BT Smart Messaging (Sinch)
The Smart Messaging (Sinch) platform is designed to help organisations fulfil their messaging requirements at scale. It is an enterprise grade communication platform that supports the delivery and execution of outbound and inbound SMS campaigns.
Features
- Mass communication with end recipients via SMS
- Communicate via a single SMS API (REST API)
- ISO27001, Cyber Essentials & NHS DSPT certified
- Both one and two way communication over SMS
- Accessible reporting via a web based dashboard
- Use your brand name as the Sender name for messages
- Send via Shortcode, keyword or Virtual Mobile Number
Benefits
- Direct, mass communication with a large audience
- Integrate the capability with a variety of existing internal systems
- Use cases include appointment reminder, notification messages and surveys
- Direct UK routing for faster and more secure messaging
- Flexible opt in and opt out support
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 6 9 7 5 5 6 1 1 5 3 5 1 3 4
Contact
BRITISH TELECOMMUNICATIONS LIMITED
Frameworks Team
Telephone: 0800 328 8077
Email: ccsframeworks@bt.com
About your service
- Service categories
-
Applications
Customer relationship management
- Marketing campaign management
- Digital commerce
- Sales force productivity and management
- Customer service
Advertising
- Advertising Placement
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Any service that is capable of messaging can extend and use the platform.
- Cloud deployment model
- Private cloud
- Service constraints
- SC's and regulations
- System requirements
- Not applicable
User support
- Email or online ticketing support
- Yes
- Support response times
- Further detail can be found here: https://www.sinch.com/fr-fr/messaging-service-level-agreement-sla/
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
- Further details can be found here: https://www.sinch.com/fr-fr/messaging-service-level-agreement-sla/
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide the developer docs, the API keys and dashboard access and any technical support required during onboarding and implementation.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Request to the appropriate account manager and dedicated DPO officer.
- End-of-contract process
- The service will continue to roll on a monthly basis at the end of the minimum term agreement unless re-contracted.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- All clients receive access to a client dashboard for access to their API tokens, billing information and statistics.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Atlassian Accessibility QA team performed an accessibility audit for the Jira Service Management DC website.
Evaluation Methods Used:
A Representative set of pages and modal dialogs were identified to perform the audit.
The pages were tested in the below environments:
Windows 10 Pro/Chrome/JAWS 2023
Windows 10 Pro/Firefox/NVDA 2023
MAC OS 13.5.2/Safari/Voiceover
Accessibility testers performed the audit using:
Automated Tools
W3C Markup Validation Service
Color Contrast Checker
ANDI
Code Inspection
Screen Readers
Keyboard-only interaction
The result reflects the accessibility of a representative set of pages and modal dialogs. Accessibility testers performed the test keeping WCAG 2.1 guidelines in mind - API
- Yes
- What users can and can't do using the API
- This service is to send a receive messages using SMS. Future capabilities may include: RCS, WhatsApp and Facebook Messenger among other social channels. Future capabilities may include a full AI chatbot and contact centre offering.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The messages themselves have the ability to be branded and personalised as required, this is done though the payload of each message setting the to and from fields. A full list of message customisation can be found here: https://developers.sinch.com/docs/sms/api-reference
Scaling
- Independence of resources
- The platform is built for scalability so heavy load by one client will not affect others. All accounts also have a max TPS (Transactions per second) to ensure only a certain amount can be sent per account.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The reporting dashboard provides stats on messages sent, delivery rates, failure rates and latency.
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Sinch UK Ltd
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- AES 256 bit encryption.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- This can be provided at the end of a contract.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Microsoft Excel
- Data import formats
-
- CSV
- Other
- Other data import formats
- Microsoft Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- UN/Pass, unique URL's, 32 Char auth tokens, White listing IP, TLS and VPN.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Data at rest encrypted with 265 bit AES
Availability and resilience
- Guaranteed availability
- Target 99.99% availability (not guaranteed).
- Approach to resilience
- Multiple Geo-redundant data centres, rate limits on accounts, automatic AIT monitoring.
- Outage reporting
- This is done through e-mail alerts, you can sign up for the relevant alerts at status.sinch.com
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- Restricted and managed access rights ensure privileged access is controlled to authorised users only. Access rights shall be assigned based on the identified need of the appropriate user. Access rights are governed by password restrictions, access reviews and multi factor authentication requirements.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Please reference Sinch Security standard document which can be made available by BT on request.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configurations, including security configurations, of hardware, software, services and networks should be established, documented, implemented, monitored and reviewed.
Changes to information processing facilities and information systems should be subject to change management procedures. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Vulnerability Scan every 7 days.
Apply security patches to all components of the application stack with
severity score higher than "low" or “optional” as determined by the
issuer of the patch within one month (30 days) after release, measure
percentage of compliance quarterly above 85% and 100% for critical.
Pen test every 12 months black box manual, fix within 30 days and
report 30 days after that, all issues linked to Jira tickets - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Protection against malware implemented and supported by appropriate user awareness.
Networks, systems and applications should be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.
The organisation should plan and prepare for managing information and security incidents by defining, establishing and communicating information security incident management processes, roles and responsibilities. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
The organisation plans and prepares for managing information security incidents by defining, establishing and communicating information security incident management processes, roles and responsibilities.
The organisation assesses information security events and decides if they are to be categorised as information security incidents.
Any information security incidents should be responded to in accordance with the documented procedures.
Any knowledge gained from information security incidents should be used to strengthen and improve future information security controls.
The organisation should establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- The same as the full service however there are limited credits and message content is overwritten.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LQRA Limited
- ISO/IEC 27001 accreditation date
- Friday 16 January 2026
- What the ISO/IEC 27001 doesn’t cover
- This covers our published service offers
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA Limited
- ISO 9001 accreditation date
- Tuesday 19 August 2025
- What the ISO 9001 doesn’t cover
- This covers our published service offers
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 30d49a42-7676-4f9e-ba34-05a211d0dd04
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 31cf450d-d8be-4c72-9251-45f5a9a4025a
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-