TTEC Digital Calabrio ONE
TTEC Digital Calabrio ONE delivers a cloud-based contact centre solution that optimises workforce management, quality assurance, and analytics. It empowers organisations to enhance customer experience through intelligent scheduling, forecasting, and performance insights, ensuring operational efficiency and improved engagement outcomes.
Features
- AI-powered forecasting for accurate staffing predictions
- Real-time adherence monitoring for schedule compliance
- Omnichannel call recording across voice, email, and chat
- Automated quality management with customisable scorecards
- Voice-of-the-customer analytics for actionable insights
- Self-scheduling tools for agent flexibility and autonomy
- Advanced sentiment analysis powered by GenAI
- Customisable dashboards for performance and KPI tracking
- Cloud-native architecture with high availability and security
- Open API for seamless integration with CRM and CCaaS
Benefits
- Reduce labour costs through precise workforce forecasting
- Improve customer experience with omnichannel interaction insights
- Boost agent engagement via self-service and coaching tools
- Enhance compliance with automated call recording and reporting
- Accelerate decision-making using real-time analytics dashboards
- Increase operational efficiency through AI-driven scheduling
- Lower attrition with flexible scheduling and gamification
- Drive revenue by optimizing agent performance and upsell opportunities
- Enable remote work with secure cloud-based platform
- Foster continuous improvement through actionable performance insights
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 1 5 1 5 5 7 2 5 0 6 7 1 8 8
Contact
TTEC CONSULTING (UK) LIMITED
Wayne Kay
Telephone: 0113 5432620
Email: gcloud@ttecdigital.com
About your service
- Service categories
-
Applications
Customer relationship management
- Marketing campaign management
- Digital commerce
- Sales force productivity and management
- Customer service
- Contact centre
Advertising
- Advertising Placement
- Advertising Measurement
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Our service extends leading contact centre and CRM platforms, including NICE CXone, Microsoft Dynamics 365, Genesys Cloud and Amazon Connect. It integrates seamlessly via APIs and adapters, enabling real-time adherence, historical reporting, and schedule synchronisation for unified workforce management across omnichannel environments.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Planned maintenance occurs during agreed low-usage windows with prior notice. Service availability depends on stable internet connectivity and supported browsers (latest and previous versions). Performance may vary on outdated hardware or unsupported operating systems. Customer must ensure compliance with technical prerequisites, including API configurations. No offline mode; cloud access required.
- System requirements
-
- Windows Server 2019 or later operating system installed and licensed.
- Microsoft SQL Server 2017 or newer database engine fully configured.
- Latest Java Runtime Environment installed for application compatibility assurance.
- Active Directory integration enabled for secure user authentication and management.
- Minimum 16 GB RAM and quad-core processor for performance.
- Reliable internet connection with minimum 10 Mbps bandwidth for operations.
- Supported web browser: Chrome, Edge, or Firefox with latest updates.
- Antivirus software installed and regularly updated on all virtual machines.
- Valid SSL certificate for secure HTTPS communication between components.
- Adequate disk space: 100 GB free for application and logs.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Service Priorities & Response Times:
P1 Emergency: Immediate contact, constant follow-up, 30 min response, hourly updates, 4-hour escalation, 24x7 coverage.
P2 High: Immediate contact via call or 4 hours via portal, daily follow-up, next business day contact, UK business hours.
P3 Medium: All types, 4-hour initial contact, 3 business days follow-up, next business day contact, UK business hours.
P4 Low: All types, 4-hour initial contact, 5 business days follow-up, next business day contact, UK business hours.
MACD: Completed within 2 business days, scheduled during business hours. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
1. Support Levels Provided
SurroundCX™ offers three support tiers: Essential, Plus, and Premium:
• Essential includes core monitoring, incident management, and standard platform support.
• Plus adds proactive health checks, configuration assistance, and enhanced reporting.
• Premium delivers strategic guidance, advanced analytics, priority case handling, and dedicated personnel.
2. Support Costs
Pricing is subscription-based and varies by tier, user volume, and service complexity. Exact costs are defined in individual contracts and service-level agreements.
3. Dedicated Support Personnel
Only Premium clients receive a dedicated Technical Account Manager for strategic oversight and a Cloud Support Engineer for technical troubleshooting and optimisation. Essential and Plus tiers rely on shared support resources. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
TTEC Digital provides a structured onboarding approach to ensure rapid adoption and measurable outcomes. We offer comprehensive training and enablement services, including:
• Instructor-led sessions delivered onsite or virtually for system setup, routing logic, quality management, and administration.
• Role-based training tailored for agents, supervisors, and administrators, covering omnichannel workflows, analytics, and WFM features.
• Train-the-Trainer programmes for internal knowledge transfer and long-term scalability.
• Custom workshops focused on workflow optimisation, AI-driven insights, and advanced analytics.
• Self-paced digital modules for flexible learning and continuous improvement.
In addition, we provide detailed user documentation and best-practice guides to support configuration and day-to-day operations. Our enablement programmes are designed to accelerate ROI, build confidence across roles, and ensure compliance with UK Government Cloud Security Principles.
This blended approach, combining technical precision, human-centric training, and change management, empowers organisations to maximise the value of Calabrio ONE from day one. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Swagger/OpenAPI specification for interactive API exploration
- Postman collections for quick API testing and integration
- Markdown files for lightweight developer documentation
- JSON examples for API request and response payloads
- YAML configuration samples for deployment and integration
- Developer portal with searchable guides and tutorials
- Knowledge base articles for troubleshooting and FAQs
- Code snippets in multiple languages for API usage
- Video tutorials for setup and feature demonstrations
- Interactive sandbox environment for live API testing
- End-of-contract data extraction
-
When the contract ends, users can extract their data through secure export options provided by Calabrio. Administrators can download all relevant data, including schedules, forecasts, reports, and historical interaction records, in standard formats such as CSV or XML. API endpoints are also available for automated data retrieval before service termination.
Calabrio ensures that data extraction is straightforward and does not require proprietary tools. Customers retain full control over timing and scope of exports, and support is available to assist with bulk downloads or structured exports. After extraction, data is removed from Calabrio systems in accordance with GDPR and contractual obligations. - End-of-contract process
-
At the end of the contract, Calabrio provides support for service termination and data extraction. Included in the contract price are secure data export options, account deactivation, and guidance on transitioning to alternative solutions. Customers can download all historical data in standard formats (CSV, XML) or use API endpoints for automated retrieval.
Additional costs may apply for extended access beyond the termination date, custom data transformation, or professional services such as migration assistance and bespoke reporting. After data extraction, Calabrio ensures complete removal of customer data from its systems in compliance with GDPR and contractual obligations. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Calabrio ONE offers full functionality on both mobile and desktop platforms. The mobile app focuses on quick access to schedules, shift bidding, and performance dashboards, enabling agents to manage tasks on the go. Desktop provides advanced configuration, detailed analytics, and administrative controls for supervisors. Both ensure secure access and real-time data synchronisation.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- The TTEC Digital web-based customer self-service support portal is accessed through redemption of a secure invitation code sent directly to authorised personnel within the client business. Once registered, clients can open new support cases, and view existing support cases, priority, status, assigned contacts, case owners, date of creation and any updates provided by the TTEC Digital support engineering team.
- Accessibility standards
- EN 301 549
- Accessibility testing
- Calabrio has conducted accessibility testing to ensure usability for individuals relying on assistive technologies. The platform includes the Accessible Contact Evaluator (ACE), a screen-reader-friendly interface optimised for JAWS and compatible with other screen readers. ACE supports keyboard navigation and shortcuts, enabling evaluators with low vision to play and assess interactions effectively. Testing focused on compliance with WCAG standards, validating features such as semantic structure, ARIA roles, and alternative text for non-visual elements. Additionally, usability checks were performed to confirm smooth navigation, accurate playback controls, and filter functionality for screen reader users. These measures ensure an inclusive experience across desktop and mobile environments.
- API
- Yes
- What users can and can't do using the API
-
Set up via API:
Calabrio ONE provides open, secure APIs to bootstrap integrations with CRM/HRIS/CCaaS/ERP systems and to configure data exports. Organisations can enable near real time and batch connectors, and create secure data pipelines from the Insights data lake to destinations such as Amazon S3 with manifest files for auditability. Datamart access and database views support external BI tools. All traffic is encrypted and aligned to GDPR/UK Government Cloud Security Principles.
Make changes via API:
Teams can automate WFM workflows (e.g., schedule updates, adherence alerts) and trigger international SMS notifications; two-way messaging lets agents confirm shifts or respond to changes programmatically. API endpoints support updating integrations and exporting historical datasets for analytics or reporting without UI intervention.
Limitations:
API usage focuses on integration, data movement, and workflow messaging rather than full tenant administration; certain configuration tasks (e.g., identity/SSO, core platform provisioning) are handled via console or professional services. Data exports follow supported patterns (data lake/Datamart/views) and require compliant destinations; rate limits and security constraints apply. International SMS depends on approved aggregators and local regulations; opt in/opt out must be enforced.
For sensitive identity and security setup (SAML/SSL, FIPS), customers should use platform configuration and implementation services rather than APIs. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
1. What can be customised:
Users can tailor their SandcastleCX™ environment to match specific CX use cases, technology platforms (e.g., Calabrio, Genesys, AWS, Microsoft, Salesforce and NiCE), integrations, and features such as voice routing, CRM connectors, bots, and reporting dashboards.
2. How users can customise:
Customisation is achieved through a guided, hands-on sandbox experience. TTEC Digital CX architects configure the environment based on client requirements, enabling iterative testing of workflows, integrations, and advanced capabilities. Optional add-ons like Learning and Performance Management or IP solutions can extend functionality.
3. Who can customise:
Authorised client stakeholders, typically CX leaders, IT teams, and solution architects, collaborate with TTEC Digital experts to define priorities and adjust configurations during the trial period.
Scaling
- Independence of resources
- Calabrio guarantees performance through a multi-tenant, cloud-native architecture with strict resource isolation. Each customer environment is logically separated, ensuring workloads do not impact others. Auto-scaling and load balancing maintain consistent service levels during peak demand. Continuous monitoring and proactive capacity management prevent performance degradation, delivering reliable uptime and responsiveness.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Calabrio provides detailed service metrics to monitor performance and usage. Metrics include system uptime and availability, API response times, data processing speed, and user activity logs. Workforce-specific metrics cover schedule adherence, forecast accuracy, and agent performance indicators. Reports are accessible via dashboards and exportable in standard formats for analysis.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- TTEC Digital: Genesys, Microsoft, Google, Calabrio, Shelf, ServiceNow – ttecdigital.com/services
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- We protect data at rest using AES-256 encryption across all storage layers, including databases, backups, and file systems. Encryption keys are managed through secure key vaults with strict rotation and access controls. Data is further safeguarded by role-based access permissions, ensuring only authorised personnel can retrieve sensitive information. Storage systems are hardened with disk-level encryption, and redundant copies are maintained in secure, geographically distributed environments. Regular integrity checks, vulnerability scans, and compliance audits (ISO 27001, SOC 2) ensure ongoing protection. These measures collectively guarantee confidentiality and resilience for all stored data.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data through secure options provided by Calabrio. Administrators can download historical data, schedules, and reports in standard formats such as CSV or XML directly from the platform. Additionally, API endpoints allow automated data extraction for integration or bulk retrieval. Secure transfer methods (HTTPS or SFTP) are supported.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML for structured data exchange and system integration
- JSON for API-driven data retrieval and interoperability
- YAML for configuration and structured export scenarios
- TXT for plain text data representation and logs
- Excel XLSX for tabular reporting and analysis
- HTML for formatted reports and browser-based viewing
- PDF for static archival and compliance documentation
- SQL dump for database migration and backup purposes
- Markdown for lightweight documentation and structured notes
- ZIP archive for bulk export of multiple data files
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- XML for structured data and system integration
- JSON for API-driven imports and interoperability
- YAML for configuration and structured data uploads
- TXT for plain text data and logs
- Excel XLSX for tabular data and scheduling
- HTML for formatted content and structured imports
- PDF for static documents and compliance uploads
- SQL dump for database migration and bulk data
- Markdown for lightweight documentation and structured notes
- ZIP archive for bulk upload of multiple files
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- In addition to TLS 1.2 or above, Calabrio enforces HTTPS with strong cipher suites and mutual authentication options for secure communication. Data integrity is maintained through certificate-based validation and strict session management. Optional IPsec or TLS VPN tunnels can be configured for enhanced security. Legacy protocols are disabled to ensure compliance with NCSC standards.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- We safeguard data within our network using segmentation and encryption at rest. Sensitive information is stored in encrypted databases using AES-256, and keys are managed through secure vaults with strict rotation policies. Access is controlled via role-based permissions and enforced through multi-factor authentication. Network traffic is monitored by intrusion detection and prevention systems, while firewalls and micro-segmentation limit lateral movement. Regular vulnerability scans and penetration tests ensure compliance with ISO 27001 and SOC 2 standards. These layered controls maintain confidentiality, integrity, and availability across all internal systems.
Availability and resilience
- Guaranteed availability
-
Calabrio guarantees 99.9% service availability as part of its SLA, excluding scheduled maintenance windows. Availability is monitored continuously, and performance metrics are shared via dashboards and reports. If availability falls below the guaranteed level, customers are eligible for service credits as outlined in the contract. Credits are calculated based on the duration and severity of the outage and applied to future invoices.
Calabrio’s cloud-native architecture uses redundant systems, load balancing, and automatic failover to maintain uptime. Disaster recovery and high-availability measures ensure resilience across multiple data centres. These commitments align with ISO 27001 and industry best practices for reliability. - Approach to resilience
-
Calabrio ONE is architected for high availability and fault tolerance. The service leverages a distributed, multi-tier architecture with redundancy at every critical layer, including application servers, databases, and storage. Automated failover mechanisms and load balancing ensure continuity during component failures or maintenance.
Data is replicated across geographically separate datacentres to mitigate risks from localised outages. Each datacentre is designed with resilient power, cooling, and network connectivity, and operates under strict physical and logical security controls. Disaster recovery plans include regular backups, tested restoration procedures, and defined recovery time objectives (RTO) and recovery point objectives (RPO).
Our infrastructure is monitored 24/7, with proactive alerting and incident response to maintain service integrity. Detailed datacentre resilience specifications are available upon request to authorised parties. - Outage reporting
-
Public Dashboard:
Calabrio provides a real-time public status dashboard that displays system health, outage notifications, and maintenance schedules. Users can view current incidents and historical uptime metrics at any time.
API:
An API is available for customers to integrate outage and status information into their internal monitoring tools. This allows automated alerts and reporting within existing systems.
Email Alerts:
Designated contacts receive email notifications for critical incidents, planned maintenance, and service restoration updates. Alerts include incident details, estimated resolution times, and progress updates.
Additional Details:
Customers can subscribe to notifications and customise alert preferences. These measures ensure transparency and timely communication during service disruptions.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- We authenticate users through secure, multi-layered controls. Access begins with username and password validation, enforced by strong complexity and rotation policies. We support Multi-Factor Authentication (MFA) using one-time codes or authenticator apps to prevent unauthorized access. For enterprise customers, Single Sign-On (SSO) via SAML 2.0 or OAuth integrates with identity providers like Azure AD. All sessions use TLS encryption and token-based authentication to maintain confidentiality. Role-based access controls ensure users only access resources aligned with their permissions. These measures collectively provide strong identity assurance and compliance with ISO 27001 and SOC 2 standards.
- Access restrictions in management interfaces and support channels
-
Access Restrictions:
Administrative access is limited to authorised personnel using role-based permissions and least-privilege principles.
Authentication:
All access requires multi-factor authentication (MFA) and secure VPN connections for remote sessions.
Session Security:
Interfaces are protected by TLS encryption, session timeouts, and continuous monitoring for anomalies.
Support Channels:
Customer support interactions are authenticated, logged, and conducted through secure portals. Sensitive actions require identity verification and approval workflows.
These measures ensure only verified users can manage or support services securely. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
PCI DSS Level 1
SOC 2 Type 2
HIPAA
Cyber Essentials
Cyber Essentials Plus - Information security policies and processes
-
TTEC's Global Information Security (GIS) reports to the VP and Chief Security Officer. The GIS department is within TTEC’s Security, Resiliency and Governance organisation, reporting to TTEC's Chief Information Officer.
TTEC’s robust Global Privacy, Risk, Compliance, Network, and InfoSec programmes are based on the guiding principles of: Availability; Integrity; and Confidentiality. These principles are achieved through defined policies, industry controls, with infosec and privacy trainings, and through the governance structure within our corporate GIS, IT, Legal and Risk Executives.
TTEC’s policies/procedures comply with ISO 27002 compliance framework that standardise the following security elements:
•InfoSec Policy & Organisational Measures
•Asset/Data Classification
•Human Resource Security- Corrective Actions
•Physical/Environment Security
•Communication/Operation Management
•Access/Authentication/Password Management
•Data Encryption
•InfoSec Acquisition Development/Maintenance
•Endpoint Security
•Auditing, Logging, Monitoring
•Vulnerability, Penetration, Patch Management
•Network Security, Configuration Management
•Applications, SDLC, Change Management
•Incident Response Management
•Security, Fraud, Ethics Code Training- Accountability
•BCP/DR
•Global IT/Risk Management
•Regulatory Compliance
TTEC performs periodic and annual, internal, and external independent, third party, qualified, industry compliance audits of the TTEC organisational controls and technology environments. TTEC continues to achieve ongoing industry compliance accreditation with PCI DSS (SL-1), ISO 27001, SOC 2 Type II (SSAE 18), Cyber Essentials Basic & Plus, and more. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Component Tracking:
All service components are tracked throughout their lifecycle using a Configuration Management Database (CMDB). Each asset is assigned a unique identifier, with version history and dependencies recorded to maintain visibility and integrity.
Change Assessment:
Changes follow a formal Change Advisory Board (CAB) process. Every modification undergoes risk and security impact analysis, including vulnerability checks and compliance validation. Approved changes are implemented with rollback plans and logged for audit purposes. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Threat Assessment:
We continuously monitor for vulnerabilities using automated scanning tools and perform risk-based analysis to assess potential threats to services.
Patch Deployment:
Critical patches are deployed within 24 hours, while high and medium-risk updates follow defined SLAs to ensure timely remediation.
Threat Intelligence Sources:
We leverage vendor advisories, CVE databases, CSA alerts, and threat intelligence feeds from trusted security partners to stay ahead of emerging risks. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Identifying Potential Compromises:
We use SIEM tools and real-time log analysis to detect anomalies, unauthorised access attempts, and suspicious patterns. Alerts are generated for predefined indicators of compromise.
Responding to Potential Compromises:
Incidents trigger an automated containment workflow, followed by manual investigation. Actions include isolating affected systems, revoking credentials, and applying patches.
Response Time:
Our Security Operations Centre (SOC) operates 24/7, with initial response within 15 minutes of detection and full remediation initiated immediately per severity level. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Pre-Defined Processes:
We maintain documented playbooks for common incidents, including service outages, security breaches, and performance degradation. These processes ensure rapid, consistent response.
User Reporting:
Users can report incidents via 24/7 support channels, including a dedicated portal, email, and phone hotline. Automated alerts also trigger internal escalation.
Incident Reports:
We provide detailed post-incident reports outlining root cause, impact, and corrective actions. Reports are shared through secure channels and archived for compliance. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- SandcastleCX™ provides a secure, customised sandbox for testing and exploring CX technologies, including CCaaS, CRM, AI, and analytics. It offers expert guidance, platform validation, and flexible trial access at no cost for standard use cases. Ideal for innovation and proof-of-concept projects, enabling rapid evaluation without production risk.
- Link to free trial
- https://youtu.be/hNmqTiNkIx8?si=9cRF7IADXikWKBm7
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.2%
- Between £500,001 and £1,000,000
- 4.2%
- Between £1,000,001 and £2,500,000
- 6.2%
- Between £2,500,001 and £5,000,000
- 8.2%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Coalfire Certification, Inc.
- ISO/IEC 27001 accreditation date
- Thursday 21 August 2025
- What the ISO/IEC 27001 doesn’t cover
- Certification available on request.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- PCI Security Standards Council
- PCI DSS accreditation date
- Friday 28 November 2025
- What the PCI DSS doesn’t cover
- Certification available on request.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2807b81c-9543-492c-805b-f1fd3347313f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 613c9a41-2540-4e86-811e-d9808a365c26
- Other security certifications
- Yes
- Any other security certifications
-
- SOC 2, Type II
- HIPAA
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Content of the outreach activity is designed to suit the target cohort
-