Sterling Global Roaming Sim and Secure Messaging Services
Phantom SIM delivers resilient, high-security physical and eSIM connectivity, offering global coverage, multi-network resilience, and cloud-based cyber protection with full customer control. Phantom Signal is a UK-engineered secure messaging platform providing auditable communications, facial recognition user verification, geofencing controls, and sender-controlled message security.
Features
- Facial ID authentication for secure, verified user access
- Geofencing with automatic message deletion if devices are lost.
- Triple Diffie-Hellman on Elliptic Curve (3DH) key, AES-256 AEAD encryption.
- Real-time monitoring and control of messages and usage.
- Complete audit trails for operational accountability and compliance.
- Instant lockdown of communications for instant security.
- Global coverage with multi-network redundancy and resilience.
- Real-time network switching via central portal control.
- Secure, private connectivity with IPsec, private APN, and tunnels.
- PAYG, flexible plans with data pooling and multi-SIM support.
Benefits
- Ensuring messages are delivered to a person not a device
- Control connectivity to respond rapidly to dynamic mission needs.
- Protect sensitive data and prevent attacks from third parties
- Monitor communications in real-time to maintain operational oversight.
- Restrict messages by location, reducing data leaks and risk.
- Maintain complete audit trails for accountability and reporting.
- Flexibly manage multi-SIM and connectivity plans on the move.
- Access secure networks with private IPs for reliable operations.
- Enable immediate lockdown of communications as incident response.
- Track usage and performance in real-time to optimise resources.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 8 5 2 9 3 2 5 1 7 6 8 1 7 2
Contact
STERLING COMPUTERS CORPORATION (UK) LTD
Luke Flanagan
Telephone: +447557400401
Email: sterlinguk@sterling.com
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Phantom SIM works with any SIM-enabled device, including phones, radios, CCTV cameras, and IoT devices. Phantom Signal operates on mobile phones, tablets, and similar devices for secure messaging. Both services can be used independently or together, extending secure connectivity and communications across existing hardware and operational systems.
- Cloud deployment model
- Hybrid cloud
- Service constraints
- Currently, Phantom Signal is avaiable on Android devices and iOS support, On request we can also make the desktop version available for MAC and Windows. Phantom SIM is compatible with any SIM-enabled device, including phones, radios, CCTV cameras, and IoT devices. Both services can be used individually or together.
- System requirements
-
- Phantom SIM requires a device that supports SIM or eSIM
- Phantom Signal is available for Android, IOS, MAC and Windows.
User support
- Email or online ticketing support
- Yes
- Support response times
- We respond to questions promptly via phone and email, typically within a couple of hours 24/7. Response times may be slightly longer over weekends. We are committed to providing timely support and are happy to discuss and implement a formal Service Level Agreement (SLA) if required, ensuring consistent, reliable communication for all enquiries.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
On set up we offer, full training and installation support as standard,
We offer the following support levels:
Basic - Mon-Fri 8am-8pm (local time) - Free
Premium - within 24 hours - enhanced cost.
Enhanced - next business day response - enhanced cost. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Onboarding for both Phantom SIM and Phantom Signal is straightforward and can be conducted in-person or remotely, depending on user preference.
For Phantom SIM, users are guided through activating SIMs via the central management portal, which controls connectivity, security, and network settings. The portal is intuitive, and full functionality can be demonstrated in 30 minutes or less. Users gain immediate control over activation, deactivation, and real-time network management.
For Phantom Signal, setup can also be done remotely, though in-person sessions are recommended to ensure proper configuration and enable full functionality. The setup process is simple, taking approximately 30–60 minutes, and ensures users can securely send and manage messages from mobile devices.
Both services come with comprehensive user documentation, including step-by-step guides for activation, configuration, and best practice use. Training is concise, user-friendly, and tailored to operational requirements, ensuring users can start using the systems effectively with minimal disruption.
We aim to make the onboarding process rapid, efficient, and fully supported, allowing users to gain secure, reliable communications and connectivity quickly. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- All messages and metadata can be downloaded to a CSV file on request. Including any personal information that is held within the server environment. On set up of the system the customer can opt to write all metadata and messaging information to any S3 storage bucket.
- End-of-contract process
- Customer will be offered the opportunity to reengage another term of contract, if not required then we will ensure that extraction of all data is delivered before then systematically destroying all information that has been held.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Other
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- We offer multiple delivery options, including availability via the App Store and Google Play, or direct Android deployment via APK. The iOS application can be disguised with a customer-specified icon and is delivered via TestFlight for both mobile and desktop. There is no functional difference between mobile and desktop versions. The server component can be deployed on any cloud platform or, if required, on bare-metal infrastructure. Phantom SIM delivery follows the same approach.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- We have an HTML web service (admin panel), that we give access to administrators and super administrators through an MFA login, where all metrics relating to the platform can be monitored/accessed in real time.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Assistive technology has been utilised on the devices that phantom SIM is providing network connectivity too with no issues. Phantom Singal secure application addresses accessible needs for users with visual impairments (including low vision and colour blindness); hearing impairments; motor and dexterity impairments; cognitive and learning disabilities; and users relying on screen readers, keyboards, or assistive technologies
- API
- Yes
- What users can and can't do using the API
- All the functions that are available on the traditional application are available through the API.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The solution can be fully white-labelled and, if required, individual components of the messaging application can be integrated into existing government agency applications. Service delivery can be configured to meet specific operational requirements, including use in restricted environments (such as STRAP) where features like facial recognition may not be approved. All customisation is performed at developer level and must be defined prior to delivery or implemented through an agreed patch or service update.
Scaling
- Independence of resources
- Each customer is provided with a dedicated, secure portal and real-time dashboard that is isolated from all other users. This ensures one customer’s usage or demand cannot impact another’s service performance or access. Connectivity, Security, and Controls are managed independently per customer. The only external dependency is the underlying internet connection, which may affect performance outside of system control.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Phantom SIM provides service metrics through a central user portal. Users can view real-time and historical usage data displayed in clear chart formats, showing data consumption per SIM or group. This enables effective monitoring and cost control. An enhancement is currently in progress to additionally display spend metrics, allowing users to view both data usage and associated costs directly within the portal. Phantom Signal will offer administration ability to manage and control who can and cannot access service access, and can make access available from the management console as required to any user.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Agreement to resell Phantom SIM and Phantom Signal globally.
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
- Other
- Other data at rest protection approach
- Using AES 256 encryption, with controlled levels of access to the data.
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Via the admin console, users can download messaging information into a CSV
- Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Phantom SIM and Phantom Signal offers 98.8% availability. We cannot be held responsible for denial of any services that are out of our control, or as a part of a force Majeure.
- Approach to resilience
- Phantom SIM uses one of the largest TELCOM network backbones in the world, which is responsible for providing 98% availability and Phantom Signal is an application hosted on our infrastructure or yours with business continuity, resilience and warnings and indicators built in, to provide a high level of availability assurance.
- Outage reporting
- Customers are notified of service-impacting incidents, planned maintenance, or significant degradation via email notifications to nominated contacts and through the admin panels.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- Users need to KTC process by enrolling their biometrics after sign in, With regards the admin panel admin users must go through an MFA process.
- Access restrictions in management interfaces and support channels
- There is one admin panel, that you can give elected individuals access to. This is the same in both Phantom Sim and Phantom Signal.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Description of management access authentication
- Through a separate authenticator (Microsoft/Google/or third party authenticator) OTP is passed to the system then providing access after a password has been provided.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We follow recognised information security policies and processes aligned with ISO27001 and strict GDPR compliance to protect data confidentiality, integrity, and availability. These controls include secure system configuration, access control, vulnerability management, and continuous monitoring.
We work closely with military and government contracts and therefore adhere to relevant customer security policies, operational security requirements, and contractual information assurance standards. Our internal security framework is designed to meet the expectations of sensitive and regulated environments.
Internal policies govern authentication, role-based access, and administrative permissions, ensuring only authorised personnel can access systems and customer data. All data handling complies with GDPR principles, including lawful processing, data minimisation, and secure storage.
We maintain incident response procedures, regular security reviews, and controlled infrastructure access throughout the service lifecycle, from onboarding to offboarding. This layered approach ensures robust protection for customer data, communications, and operational systems. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Configuration and change management follow documented processes aligned to ISO/IEC 27001 principles. All service components, including application code, container images, infrastructure, and configuration items, are uniquely identified and tracked throughout their lifecycle using version control, configuration inventories, and immutable artefacts. Changes are raised, reviewed, and approved through formal change control. Each change is assessed for potential security impact, including access control, data protection, network exposure, and dependency risk. Changes are tested in controlled environments and deployed using phased or rolling updates. Emergency changes follow an expedited process with retrospective security review to maintain compliance.
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Our vulnerability management process follows ISO 27001 and NCSC guidelines, with continuous monitoring, automated vulnerability scanning, penetration testing, and threat modelling to assess potential threats to services and evaluate their impact and likelihood. Information about threats is sourced from reputable industry feeds and official government advisories; specific sources remain sensitive for security. Patches are deployed rapidly: critical vulnerabilities within 7 days, high-severity vulnerabilities within 14 days, and others based on risk, with offline mechanisms for disconnected edge nodes in remote environments to ensure resilience.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Real-time monitoring and security alerts allow users and system administrators to kill devices off the network or from the user group within seconds of an incident.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- The service operates defined incident management processes aligned to recognised security practices. Pre-defined procedures exist for common incident types, including service outages, security events, and data protection incidents, covering identification, escalation, containment, investigation, and resolution. Users can report incidents via agreed support channels such as a service desk or dedicated support email, with escalation paths defined for critical incidents. Automated system alerts may also trigger incident handling. Users are kept informed through email updates during incidents. Post-incident reports can be provided on request, detailing impact, root cause, corrective actions, and preventative measures.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
Phantom Signal, you will be given a 30 day trial period. You will not have access to the admin panel.
Phantom Sim, will include a Physical Sim or eSIM and free access up to 3GB of data for 1 month with access to the management platform.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 4%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7%
- Between £1,000,001 and £2,500,000
- 8%
- Between £2,500,001 and £5,000,000
- 9%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Perry Johnson Registrars INC
- ISO/IEC 27001 accreditation date
- Friday 13 December 2024
- What the ISO/IEC 27001 doesn’t cover
- Sterling’s ISO/IEC 27001:2022 certification covers our internal Information Security Management System supporting Sales, Solution Engineering, Order Fulfilment, and Professional Services Delivery. It does not extend to customer-owned environments, third-party systems, or customer platforms outside of Sterling’s operational control unless covered under a managed service agreement
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Perry Johnson Registrars INC
- ISO 9001 accreditation date
- Friday 29 December 2023
- What the ISO 9001 doesn’t cover
- Sterling’s ISO 9001:2015 certification covers our Quality Management System as an IT Service Provider and Reseller of IT Products and Services. It does not extend to customer-owned environments, third-party delivery outside Sterling’s contractual control, or customer-operated platforms and services.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- D689C512-D9CF-4BB3-AA95-B29C1B196210
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 46CE9863-70BD-47F7-88AE-2A4AE9DDD3E4
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-