Yay.com - Hosted VoIP Telephony System For Customer Service
Yay.com is a leading provider of hosted VoIP phone systems. Our feature-rich 'Cloud PBX' includes Call Recording, Smart Queuing and more. With easy online Dashboard management and simple deployment through intuitive desktop/smartphone/web apps. We are the ideal cost-effective solution when updating telephony systems, enhancing productivity or seeking secure, robust telecoms.
Features
- Fully customisable call routing, IVR menus, auto-attendants and call handling
- Keep existing phone numbers, or choose new local/non-geographic numbers
- Complete online admin portal for easy configuration, roles and permissions
- Choose from unlimited calls or PAYG plans with free minutes.
- Flexibility to handle calls on deskphones and smartphone/desktop via apps
- CRM integration, auto phone setup, and phonebook management
- Real-time reporting, wallboard statistics. call queuing, call screening and blocking
- Remote collaboration via conference bridges and voice calling
- Call recording and monitoring for compliance, training and auditing purposes
- Extensive call logs, BLF presence indication and voicemail to email/transcription
Benefits
- Reduces costs substantially, enabling increased savings
- Fully scalable solution - Easily add numbers, extensions and users
- Instant set-up with no installation wait times or maintenance fees
- Helps increase workforce productivity, agility and efficiency
- Enhances caller satisfaction through professional enterprise call features
- Empowers distributed workforces and easily facilitates remote and home working
- Competitive call costs, with better than landline HD call quality
- Reduces complexity via intuitive management and a robust easy-to-master system
- Effortlessly create bespoke call routes to multiple devices or locations
- Knowledgeable experts on-hand for support and advice
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 3 9 7 7 0 1 9 7 9 7 1 2 6 9
Contact
Yay.com
Jez Pickering
Telephone: 0330 122 6095
Email: operations@yay.com
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Contact centre
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- None
- System requirements
-
- Internet Access or a Cellular Data Connection
- A VoIP compatible device eg. VoIP phone, smartphone, desktop computer/laptop
User support
- Email or online ticketing support
- Yes
- Support response times
- Support operating hours are between 07:00am - 22:00pm UK time, Monday - Friday. During these periods, calls are answered on average, in under 60 seconds, with support-related emails responded to within a maximum of 4 hours of receipt.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Our Network Operations Centre operates 24/7, 365 days a year, continually monitoring our platform for any issues or faults that could arise.
We offer comprehensive and unrestricted support where all support enquiries are treated equally with the respect, discretion and urgency they deserve. Operating between 07:00am and 22:00pm, Monday to Friday, tickets can be raised via phone, email or the contact form on the Yay.com website.
A technical account manager will be assigned to accounts and is accessible to should any queries arise. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
While we give our customers all the tools to create and deploy their telephony system themselves, our teams are on hand to facilitate and assist any business that needs the security and reassurance.
Over-the-phone walkthroughs, individual training and introductions are available, as well as bi-weekly webinars and FAQs that can be sourced at any time from the Yay.com website. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Users can extract their data via an email request from an authorised administrator of the account. User configurations, phonebooks and call histories can be exported in CSV file format.
- End-of-contract process
-
Users, phone numbers, calling minutes are included in the price of the plan. This pricing will change depending the plan chosen as well number of users, phone numbers and chosen allocation of minutes included with the chosen plan.
At the end of a contract, customers are free to continue for either another year or another month on a rolling basis. Alternatively customers can cancel their plan which can be actioned via the the online Dashboard. Customers are able to move their phone number or number ranges to an alternative provider. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- The Yay.com service is successfully used by thousands of customers around the world on a variety of devices and operating systems. Our online documentation has been designed using appropriate colours, fonts, text and tooltips to allow users to navigate and easily find the information required.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Full management and customisation of accounts is possible through the online Dashboard which is accessible on both desktop and mobile. The mobile version of the Dashboard is optimised for mobile use.
Both the mobile and desktop applications fully support calling, presence and business instant messaging features.
The mobile application is available for Android and iOS operating systems. The desktop application is available for Windows, MacOS and Linux operating systems. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
Our online Dashboard allows complete real-time phone system management of users, phone lines, number configuration and call routing.
Call histories, recordings and analytics can also be managed via the online Dashboard, with accessibility available based on specified role and permission settings. - Accessibility standards
- None or don’t know
- Description of accessibility
-
The Yay.com service is successfully used by thousands of customers around the world on a variety of devices and operating systems.
The Dashboard has been designed using appropriate colours, fonts, text and tooltips to allow users to navigate and manage their business phone systems. - Accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
-
Our API is adaptable and granular, so integrating VoIP into existing offerings is possible through us.
Built by us from the ground-up, out API is accessible first by signing up via our website and creating an API account. Setup requires adding a user's IP address to an allow list. This is to help ensure no unauthenticated persons can make API commands. Once configured a Sandbox access provides an environment to test and become familiar with the platform and its commands.
Changes can be made using REST API requests to create and edit users, phone numbers and call routes, alongside managing call routes, logs and more. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Based on access privileges, from within our online Dashboard, administrators can customise:
Roles and permissions,
User names and extension numbers,
Phone number nicknames for easy identification,
Inbound call routing (including rule-based call destinations and time of day routing and call menus),
Voicemail (mailbox names and greetings),
Audio (including on-hold audio, playlists and text-to-speech,
Per user call recording),
Presence settings (including DND and instant messaging statuses),
Caller IDs (based on authorised numbers owned),
Call queue availability,
Wallboard analytics,
Custom phonebooks (with password protection),
Editable shortcodes to map functions to keypad combinations.
Scaling
- Independence of resources
- Our platform effectively and efficiently load balances traffic dynamically across data centres across the world to ensure optimum call quality at all times, for all customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
- Answered calls
- Missed calls
- Abandoned calls
- Inbound/Outbound/Internal call breakdown
- Call durations
- Maximum wait times
- Maximum call times
- Average wait times
- Average call times
- Callers in queue
- Active calls
- Unanswered calls
- Total calls (within specified time periods) - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Users can extract their data via an email request from an authorised administrator of the account. User configurations, phonebooks and call histories can be exported in CSV file format from within the online Dashboard.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- An SLA is not included as standard with a plan, but bespoke SLA arrangements can be discussed on request.
- Approach to resilience
-
Our service and platform is dynamically load balanced and distributed across multiple services. Designed for resiliance, reliability and scalability, dynamic failovers ensure our infrastructure automatically responds to mitigate any platform-wide risks in real-time.
In addition, our Network Operations Centre operates 24/7, 365 days a year, continually monitoring our platform to further reinforce our infrastructure.
In the event that the end-user has an Internet connection failure, failover setup is available to forward calls to an alternative off-platform phone number, or a voicemail mailbox.
By leveraging Google Cloud Platform’s globally distributed infrastructure and redundant, high-availability zones, our solution ensures continuous uptime and rapid disaster recovery, minimizing service disruptions even in the event of regional outages.
Further information regarding our platform resilience is available on request. - Outage reporting
- A publically accessible status page is available for real-time service reports, along with manual communication to affected users during and after incidents as necessary.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access management processes are in place that meet the requirements of ISO27001. All access is regulated by the role-based access control (RBAC) method, based on the Principle of Least Privilege. Controls are in place for joiners, leavers, role/access changes. Internal audits are undertaken periodically.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Our Information Security Management System (ISMS) is certified to ISO27001:2022 standards and includes policies and processes for organisational controls (such a management's commitment to Information Security, responsibilities, our main InfoSec Policies, resource management, monitoring & improvement, etc), people controls (awareness, education training, checks, etc), physical controls and technological controls (malware protection, data masking, information deletion, etc). All these controls are based around risk assessments specific to Yay's platform/systems, people and location. Our ISMS policies/processes cover topics such as: Data Back-Up, Data Breach, Pen Testing, IT Systems Monitoring, Asset Management, Incident Response, IT Acceptable Use, Ethical AI Use, Cloud Computing, etc. Each process has a clear owner and reporting steps to be followed where necessary. These are further detailed in the Responsibilities section of our IMS Manual and shared with all staff. Each relevant policy is reviewed at least annually and processes are assessed on an on-going basis. All major updates are communicated to staff and all latest versions of policies are available on our HR system to all staff.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Changes may be required in response to a significant problem, a planned improvement or in response to some other internal or external requirement. Changes must be planned and reviewed with consideration of any impact the change could have on identified risks or any new risks that might result from the change.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We use our Information Security Risk Register to monitor threat intelligence. Our source of threat intelligence include Internal Audits, Identified Malware, Threat Reports from Anti-malware, Internet Security systems and a variety of External Sources of threat Information (European Union Agency for Cybersecurity, UK National Cyber Security Centre, SANA internet storm center, Cisco Talos Intelligence group, Spamhaus Project etc). Testing of a Vulnerable Product Release is performed when at public restricted preview platform, before release; testing of Vulnerable Network infrastructure changes is performed immediately following change. Routine scans are performed and reviewed quarterly.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We proactively monitor the platform 24/7, 365 days a year to assess and reinforce our infrastructure about any potential system vulnerabilities. Our vulnerability management process is structured in four phases: Identificy, Evaluate, Address, Improve.
Any potential compromises are immediately reported to the Head of Engineering and NOC team who assess the urgency and category as per our Incident Response Policy (immediate, high, moderate or routine).
Patches would be deployed immediately upon realisation of system-critical threats, and the service would be resumed as soon as possible. Patches are routinely installed to improve the platform. - Incident management type
- Supplier-defined controls
- Incident management approach
- Our predefined processes are all detailed in our Incident Response Policy and includes drafted communication for common events. Users report incidents by contacting customer support or raising a ticket. The team looks at what feature(s) or component(s) are affected and how many customers are affected; it is then escalated according to the determined urgency. Reports are sent every 30min to SLT during the incident management and a status update is shared on our website and updated for users. The report is reviewed by those responsible per the Incident Response Policy and must be approved before sharing externally with users.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
We offer a free 14 day trial of our service, with access to the features provided on the highest level Yay.com plan.
The free trial includes 3 users, a phone number and 5 minutes daily calling with which to test and sample the service. - Link to free trial
- https://www.yay.com/voip/try-free/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 45%
- Between £250,000 and £500,000
- 50%
- Between £500,001 and £1,000,000
- 55%
- Between £1,000,001 and £2,500,000
- 60%
- Between £2,500,001 and £5,000,000
- 60%
- Over £5,000,001
- 60%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- URS Holdings
- ISO/IEC 27001 accreditation date
- Saturday 10 January 2026
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 9705c9c5-67e0-46dd-816c-2e5594cf5c83
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
-