Skip to main content

Help us improve the Digital Marketplace - send your feedback

Yay.com

Yay.com - Hosted VoIP Telephony System For Customer Service

Yay.com is a leading provider of hosted VoIP phone systems. Our feature-rich 'Cloud PBX' includes Call Recording, Smart Queuing and more. With easy online Dashboard management and simple deployment through intuitive desktop/smartphone/web apps. We are the ideal cost-effective solution when updating telephony systems, enhancing productivity or seeking secure, robust telecoms.

Features

  • Fully customisable call routing, IVR menus, auto-attendants and call handling
  • Keep existing phone numbers, or choose new local/non-geographic numbers
  • Complete online admin portal for easy configuration, roles and permissions
  • Choose from unlimited calls or PAYG plans with free minutes.
  • Flexibility to handle calls on deskphones and smartphone/desktop via apps
  • CRM integration, auto phone setup, and phonebook management
  • Real-time reporting, wallboard statistics. call queuing, call screening and blocking
  • Remote collaboration via conference bridges and voice calling
  • Call recording and monitoring for compliance, training and auditing purposes
  • Extensive call logs, BLF presence indication and voicemail to email/transcription

Benefits

  • Reduces costs substantially, enabling increased savings
  • Fully scalable solution - Easily add numbers, extensions and users
  • Instant set-up with no installation wait times or maintenance fees
  • Helps increase workforce productivity, agility and efficiency
  • Enhances caller satisfaction through professional enterprise call features
  • Empowers distributed workforces and easily facilitates remote and home working
  • Competitive call costs, with better than landline HD call quality
  • Reduces complexity via intuitive management and a robust easy-to-master system
  • Effortlessly create bespoke call routes to multiple devices or locations
  • Knowledgeable experts on-hand for support and advice

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at operations@yay.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 3 9 7 7 0 1 9 7 9 7 1 2 6 9

Contact

Yay.com Jez Pickering
Telephone: 0330 122 6095
Email: operations@yay.com

About your service

Service categories

Applications

Customer relationship management

  • Customer service
  • Contact centre
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
None
System requirements
  • Internet Access or a Cellular Data Connection
  • A VoIP compatible device eg. VoIP phone, smartphone, desktop computer/laptop

User support

Email or online ticketing support
Yes
Support response times
Support operating hours are between 07:00am - 22:00pm UK time, Monday - Friday. During these periods, calls are answered on average, in under 60 seconds, with support-related emails responded to within a maximum of 4 hours of receipt.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Our Network Operations Centre operates 24/7, 365 days a year, continually monitoring our platform for any issues or faults that could arise.

We offer comprehensive and unrestricted support where all support enquiries are treated equally with the respect, discretion and urgency they deserve. Operating between 07:00am and 22:00pm, Monday to Friday, tickets can be raised via phone, email or the contact form on the Yay.com website.

A technical account manager will be assigned to accounts and is accessible to should any queries arise.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
While we give our customers all the tools to create and deploy their telephony system themselves, our teams are on hand to facilitate and assist any business that needs the security and reassurance.

Over-the-phone walkthroughs, individual training and introductions are available, as well as bi-weekly webinars and FAQs that can be sourced at any time from the Yay.com website.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Users can extract their data via an email request from an authorised administrator of the account. User configurations, phonebooks and call histories can be exported in CSV file format.
End-of-contract process
Users, phone numbers, calling minutes are included in the price of the plan. This pricing will change depending the plan chosen as well number of users, phone numbers and chosen allocation of minutes included with the chosen plan.

At the end of a contract, customers are free to continue for either another year or another month on a rolling basis. Alternatively customers can cancel their plan which can be actioned via the the online Dashboard. Customers are able to move their phone number or number ranges to an alternative provider.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
The Yay.com service is successfully used by thousands of customers around the world on a variety of devices and operating systems. Our online documentation has been designed using appropriate colours, fonts, text and tooltips to allow users to navigate and easily find the information required.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Full management and customisation of accounts is possible through the online Dashboard which is accessible on both desktop and mobile. The mobile version of the Dashboard is optimised for mobile use.

Both the mobile and desktop applications fully support calling, presence and business instant messaging features.

The mobile application is available for Android and iOS operating systems. The desktop application is available for Windows, MacOS and Linux operating systems.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Our online Dashboard allows complete real-time phone system management of users, phone lines, number configuration and call routing.

Call histories, recordings and analytics can also be managed via the online Dashboard, with accessibility available based on specified role and permission settings.
Accessibility standards
None or don’t know
Description of accessibility
The Yay.com service is successfully used by thousands of customers around the world on a variety of devices and operating systems.

The Dashboard has been designed using appropriate colours, fonts, text and tooltips to allow users to navigate and manage their business phone systems.
Accessibility testing
None
API
Yes
What users can and can't do using the API
Our API is adaptable and granular, so integrating VoIP into existing offerings is possible through us.

Built by us from the ground-up, out API is accessible first by signing up via our website and creating an API account. Setup requires adding a user's IP address to an allow list. This is to help ensure no unauthenticated persons can make API commands. Once configured a Sandbox access provides an environment to test and become familiar with the platform and its commands.

Changes can be made using REST API requests to create and edit users, phone numbers and call routes, alongside managing call routes, logs and more.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Based on access privileges, from within our online Dashboard, administrators can customise:
Roles and permissions,
User names and extension numbers,
Phone number nicknames for easy identification,
Inbound call routing (including rule-based call destinations and time of day routing and call menus),
Voicemail (mailbox names and greetings),
Audio (including on-hold audio, playlists and text-to-speech,
Per user call recording),
Presence settings (including DND and instant messaging statuses),
Caller IDs (based on authorised numbers owned),
Call queue availability,
Wallboard analytics,
Custom phonebooks (with password protection),
Editable shortcodes to map functions to keypad combinations.

Scaling

Independence of resources
Our platform effectively and efficiently load balances traffic dynamically across data centres across the world to ensure optimum call quality at all times, for all customers.

Analytics

Service usage metrics
Yes
Metrics types
- Answered calls
- Missed calls
- Abandoned calls
- Inbound/Outbound/Internal call breakdown
- Call durations
- Maximum wait times
- Maximum call times
- Average wait times
- Average call times
- Callers in queue
- Active calls
- Unanswered calls
- Total calls (within specified time periods)
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Users can extract their data via an email request from an authorised administrator of the account. User configurations, phonebooks and call histories can be exported in CSV file format from within the online Dashboard.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
An SLA is not included as standard with a plan, but bespoke SLA arrangements can be discussed on request.
Approach to resilience
Our service and platform is dynamically load balanced and distributed across multiple services. Designed for resiliance, reliability and scalability, dynamic failovers ensure our infrastructure automatically responds to mitigate any platform-wide risks in real-time.

In addition, our Network Operations Centre operates 24/7, 365 days a year, continually monitoring our platform to further reinforce our infrastructure.

In the event that the end-user has an Internet connection failure, failover setup is available to forward calls to an alternative off-platform phone number, or a voicemail mailbox.

By leveraging Google Cloud Platform’s globally distributed infrastructure and redundant, high-availability zones, our solution ensures continuous uptime and rapid disaster recovery, minimizing service disruptions even in the event of regional outages.

Further information regarding our platform resilience is available on request.
Outage reporting
A publically accessible status page is available for real-time service reports, along with manual communication to affected users during and after incidents as necessary.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access management processes are in place that meet the requirements of ISO27001. All access is regulated by the role-based access control (RBAC) method, based on the Principle of Least Privilege. Controls are in place for joiners, leavers, role/access changes. Internal audits are undertaken periodically.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Our Information Security Management System (ISMS) is certified to ISO27001:2022 standards and includes policies and processes for organisational controls (such a management's commitment to Information Security, responsibilities, our main InfoSec Policies, resource management, monitoring & improvement, etc), people controls (awareness, education training, checks, etc), physical controls and technological controls (malware protection, data masking, information deletion, etc). All these controls are based around risk assessments specific to Yay's platform/systems, people and location. Our ISMS policies/processes cover topics such as: Data Back-Up, Data Breach, Pen Testing, IT Systems Monitoring, Asset Management, Incident Response, IT Acceptable Use, Ethical AI Use, Cloud Computing, etc. Each process has a clear owner and reporting steps to be followed where necessary. These are further detailed in the Responsibilities section of our IMS Manual and shared with all staff. Each relevant policy is reviewed at least annually and processes are assessed on an on-going basis. All major updates are communicated to staff and all latest versions of policies are available on our HR system to all staff.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Changes may be required in response to a significant problem, a planned improvement or in response to some other internal or external requirement. Changes must be planned and reviewed with consideration of any impact the change could have on identified risks or any new risks that might result from the change.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We use our Information Security Risk Register to monitor threat intelligence. Our source of threat intelligence include Internal Audits, Identified Malware, Threat Reports from Anti-malware, Internet Security systems and a variety of External Sources of threat Information (European Union Agency for Cybersecurity, UK National Cyber Security Centre, SANA internet storm center, Cisco Talos Intelligence group, Spamhaus Project etc). Testing of a Vulnerable Product Release is performed when at public restricted preview platform, before release; testing of Vulnerable Network infrastructure changes is performed immediately following change. Routine scans are performed and reviewed quarterly.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We proactively monitor the platform 24/7, 365 days a year to assess and reinforce our infrastructure about any potential system vulnerabilities. Our vulnerability management process is structured in four phases: Identificy, Evaluate, Address, Improve.

Any potential compromises are immediately reported to the Head of Engineering and NOC team who assess the urgency and category as per our Incident Response Policy (immediate, high, moderate or routine).

Patches would be deployed immediately upon realisation of system-critical threats, and the service would be resumed as soon as possible. Patches are routinely installed to improve the platform.
Incident management type
Supplier-defined controls
Incident management approach
Our predefined processes are all detailed in our Incident Response Policy and includes drafted communication for common events. Users report incidents by contacting customer support or raising a ticket. The team looks at what feature(s) or component(s) are affected and how many customers are affected; it is then escalated according to the determined urgency. Reports are sent every 30min to SLT during the incident management and a status update is shared on our website and updated for users. The report is reviewed by those responsible per the Incident Response Policy and must be approved before sharing externally with users.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We offer a free 14 day trial of our service, with access to the features provided on the highest level Yay.com plan.

The free trial includes 3 users, a phone number and 5 minutes daily calling with which to test and sample the service.
Link to free trial
https://www.yay.com/voip/try-free/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
45%
Between £250,000 and £500,000
50%
Between £500,001 and £1,000,000
55%
Between £1,000,001 and £2,500,000
60%
Between £2,500,001 and £5,000,000
60%
Over £5,000,001
60%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
URS Holdings
ISO/IEC 27001 accreditation date
Saturday 10 January 2026
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
9705c9c5-67e0-46dd-816c-2e5594cf5c83
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at operations@yay.com. Tell them what format you need. It will help if you say what assistive technology you use.