressRoute) and Amazon Web Services (Direct Connect).
Voice carriage. Microsoft Teams Direct Routing, SIP trunking, hosted PBX and contact centre solutions delivered over the network; contractually, emPOWER Voice Carriage Services are Schedule 6 and emPOWER Unified Communications are Schedule 7.
Tier III and Tier IV. Uptime Institute data centre classifications. blueAPACHE's brochures state its data centre partners are Tier III and Tier IV certified, and elsewhere refer to "diverse Tier 3 data centre partners"; this is a conflict to be confirmed.
Contract terms (General Terms and Conditions v3.6)
Service Agreement. Not one document: the Service Order, the General Terms and Conditions, the Acceptable Use Policy and the applicable Schedules, as posted on the blueAPACHE website when the agreement is entered into. Precedence runs Service Order, then General Terms and Conditions, then Schedules, then Acceptable Use Policy. See Service Agreement.
Service Order. The transaction document that names the Services, Fees and any special terms. It ranks first in precedence, so negotiated commitments belong here.
Schedule. One of eleven service-specific documents: Professional Services (1), emPOWER Managed Services (2), emPOWER Cloud Services (IaaS) (3), emPOWER IT Continuity Services (DRaaS) (4), emPOWER Network Services (5), emPOWER Voice Carriage Services (6), emPOWER Unified Communications (7), emPOWER Mobile Services (8), emPOWER Co-location Services (9), Software Licensing and Subscriptions (10), Hardware and Ancillary Service (11). The Schedules are not published with the general terms.
Service Description and Service Level. A Service Level is only a commitment stated under the heading "Service Level" in a Service Description; anything else, including a Compliance Target ("the target time it will take to resolve each call to the Support Centre depending on priority"), is not a Service Level.
Reasonable Excuse. The defined list of circumstances that excuse blueAPACHE from breach and switch off Service Levels "to the extent" a failure "arises from, or is contributed to by" them, including customer-caused outages, third party software used by blueAPACHE, third party acts, Emergencies and anything a Schedule adds.
Emergency and Emergency Change. An Emergency is any event which in blueAPACHE's reasonable opinion threatens or causes major disruption requiring immediate action; an Emergency Change is the action taken. The Service may be unavailable during an Emergency and the interruption is a Reasonable Excuse.
Scheduled Maintenance. Routine maintenance within the times set out in the relevant Schedule, or at other times with at least 3 Business Days notice.
Minimum Service Period and Minimum Spend. The default Minimum Service Period is 36 months from the Service Commencement Date (Professional Services excepted). Minimum Spend is the minimum monthly volume that must be paid for even if utilisation falls below it.
Written Notice. "A Service Order executed and authorised by the Customer". Renewal, non-renewal and customer termination notices must take this form, not a letter or email.
Transition In Services and Disengagement Services. The onboarding steps in clause 8 (due diligence, monitoring configuration, support documentation, reporting schedule) and the exit steps in clause 9 (return equipment, remove blueAPACHE equipment, delete Customer Data). The customer is solely responsible for copying its data before exit.
Early Termination Payment. The amount payable if a Service is terminated before the end of its Minimum Service Period where a right to do so exists, or on force majeure termination; calculated under the relevant Schedule.
Customer Data and Customer Records. Distinct terms. Customer Data is what is loaded, stored or processed on blueAPACHE Environments or Customer Managed Equipment by anyone other than blueAPACHE; Customer Records are records the Customer owns or supplies to which blueAPACHE is given access, and expressly exclude Customer Data. Co-location data is excluded from both.
Business Hours. 0700 to 1900 AEST/AEDT on any Business Day, where a Business Day excludes Saturdays, Sundays and nationally recognised Australian public holidays.
Action Plan (BCP). The document blueAPACHE prepares on request under clause 15 to integrate its Services into a customer's business continuity plan. It is opt-in, chargeable as a Professional Service, and distinct from DRaaS.
Variation. A change to the Service Agreement agreed in writing and binding when both parties sign, with exceptions for renewals, Acceptable Use Policy changes, Service Description updates and shared services changes.
Acceptable Use Policy. Incorporated into every Service Agreement, changeable by blueAPACHE at its discretion by posting an update on its website, and a termination trigger if breached. Its text is not reproduced here.
Certification terms
ISMS and ISO/IEC 27001:2022. blueAPACHE holds certificate 202507-118 for an Information Security Management System conforming to ISO/IEC 27001:2022, issued by Sensiba Australia Pty Ltd, valid 1 August 2025 to 1 August 2028. The certificate certifies the management system, not any product or service. See ISO 27001 certification.
Statement of Applicability. The ISMS document listing which Annex A controls apply; the certificate references version 5.0a (July 2025).
APRA CPS 231 and APRA Request. Clause 10 of the General Terms and Conditions applies where a customer is an APRA regulated entity and the Services are a material business activity under Prudential Standard CPS 231. An APRA Request is a request from APRA for information, documents or an on-site visit, which blueAPACHE will comply with and notify the customer of.
Related
- Service comparison
- Terms and conditions guide
- Support and service levels
- ISO 27001 certification
- Services hub
- Service Agreement
Frequently asked questions
Is emPOWER a product or a brand?
emPOWER is the brand name for blueAPACHE's whole service portfolio, created in 2003 when Facilities Management Services were renamed emPOWER Managed Services. Individual services carry the prefix, for example emPOWER Cloud or emPOWER Connectivity. The 2026 site groups them under pillars such as Managed Services, Security, Cloud, Connectivity and Collaboration.
What is the difference between IaaS, DRaaS and STaaS at blueAPACHE?
IaaS is emPOWER Cloud, the compute and storage platform where workloads run. DRaaS is emPOWER IT Continuity Services, a contracted restoration capability measured against an agreed RPO and RTO. STaaS is a private S3-compatible storage tier, described as immutable and replicated across three data centres, used for archives such as the pathology provider's health records.
Does "Customer Zero" have a defined scope?
No. blueAPACHE uses the phrase as a differentiator meaning it runs its own business on the operating model it sells, but the published material does not define which services or functions the claim covers. The Zoom, CyberArk and HPE case studies on this site show blueAPACHE as its own customer for collaboration, identity security and private cloud respectively.
What counts as a Service Level in a blueAPACHE agreement?
Only a commitment written under the heading "Service Level" in a Service Description. The General Terms and Conditions state that other delivery obligations, including a Compliance Target for resolution time, are not Service Levels. Brochure uptime figures are published service levels only if the relevant Schedule records them that way.
What is a Reasonable Excuse and why does it matter?
It is the defined list of events that excuse blueAPACHE from breach and suspend Service Levels to the extent a failure is contributed to by them. The list covers customer-caused problems, third party software blueAPACHE uses, acts of third parties, Emergencies, and any further items a Schedule or Service Order adds.
What is the difference between Customer Data and Customer Records?
Customer Data is what the customer loads or processes on blueAPACHE systems. Customer Records are records the customer owns or supplies to which blueAPACHE is given access, and the definition expressly excludes Customer Data. The distinction affects the integrity obligations in clause 17 and the liability carve-outs in clause 19.
Does MDR include Human Risk Management?
The MDR brochure lists Vulnerability Management, Incident Response Retainer, vCISO Advisory and Human Risk Management after its key features without stating whether they are included. Human Risk Management is marketed separately as its own service, so treat inclusion as something to confirm on the Service Order.
What does SASE mean in blueAPACHE's portfolio?
Secure Access Service Edge: modern networking and security controls combined in one managed approach so distributed users get consistent, protected access. blueAPACHE bundles SASE into emPOWER Connectivity alongside SD-WAN and next-generation firewalls, delivered over its own MPLS core.
What does the ISO/IEC 27001 certificate actually certify?
An Information Security Management System covering the systems, processes and infrastructure used to provide and manage the emPOWER infrastructure and managed service offerings at the Melbourne, Sydney and Brisbane offices. The certificate states expressly that it does not imply any product or service is certified.
Where are RPO, RTO and backup retention values published?
They are not published. The General Terms and Conditions say they are set in the relevant Schedule or Service Order, and the emPOWER Backup for Microsoft Entra ID brochure publishes no frequency, retention, RPO or RTO. Ask for the Schedule before relying on any figure.
Source
blueAPACHE published material, including the emPOWER service brochures, the General Terms and Conditions, the ISO/IEC 27001 certificate and the published case studies, and the pages on blueapache.com.