HireBOB
HireBOB provides conversational AI “employees” for the health and fitness industry. Its AI agents help gyms, leisure centres, and wellness providers improve member engagement, sales, and retention by automating conversations across channels while delivering measurable ROI and human-like customer experiences.
Features
- AI Employees to automate conversations that feel human, not robotic
- Omnichannel messaging across web, WhatsApp, Messenger, SMS, and email
- Lead Conversion to turns enquiries into paying members
- Cancellation Prevention to identify and re-engage members
- Service Automation to handle service queries instantly
- CRM Integration. Syncs seamlessly with major leisure systems
- 24/7 Availability for always-on support without staffing costs
- Performance Analytics to Track ROI
- AI Training – teaches agents using natural human language
- GDPR Compliance – Secure, privacy-first design
Benefits
- Frees staff to support customers in person
- Reduces manual follow-ups for staff workload
- Staff can make informed decisions faster
- No IT distraction for frontline teams
- Staff spend less time answering routine queries
- Reduces staff training needs
- Drives greater revenue
- Increases operational efficiency
- Improves customer satisfaction
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 9 8 9 1 9 8 8 6 2 4 0 7 9 0
Contact
BOB AI LTD
Justin Mendleton
Telephone: 07455110141
Email: justin@hirebob.ai
About your service
- Service categories
-
Application Development and Deployment
AI platforms
- Search and knowledge discovery
AI software services
- Conversational AI Software Services
- Generative AI Software Services
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
CRM systems,
Websites,
Enquiry forms / platforms,
Support systems,
Fitness apps - Cloud deployment model
- Public cloud
- Service constraints
- N/a
- System requirements
- No requirements
User support
- Email or online ticketing support
- Yes
- Support response times
- 1 working day
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- Full technical support is included in licence fees
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- A combination of online training, videos, user documentation, and guided onboarding. New customers receive a customer success plan and access to an onboarding portal clarifying actions and status. For larger deployments, we can provide onsite support and training sessions to ensure staff are confident using the platform. Continuous support is available via email once live.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Users can easily export all customer data via the user interface in common, machine-readable formats such as CSV, or can be supported by our team on request.
- End-of-contract process
- All services required to end the contract e.g. extraction / deletion of data are included in the standard contract price.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation is fully accessible online, available 24/7 from any device. All materials are written in clear, structured language, with step-by-step instructions, screenshots, and video tutorials to accommodate different learning styles. Documentation follows accessibility best practices, including keyboard navigation, screen-reader compatibility, and high-contrast visuals, ensuring all users, including those with disabilities, can access and understand the content.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The end-user experience is the same on desktop and mobile.
The admin interface is optimised for desktop. It can be loaded on mobile, its just not as easy to use. This is a deliberate decision as all existing clients carry out their administrative tasks on desktop. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
The behaviour of the agent can be customised (a) during client onboarding, and (b) throughout the contract period. This is done via a combination of documentation sharing, interactive calls, and the administrative web interface.
The channels through which the agent communicates are configured/customised during onboarding, through discussions with us.
Integrations with client systems (e.g. CRMs) are configured during onboarding, through discussions with us.
Scaling
- Independence of resources
- Compute resources auto-scale to meet demand, using AWS Fargate and Elastic Container Service.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Counts of conversations, common topics
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- AI Agent Group Ltd t/a SalesAPE
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Via export function in the product interface
- Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- TXT
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
95% uptime SLA within each calendar month, with service credits if availability falls below this:
between 94.99% and 93% - 3 days credit
between 92.99% and 90% - 7 days credit
below 90% - 15 days credit - Approach to resilience
-
Storage and compute are configured with redundancy and automatic failover. Replicas are split between AWS availability zones, and the service is therefore resilient to both individual machine and entire availability zone outages.
Where possible, AWS managed services are utilised, such as load balancers, which have resilience built in. - Outage reporting
-
A public dashboard at https://status.salesape.ai/
Support links within the platform
Specific email updates via our customer services team
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
Client users require authentication as above.
End-users do not require authentication, that part of the service is designed to be public. - Access restrictions in management interfaces and support channels
-
Authentication with SSO, email/password and MFA as above.
Role-based access controls are in place. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We use an information security management system (ISMS) aligned with ISO27001 to govern security, though we are not yet certified.
- Information security policies and processes
-
We are Cyber Essentials certified, and our policies and processes are designed around ISO27001.
We have an information security lead, who regularly reviews our information security posture and reports and deviations from policy to leadership. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration changes are handled by our onboarding team, who are trained to assess each change for suitability and test the outputs of the system after each change.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We use the STRIDE framework to model threats, we run a risk register to track risks and mitigations, and we have several approaches for detecting vulnerabilities in our software, including static code analysis, Github's Dependabot dependency tracker, relevant CVE alerts, and peer-review of new code.
Depending on the perceived threat level, we deploy patches either next business day or within 4 weeks of publication. - Protective monitoring type
- Undisclosed
- Protective monitoring approach
- We have a documented incident response process available on request, including escalation and how to deal with data breaches.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Users report incidents via email to our support team.
We have pre-defined, documented processes for handling incidents.
For major incidents, a post-mortem is conducted and documented and shared with affected parties. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ccf05e48-4bfb-4bb2-be89-6712512426f2
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
-