Skip to main content

Help us improve the Digital Marketplace - send your feedback

ARVATO LIMITED

Avoira (Xdroid) Speech & Text Analytics by ArvatoConnect

ArvatoConnects delivers AI‑driven Speech & Text Interaction Analytics to process 100% of customer interactions, with call transcription, emotion analysis, keyword detection, and Auto Quality Assurance, Caller Vulnerability Checking & Fraud ID. It improves customer experience, agent performance and operational efficiency. Agent Assist provides Live-in-Call Prompts & Auto Call Summary.

Features

  • Real‑time call transcription and analysis
  • Sentiment detection across all customer interactions
  • Automated quality management for every interaction
  • Agent Assist with live in‑call coaching
  • Call categorisation with intent identification
  • Auto‑summarisation of conversations
  • Language‑independent emotion analytics
  • NPS prediction using AI insights
  • Omnichannel analytics for chat, email, social media
  • Predictive alerts highlighting at‑risk customers

Benefits

  • Improve agent performance using real‑time coaching insights.
  • Reduce handling time through automated compliance checking.
  • Identify dissatisfied customers before churn increases.
  • Enhance decision‑making with AI‑driven predictive insights.
  • Boost customer satisfaction using sentiment‑based insights (Across 100% interactions)
  • Accelerate quality assurance by analysing 100% interactions automatically.
  • Optimise workflows using real‑time interaction summaries.
  • Increase operational efficiency with automated categorisation.
  • Strengthen compliance through continuous monitoring and alerts.
  • Improve customer understanding using omnichannel behaviour analysis.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at richard.husband@arvatoconnect.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 2 9 5 6 2 7 7 2 8 1 1 9 7 1

Contact

ARVATO LIMITED Richard Husband
Telephone: 07867464428
Email: richard.husband@arvatoconnect.co.uk

About your service

Service categories

Application Development and Deployment

AI platforms

AI software services

  • Conversational AI Software Services
  • Generative AI Software Services
  • Document AI Software Services
  • Personalize AI Software Services
Multi cloud support
No

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Xdroid is designed to integrate directly with multiple contact‑centre, telephony, and communication platforms rather than operate as a standalone CCaaS solution. It enhances these platforms with AI‑driven analytics. (8x8, Five9, Genesys Cloud, Avaya, RingCentral). Ringover users can activate Xdroid analytics directly, turning call data into insights without technical setup.
Cloud deployment model
Private cloud
Service constraints
No Constraints
System requirements
  • Requires on‑premise infrastructure for private deployment
  • Needs compatible CCaaS platform for integration.
  • Requires ability to send recordings via SFTP
  • Requires supported telephony system for call capture.
  • Needs API access for cloud telephony integrations.
  • Needs storage environment for transcripts and analytics.
  • Requires secure data‑handling environment for GDPR compliance.
  • Requires supported speech‑recording format and metadata.
  • Requires platform access permissions for integration setup.

User support

Email or online ticketing support
Yes
Support response times
When you log a support request, we categorises it by priority and applies the following typical SLA response times:

Priority 1 (P1) – Critical / Business Down - Response Time: 1 working hour.
Priority 2 (P2) – Major Issue - Response Time: 2 working hours
Priority 3 (P3) – Minor Impact - Response Time: 8 working hours
Priority 4 (P4) – Low Priority / Routine Changes - Not explicitly defined beyond being lower priority and handled accordingly.

We do offer extended support up to 24/7/365, but only if your organisation has purchased an Out‑of‑Hours Maintenance Contract.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We offer extended support packages that go beyond standard business hours.

Out‑of‑hours support is available up to 24/7/365, providing access to engineers outside Monday–Friday core hours.

This support level is only available to customers with a pre‑paid Out‑of‑Hours Maintenance Contract.

What it includes
Access to an engineer for urgent support outside business hours.
Continuity of monitoring and response where customer’s contract includes 24/7 coverage.
Support available to third parties
No

Onboarding and offboarding

Getting started
We support new Xdroid users primarily through consultancy, deployment support, configuration, and ongoing expert guidance. Our role is to ensure the Xdroid platform is aligned with each organisation’s systems, goals, and operational needs.

Expert Consultancy & Requirements Analysis - We carefully assess a customer’s objectives and environment before implementation. Our team of business analysts works closely with clients to understand needs and ensure Xdroid is configured to deliver the intended outcomes.

Deployment & Technical Integration Support - We manage and support the technical implementation of Xdroid, ensuring seamless integration with existing contact‑centre systems. This includes setup, configuration, and ensuring the system runs smoothly in the customer environment.

Ongoing Management & Support - We emphasise long‑term partnerships, offering responsive technical support and service management after go‑live. We remain “always there for you,” helping organisations extract maximum value from the platform.

Continuous Insights & Performance Optimisation - Our team helps organisations interpret insights from Xdroid and derive actionable improvements, ensuring the analytics deliver meaningful ROI and operational benefits.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
We ensure that customers can securely extract their data at the end of a contract through a structured and compliant process.
End-of-contract process
At the end of a Xdroid contract, a secure and transparent offboarding process ensures customers retain full control of their data while meeting compliance obligations. This includes:

Confirm termination or renewal terms in the Master Agreement.
Issue formal communications (letters, SoWs) to close or extend the relationship.
Complete compliance checks and ensure secure data destruction.
Remove system access and handle any technical offboarding.
Conduct a final review meeting to validate obligations and performance.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Linux or Unix
  • Windows
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Avoira does provide service interfaces, but they differ depending on which part of the service you're using. There is no single universal “Avoira app”, but there are multiple web‑based interfaces and portals that customers use to interact with Avoira services.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We’re committed to making our service usable by as many people as possible and to meeting UK public‑sector accessibility regulations.

We design for perceivable, operable, understandable and robust content, including keyboard access, screen‑reader compatibility (JAWS, NVDA, VoiceOver), sufficient colour contrast, and responsive layouts.
API
Yes
What users can and can't do using the API
Import & Export Data from the existing phone system
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Xdroid is a highly configurable AI-driven speech and interaction analytics platform that can be tailored to meet the specific operational, regulatory, and performance needs of public‑sector organisations. The solution includes a unique, customer‑specific speech engine, which is trained to recognise an organisation’s terminology, product names, and acronyms, ensuring accurate transcription, sentiment analysis, and call categorisation tailored to each environment. Xdroid also enables the creation of custom reporting dashboards, alerts, and automated quality‑assurance scoring, allowing teams to track the metrics and behaviours most relevant to their service environment.

The platform supports flexible configuration of compliance checks, vulnerability indicators, and performance KPIs, ensuring alignment with organisational processes and regulatory frameworks such as consumer duty or industry‑specific compliance requirements. Organisations can also tailor agent‑assist prompts, real‑time analytics, and workflows to provide targeted, context‑specific guidance for frontline advisors. Severity / Risk scoring of certain identifiers, such as a declared vulnerability, can be configured. The caller may have a vulnerability that is of higher risk to the organisation and so can be scored as such.

Xdroid IQ, the platform’s advanced AI engine, further supports customisation through the ability to add organisational documents and protocols to enhance tagging, scoring, and contextual analysis using Retrieval Augmented Generation.

Scaling

Independence of resources
Xdroid ensures consistent performance through a dedicated, single-client environment, eliminating multi-tenant resource contention. Its containerised architecture uses Docker for workload isolation and responsive scaling, supported by active-active or active-passive configurations for high availability. Load balancing and automated scaling maintain service quality under varying demand. Continuous monitoring via AWS CloudWatch and CloudTrail, combined with vulnerability checks through AWS Inspector, ensures proactive performance management. This design guarantees that user experience remains unaffected by other users’ activity, meeting G-Cloud requirements for reliability, resilience, and service assurance.

Analytics

Service usage metrics
Yes
Metrics types
Xdroid delivers comprehensive service usage metrics through real-time and post-call analytics. It monitors 100% of interactions across voice, email, chat, and social channels, providing sentiment analysis, compliance checks, and predictive insights. Key metrics include Average Handling Time (AHT), Net Promoter Score (NPS), agent productivity, and quality assurance adherence. AI-driven dashboards highlight trends, training needs, and process inefficiencies, enabling proactive improvements. By offering operational, performance, and strategic insights, Xdroid supports compliance, optimises customer experience, and enhances agent wellbeing. These capabilities align with G-Cloud requirements for transparency, measurable outcomes, and continuous service improvement.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Avoira

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Our solution primarily handles call recordings and associated metadata for analytics. We have the following supported export methods:

SFTP Transfer: Directly to the API server over MPLS links.
AWS S3 Bucket: Avoira can provide a secure bucket for uploads.
Encrypted USB Drive: Physical transfer with passcode protection.
Customer System Pull: Avoira can collect recordings from your environment using provided credentials.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • Other
Other data import formats
JSON

Data-in-transit protection

Data protection between buyer and supplier networks
Private network or public sector network
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Xdroid guarantees high availability through its cloud-native architecture hosted on AWS, designed for resilience and scalability. The platform supports active-active and active-passive configurations, load balancing, and automated failover to maintain service continuity.

Service Level Agreement (SLA):
Xdroid typically offers an availability SLA of 99.9% uptime, excluding scheduled maintenance windows. This is consistent with AWS-backed infrastructure standards and ensures minimal downtime for critical services.
Approach to resilience
Xdroid is designed for resilience and high availability, leveraging a cloud-native architecture hosted on AWS. The platform uses distributed components within Docker containers, enabling workload isolation, responsive scaling, and rapid recovery in case of failure. High availability is achieved through active-active and active-passive configurations, supported by load balancing across multiple instances to maintain service continuity. For disaster recovery, Xdroid supports multi-site deployments and SQL Always On Availability Groups, ensuring critical data remains accessible even during regional outages.

The underlying AWS infrastructure provides robust physical and environmental security, with private subnets, hardened servers (CIS Benchmarks), and continuous monitoring via AWS CloudWatch, CloudTrail, and Inspector. These tools proactively detect vulnerabilities and performance issues, ensuring resilience at both application and infrastructure levels. Data is encrypted at rest using AES-256 and managed through AWS KMS (FIPS 140-2 validated), while all communications use TLS 1.2+ for secure transmission.

Xdroid’s design guarantees compliance with ISO/IEC 27001 and UK Government Cloud Security Principles. Detailed datacentre resilience configurations, including failover strategies and disaster recovery plans, are available on request for security reasons. This approach ensures uninterrupted service, robust protection, and alignment with G-Cloud requirements for reliability and resilience.
Outage reporting
Xdroid manages outage reporting through secure, automated notifications and robust monitoring systems. The platform uses Amazon Simple Email Service (SES) to deliver email alerts whenever an outage or critical event occurs. These alerts include a secure link to the system for further details, ensuring sensitive data is never exposed in the email body or attachments. Users can configure alert settings within the web interface, allowing targeted notifications to relevant stakeholders.

Internally, Xdroid leverages AWS CloudWatch, CloudTrail, and Inspector for continuous monitoring of system health, performance, and vulnerabilities. These tools provide proactive detection and escalation of issues, supporting rapid resolution and maintaining service continuity. While there is no public dashboard or API for outage reporting, the combination of email alerts and AWS monitoring ensures transparency and reliability for clients.

This approach aligns with G-Cloud requirements for resilience and incident management, guaranteeing that customers receive timely notifications and that outages are managed effectively within a secure, compliant environment. Detailed outage management procedures and escalation workflows are available on request for security reasons.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Xdroid enforces strict access controls for management interfaces and support channels. Administrative access is limited to authorised personnel through role-based permissions and multi-factor authentication. All management actions require secure HTTPS connections with TLS 1.2+ and RSA 2048-bit encryption. Support channels operate via authenticated portals, ensuring only verified users can raise or view tickets. Sensitive operations are logged and monitored using AWS CloudTrail, with audit trails maintained for compliance. Privileged accounts follow least-privilege principles, and access reviews are conducted regularly. These measures prevent unauthorised changes, safeguard customer data, and maintain adherence to GDPR and ISO 27001 standards.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users receive audit information on a regular basis
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Xdroid follows robust information security policies aligned with internationally recognised standards, including ISO/IEC 27001, Cyber Essentials Plus, ISO 9001, and GDPR compliance. These policies cover data protection, retention, and destruction, supported by encryption protocols such as TLS 1.2+, RSA 2048-bit keys for data in transit, and AES-256 for data at rest. Key management is handled through AWS KMS, validated under FIPS 140-2, ensuring secure cryptographic controls.

Processes include annual reviews of management-approved IT security documentation and integration of OWASP recommendations into the development lifecycle. Vulnerability testing is conducted during development and before each release, with additional client-driven assessments as required. Incident reporting and escalation follow structured workflows, with dedicated contact points for security queries and compliance oversight.

The reporting structure ensures accountability through clearly defined roles across system managers, architects, and compliance teams. Governance is reinforced via scheduled audits, penetration testing, and coordinated validation before production deployment. Continuous monitoring using AWS CloudWatch, CloudTrail, and Inspector supports proactive detection and remediation of risks.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Xdroid follows structured configuration and change management processes aligned with ISO/IEC 27002 and OWASP best practices. All service components are tracked throughout their lifecycle using automated provisioning tools and version control. Changes are implemented in controlled environments, tested internally, and validated before production deployment. Each change undergoes a formal risk assessment to evaluate potential security impacts, including encryption, access controls, and compliance requirements. Governance is enforced through scheduled maintenance windows, documented release notes, and sign-off procedures. Continuous monitoring via AWS CloudWatch and Inspector ensures post-change validation, maintaining security and audit readiness.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Xdroid follows a robust vulnerability management process aligned with ISO/IEC 27002 and OWASP best practices. Potential threats are assessed through continuous scanning using AWS Inspector, supported by CloudWatch and CloudTrail monitoring. Threat intelligence is sourced from AWS Security Bulletins, OWASP guidelines, industry-standard tools, and client-driven assessments. Patches and updates are deployed rapidly, with a standard cycle of every 2–3 weeks and immediate remediation for critical vulnerabilities within agreed maintenance windows. This proactive approach ensures timely detection, prioritisation, and resolution of risks, maintaining compliance and service integrity.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Xdroid employs continuous monitoring using AWS CloudTrail, CloudWatch, and Amazon Inspector to identify potential compromises through anomaly detection, vulnerability scans, and CIS benchmark checks. When a potential compromise is detected, automated alerts trigger predefined incident response workflows, including isolation of affected resources, forensic analysis, and escalation to security teams. Responses are prioritised based on severity, with critical incidents addressed immediately and mitigated within minutes. Regular patching, encryption, and strict access controls ensure ongoing protection. All incidents are logged, reviewed, and reported to maintain compliance with GDPR and FCA standards, supporting rapid recovery and continuous improvement.
Incident management type
Supplier-defined controls
Incident management approach
Xdroid operates a structured incident management framework with pre-defined processes for common events such as system outages, security alerts, and data breaches. These workflows include automated detection, escalation, and resolution steps to minimise impact. Users can report incidents via a dedicated support portal, email, or integrated service desk, ensuring rapid acknowledgement and tracking. Each incident is documented in detail, and comprehensive incident reports are generated post-resolution, outlining root cause, actions taken, and preventive measures. Reports are shared securely with stakeholders to maintain transparency and compliance, supporting continuous improvement and adherence to regulatory standards.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Wednesday 7 September 2022
What the ISO/IEC 27001 doesn’t cover
While it is not practicable to list exclusions in isolation, our ISO 27001 certification supports all contracted services to ArvatoConnect customers, including contact centre, back-office and IT services.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Monday 16 January 2023
What the ISO 9001 doesn’t cover
While it is not practicable to list exclusions in isolation, our ISO 9001 certification supports business process outsourcing, delivering a comprehensive range of front and back office services. This includes customer experience services and administrative services.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fbb5c636-5561-4d78-b819-3360c25ffe07
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
A774e5a5-9ad4-4cbf-a7a3-e47ea2c0ef05
Other security certifications
Yes
Any other security certifications
  • Tisax
  • ISO 20000-1:2018

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at richard.husband@arvatoconnect.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.