Skip to main content

Help us improve the Digital Marketplace - send your feedback

OPUS BUSINESS SYSTEMS LIMITED

Five9 Contact Centre as a Service (CCaaS)

Five9 delivers a cloud-based contact centre platform that powers voice, digital, and AI-driven customer engagement. It enables intelligent routing, automation, analytics, workforce optimisation, and seamless CRM integration, helping businesses improve customer experience, boost agent productivity, scale operations globally, and gain actionable insights in real time across channels securely and reliably.

Features

  • Omnichannel engagement seamless routing across voice, chat, email, SMS, social.
  • AI capabilities AI-powered IVR, virtual agents, analytics, real-time agent assistance.
  • Smart routing skills-based routing using customer data and real-time context.
  • Cloud architecture cloud-native platform enabling rapid, secure, global scalability.
  • Workforce optimisation forecasting, scheduling, quality management, performance analytics.
  • Analytics & reporting realtime dashboards and historical operational insights.
  • CRM integrations integrates with Salesforce, ServiceNow, Zendesk, Microsoft Teams.
  • Remote agents secure support for hybrid and distributed workforces.
  • Reliability & security high availability with enterprise-grade security and compliance.
  • Outbound dialling automated dialling for sales, service, collections efficiency.

Benefits

  • Cloud-based scalability instantly scales without hardware or infrastructure complexity
  • Omnichannel engagement manages voice, chat, email, SMS, social centrally
  • AI-powered automation automates routing, IVR, analytics, agent assistance
  • Intelligent call routing connects customers to best agents faster
  • Workforce optimisation improves scheduling, quality management, performance tracking
  • Advanced analytics real-time insights into performance and customer behaviour
  • CRM integrations integrates seamlessly with leading CRM and business tools
  • Remote agent support enables secure remote and hybrid workforces
  • High reliability security enterprise-grade uptime, compliance, data protection
  • Enhanced customer experience faster resolutions, personalised service, higher satisfaction

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bid@opustech.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 9 7 0 0 7 9 1 1 7 0 8 1 2 4

Contact

OPUS BUSINESS SYSTEMS LIMITED Jenny Critchfield
Telephone: 02085457121
Email: bid@opustech.co.uk

About your service

Service categories

Applications

Collaborative

  • Enterprise community
  • Team collaboration
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Our service extends Five9 CCaaS by enhancing conversational AI, intelligent automation, analytics, and integration capabilities. It complements core contact centre functions with advanced NLP, workflow orchestration, CRM and business system integrations, and actionable insights to improve self-service, agent efficiency, and overall customer experience.
Cloud deployment model
Public cloud
Service constraints
Our service depends on Five9 CCaaS availability and configuration, so performance is influenced by Five9 platform limits, APIs, and regional support. Advanced features require proper data quality, integration setup, and ongoing tuning. Buyers should also plan for change management, agent training, and compliance alignment with their industry and geographic regulations.
System requirements
  • Web browser – Latest Chrome, Edge, or Firefox supported.
  • Operating system – Windows 10/11 or macOS recent versions.
  • Internet connection – Minimum 1 Mbps stable broadband recommended.
  • Headset – USB or 3.5mm compatible noise-cancelling headset.
  • Software licenses – Active Five9 subscription required for agent access.
  • Antivirus – Updated antivirus software for secure operation.
  • Firewall – Configured to allow Five9 cloud ports.
  • Pop-up blockers – Disabled for proper application functionality.
  • Microphone & speakers – Functional for voice communications.
  • Screen resolution – Minimum 1024x768 recommended for agent interface.

User support

Email or online ticketing support
Yes
Support response times
Alongside 24/7 telephone assistance, we provide convenient email support. During core hours (08:30–17:30, Monday–Friday, excluding bank holidays), buyers can report issues to customerservice@opustech.co.uk. On receipt, our Operations Service Desk logs the ticket in our Incident Management System, assigns priority, and sends an automated confirmation with your reference and details. From there, a technician begins triage and investigation, escalating seamlessly through first to fourth line if required. For critical P1 incidents outside core hours, we only accept phone calls so we can engage immediately. Responses adhere strictly to your contracted SLAs and performance targets.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
EN 301 549
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
EN 301 549
Web chat accessibility testing
Opus is currently running formal assistive‑technology user testing on our Service Desk online chat, the platform has been designed with accessibility in mind. Features such as browser‑based access, clear navigation, and compatibility with standard assistive tools (including screen readers and keyboard‑only navigation) support inclusive use. We continually review accessibility requirements and are committed to engaging assistive‑technology users in future testing cycles to further enhance usability and ensure a fully accessible support experience.
Onsite support
Yes, at extra cost
Support levels
Opus provides a flexible, scalable support model designed to meet the operational needs of organisations of all sizes. Core Business Hours Support (08:30–17:30, Monday–Friday) includes incident reporting via telephone, email, portal, or webchat, with all issues logged and prioritised using a P1–P4 severity framework. For customers requiring higher resilience, 24/7 support is available, ensuring rapid engagement for critical P1 faults and seamless escalation through multi‑level engineering teams.

Support can be delivered as Fully Managed or Co‑Managed, with optional services such as monitoring, release and update management, antivirus administration, supplier coordination, and change control. Pricing is fully tailored and based on the number of users and the level of cover required, allowing organisations to select an appropriate package without over‑committing resources.

Every customer benefits from a dedicated Account Director to oversee service delivery and a Solution Architect to ensure technical alignment and design assurance. Service Managers can be added where enhanced governance, regular service reviews, and deeper operational oversight are required. All services are supported by defined SLAs, transparent incident handling, and cloud and telephony expertise to ensure reliable, end‑to‑end performance for business‑critical communications.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
To start using the Five9 service, users first receive login credentials from their administrator and ensure their system meets basic requirements, including a supported browser (Chrome, Edge, or Firefox), stable internet, and a headset. They log in to the Five9 Agent Desktop or Service Console through a browser, configure the softphone if needed, and test microphone and speaker functionality. Users should familiarise themselves with the interface, including tabs for voice, chat, email, SMS, call controls, and queue status. Completing any onboarding tutorials or training helps them understand handling calls, transfers, and logging interactions. Once ready, they set their status to “Available” to begin receiving interactions, using scripts, notes, and CRM integrations to manage customer communications efficiently. Built-in help menus and supervisor support are available if assistance is needed, enabling users to quickly start handling multi-channel customer interactions seamlessly.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
To extract the contract end date in Five9, users typically need access to the account or subscription details through the Five9 Admin Console or support portal.

First, log in with administrator or account-level credentials. Navigate to the Account Settings or Subscription/Contract Management section, where current plan details are stored. Look for fields labelled “Contract Start Date,” “Contract End Date,” or “Subscription Expiry”. If available, these dates are usually displayed in a summary or detailed view.

For organisations using CRM integration, the contract end date may also be stored in the connected CRM system (e.g., Salesforce or ServiceNow), where it can be extracted using reports or queries. Additionally, users can request official contract documentation or invoices from the Five9 billing/support team, which will explicitly list the end date.

For automated access, administrators can use the Five9 APIs to retrieve subscription or contract information programmatically, provided proper authentication and permissions are in place. Always verify the extracted date against official billing or contract records to ensure accuracy.
End-of-contract process
Opus recognises that every partnership may eventually conclude, and we ensure this phase is managed with the same professionalism as all others. Our Exit Management Plan is designed to deliver a smooth, transparent transition that protects both parties—financially, operationally, and reputationally—while maintaining service continuity.

We will work closely with  Buyers to minimise disruption and coordinate a seamless handover. Opus maintains an up-to-date inventory of communication assets and service levels, enabling us to create a tailored exit plan covering phased activities, resource allocation, and responsibilities.

A dedicated Exit Transition Manager from our Professional Services team will oversee the process, coordinating with  the Buyer, suppliers, and internal teams, providing consistent updates through to full contract closure.

The exit plan will define roles and responsibilities, maintain ongoing service until cessation, outline post‑cessation support, detail work‑in‑progress, manage asset return, and ensure full documentation and data transfer. It will also cover phased decommissioning, risk and issue management, knowledge transfer, and regular progress reporting.

By following this structured approach, Opus ensures minimal disruption, clear communication, and a well‑managed, professional conclusion to our partnership.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our onboarding and offboarding documentation is designed to be accessible to all users, including those with disabilities. All materials are provided in digital formats compatible with assistive technologies, such as screen readers, ensuring visually impaired users can navigate and comprehend content effectively. Documents follow a clear, consistent structure with headings, bullet points, and descriptive links to improve readability and navigation. Colour contrasts, font sizes, and spacing are chosen to support users with visual impairments or dyslexia. Alternative text is included for all images, diagrams, and screenshots, allowing users who rely on screen readers to access visual information. Additionally, we provide guidance in plain language to reduce cognitive load and ensure comprehension across a broad audience. For users requiring further accessibility accommodations, such as audio versions or Braille copies, these are made available on request. By combining digital compatibility, structured formatting, descriptive content, and alternative formats, our documentation meets recognised accessibility standards and supports inclusive access throughout the employee lifecycle. This ensures that every team member can successfully engage with onboarding and offboarding processes regardless of ability.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mobile and desktop services differ in interface, functionality, and connectivity. Mobile apps are optimised for small screens and touch, supporting mobility and push notifications, but may limit advanced reporting, admin controls, or integrations. Desktops offer full-featured dashboards, multitasking, and richer tools for complex tasks, with in-app or email alerts. Mobile relies on cellular or Wi-Fi, which can affect call quality, while desktops provide more stable connections. Both platforms complement each other: mobile enables work from anywhere, while desktop maximises productivity for detailed workflows and analytics. Users should choose based on task complexity and mobility needs.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
In the context of a contact centre platform like Five9 (and extensions built on it), the service interface is typically a web-based dashboard or app that allows users to:

Manage calls, chats, and messages across channels
Monitor queues, agent status, and performance metrics
Access reporting and analytics
Configure workflows, routing, and automation
Integrate with CRM or other business systems

It is usually available on desktop browsers and often as a mobile app with optimised functionality for on-the-go access.
Accessibility standards
None or don’t know
Description of accessibility
Our service is accessible via desktop browsers, mobile apps, and integrated APIs. Users can connect from anywhere with an internet-enabled device, accessing calls, chat, and messaging across channels. Accessibility features include keyboard navigation, screen reader support, and responsive design to ensure usability for all agents and supervisors.
Accessibility testing
We have conducted comprehensive interface testing with users of assistive technologies to ensure our service is accessible and inclusive. Testing included screen readers (e.g., JAWS, NVDA, VoiceOver), keyboard-only navigation, and high-contrast mode to verify that all menus, dashboards, chat windows, and notifications are fully operable without a mouse. We engaged real users with visual, auditory, and motor impairments to provide feedback on usability, navigation flow, and content clarity.

Our team also tested mobile and desktop interfaces to ensure consistent accessibility across devices, confirming that touch targets, text scaling, and responsive layouts meet accessibility standards. Forms, alerts, and dialogs were validated for proper focus management and descriptive labelling.

Feedback from these sessions informed interface improvements, including clearer labelling, enhanced ARIA attributes, and simplified workflows for assistive tech users.

All testing was aligned with WCAG 2.1 guidelines and accessibility best practices, ensuring that users relying on assistive technologies can fully access the platform’s features, manage interactions, and monitor performance without barriers, fostering an inclusive and equitable user experience.
API
Yes
What users can and can't do using the API
The API provides users with programmatic access to many core platform functions, enabling automation, integration, and customisation. Users can create, read, update, and manage contacts, call records, chat interactions, and messaging workflows. It supports integration with CRM, analytics tools, and third-party applications, allowing data synchronisation, automated reporting, and event-driven triggers. Users can also initiate calls or messages, retrieve historical interaction data, and manage agent assignments through the API.

However, there are certain limitations. Users cannot directly modify underlying platform infrastructure or system-level configurations via the API, such as server settings, security policies, or platform updates. Advanced features like AI model retraining, internal workflow orchestration, or core routing logic changes are restricted and require access through the main platform interface. Rate limits and authentication requirements apply, and excessive or unauthorised API usage may be throttled.

Overall, the API enables robust integration and automation capabilities while maintaining platform integrity, security, and compliance. Users can extend functionality and streamline operations but must rely on the main platform for administrative, infrastructure, or advanced configuration changes, ensuring controlled and stable system operation.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise the Five9 service to fit their specific business needs through a combination of administrative settings, workflow design, and API integrations. Within the platform, users can configure call routing rules, IVR menus, queues, and skill-based assignments to ensure interactions reach the right agents. Scripts, prompts, and chat flows can be tailored for different channels, including voice, chat, email, SMS, and social messaging.

The platform also supports CRM and third-party system integrations, allowing users to customise data handling, reporting, and agent workflows. Through the API, users can automate tasks, synchronise records, or create custom dashboards and reports. Supervisors can set performance thresholds, alerts, and analytics metrics to match organisational priorities.

For agent experience, users can customise desktop and mobile interfaces, adjusting layout, widgets, and notifications to improve usability. Additionally, features such as skills, schedules, and access permissions can be tailored to team roles.

Overall, Five9 offers a flexible environment where users can adapt routing, automation, reporting, and interfaces to meet business goals and provide a seamless customer experience

Scaling

Independence of resources
Five9 ensures users are unaffected by other tenants’ demand through multi-tenant isolation, elastic cloud infrastructure, and load balancing. Each customer’s data and interactions are logically separated, while resources like CPU, memory, and bandwidth scale automatically to meet demand.

Redundancy and failover ensure traffic is redirected if a node becomes overloaded, and Quality of Service (QoS) prioritises voice traffic for consistent call quality. Continuous monitoring and auto-scaling detect usage spikes, maintaining performance for all users. This combination guarantees reliable, high-quality service regardless of the activity levels of other organisations on the platform.

Analytics

Service usage metrics
Yes
Metrics types
Five9 provides comprehensive service usage metrics through its dashboards, reports, and APIs. Users can track call volumes, interaction counts, agent activity, queue wait times, service levels, and average handling times. These metrics are available in real time or via historical reports and can be customised to monitor specific KPIs. Administrators and supervisors can export data for analysis, integrate metrics with CRM or business intelligence tools, and use them for operational insights, performance tracking, and billing verification. The platform’s reporting tools make it easy to access and act on usage data efficiently.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Five9

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
To export data in Five9, customers need to log in to the Agent or Admin Console. Navigate to Reports or Analytics, select the desired report or dataset, and set the date range and filters. Click “Run” to generate the report, then choose Export. Available formats typically include CSV, Excel, or PDF. For automated or large-scale exports, use Five9 APIs to pull data programmatically into external systems. Always verify permissions to ensure access to the data you need before exporting.
Data export formats
  • CSV
  • Other
Other data export formats
  • Excel
  • PDF
Data import formats
  • CSV
  • Other
Other data import formats
  • XLSX
  • TSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Five9 protects data between its cloud platform and customer networks using encryption, secure protocols, and access controls. All data in transit is encrypted with TLS 1.2+, while voice traffic uses WebRTC or SRTP. Connections are safeguarded by firewalls, intrusion detection, and secure gateways, with optional VPN or private links for added isolation. Role-based access and multi-factor authentication restrict access to authorised users only. Continuous monitoring and compliance with standards like PCI, HIPAA, and GDPR ensure data integrity and confidentiality, keeping customer interactions and sensitive information secure at all times.
Data protection within supplier network
Other
Other protection within supplier network
Five9 protects data within its network in line with government rules by applying strong security, access control, and compliance practices. Customer data is encrypted at rest using industry-standard encryption and stored in logically isolated environments to prevent cross-tenant access. Internal access is restricted through role-based access control, least-privilege policies, and multi-factor authentication, with all activity logged and audited. Network segmentation, firewalls, and intrusion detection systems protect internal traffic. Continuous monitoring, regular vulnerability testing, and alignment with standards such as ISO 27001, PCI DSS, and GDPR ensure data remains secure and compliant.

Availability and resilience

Guaranteed availability
Five9 provides high availability for its cloud contact centre platform to ensure uninterrupted, mission‑critical customer service. The platform runs on resilient, geographically distributed infrastructure with multiple data centres, network paths, and storage systems to eliminate single points of failure. Five9’s standard SLA guarantees 99.99% uptime for core services such as voice, omnichannel interactions, and administration, and sets out the monitoring and response expectations for any service issues.
Reliability is supported through automated failover, load balancing, and proactive monitoring so that demand spikes or hardware and network issues do not affect operations. Scheduled maintenance is planned within defined windows and communicated in advance to minimise disruption.
For regulated or public‑sector customers, Five9 can provide region‑specific deployments to meet data residency and continuity requirements. Redundant connectivity, storage, and call routing protect service performance even if local issues occur. Visibility is offered through historical uptime data, real‑time dashboards, and SLA credit provisions.
Together, these measures ensure enterprise‑grade reliability, enabling organisations to manage multi‑channel customer communications smoothly and consistently, including during peak demand or unexpected infrastructure events.
Approach to resilience
Available on request.
Outage reporting
During an outage, Opus ensures customers receive clear, timely, and proactive communication to maintain confidence and minimise disruption. As soon as an incident is detected or reported, customers receive an automatic email acknowledgement confirming that the issue has been logged. This notification includes the assigned severity level and the corresponding SLA response thresholds, ensuring users understand the urgency and expected handling of the outage.

Throughout the investigation, Opus technicians provide regular progress updates, keeping customers informed of diagnostic findings, any identified root causes, and the steps being taken to restore service. This continuous communication ensures transparency and helps customers plan around the disruption.

Customers can also track the live status of their outage via the Opus Customer Portal, which displays real‑time incident information, current severity, timers, and any updates posted by the support team. This self‑service visibility means users are never left waiting for manual updates and can access the latest details whenever needed.
Together, these communication channels—automated notifications, technician updates, and real‑time portal visibility—ensure that Opus keeps customers fully informed throughout every outage, supporting effective service management and maintaining trust.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
User authentication is required to access Five9. All users, including agents, supervisors, and administrators, must log in with unique credentials. Multi-factor authentication (MFA), strong passwords, and role-based access controls (RBAC) ensure only authorised users access the platform. Authentication covers the Agent Desktop, administrative portals, and APIs. This makes all interactions, configuration changes, and data access traceable and accountable, maintaining security and compliance with standards such as ISO 27001 and SOC 2.
Access restrictions in management interfaces and support channels
Five9 restricts access to management interfaces and support channels using role-based access control (RBAC), authentication, and auditing. Users are assigned roles—such as agent, supervisor, or administrator—with permissions limited to their responsibilities. All users authenticate with unique credentials, supported by multi-factor authentication (MFA). Access follows the least-privilege principle, ensuring users have only the minimum required permissions. Support personnel access customer environments through secure, monitored channels with temporary or session-based permissions. All actions are logged and regularly reviewed. This approach ensures only authorised personnel access sensitive interfaces, maintaining security, accountability, and compliance with ISO 27001 and SOC 2 standards.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
Five9 authenticates management access using multi-layered security controls to ensure only authorised personnel can access administrative interfaces. Each administrator or supervisor has unique credentials, and multi-factor authentication (MFA) is required, combining passwords with a mobile or hardware token. Role-based access control (RBAC) limits permissions to necessary functions, while session timeout and inactivity controls reduce unauthorised use. All access attempts and actions are logged, monitored, and reviewed for anomalies. This combination of authentication, access restriction, and auditing ensures management access is secure, accountable, and traceable, protecting customer data and maintaining system integrity.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Five9’s security governance complies with ISO 27001, ISO 27017, SOC 2 Type 2, PCI DSS Level 1, HIPAA, and CSA cloud security guidance, supported by frameworks like NIST and COBIT, ensuring robust policies, controls, audits, and risk management for secure, compliant cloud contact centre operations.
Information security policies and processes
Five9 follows a comprehensive information security policy framework aligned with international standards such as ISO 27001, ISO 27017, SOC 2, and NIST. Policies cover data protection, access control, encryption, network security, incident response, vulnerability management, and business continuity. Employees are required to follow role-based procedures, including multi-factor authentication, least-privilege access, and secure handling of sensitive data.

The reporting structure is clearly defined: the Chief Information Security Officer (CISO) oversees the information security programme, reporting to the executive leadership team. Security teams and system owners report incidents, risks, and compliance issues through established channels. All staff receive security training and awareness updates, with compliance monitored via audits and automated controls.

Policy enforcement includes continuous monitoring, vulnerability scanning, penetration testing, and access reviews. Security incidents are logged, assessed, and escalated according to severity, with corrective actions documented. Policies are regularly reviewed and updated to reflect emerging threats, regulatory changes, and operational requirements.

In summary, Five9 maintains a structured governance and operational approach, ensuring consistent adherence to information security policies, accountability through a formal reporting hierarchy, and continual assessment to safeguard customer data and maintain regulatory compliance.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Five9’s configuration and change management process follows formal change control and asset tracking procedures. All system components, including servers, software, and integrations, are recorded in a configuration management database (CMDB) and tracked throughout their lifecycle. Proposed changes undergo rigorous assessment, including testing, security impact analysis, and approval by designated change authorities. Security risks, potential service disruption, and compliance implications are evaluated before implementation. Changes are documented, communicated to stakeholders, and monitored post-deployment for issues. Continuous audits and automated controls ensure all configurations remain accurate, authorised, and secure, maintaining service integrity and compliance with industry standards.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Five9’s vulnerability management process involves continuous identification, assessment, remediation, and monitoring of security risks across its platform. Threats are assessed for impact on confidentiality, integrity, and availability, including compliance and service continuity considerations. Vulnerabilities are prioritised based on severity, and patches or mitigations are applied promptly, often within defined SLA windows. Information about threats is gathered from internal monitoring, automated vulnerability scanners, security advisories, vendor updates, threat intelligence feeds, and industry sources. All findings and actions are logged, reported, and reviewed by security teams to ensure risks are addressed effectively, maintaining a secure and resilient service environment.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Five9’s protective monitoring processes involve continuous surveillance of networks, systems, applications, and user activity using automated tools, log analysis, and SIEM platforms. Potential compromises are identified through anomaly detection, intrusion alerts, and correlation of unusual behaviours. When an incident is detected, the security team immediately investigates, containing the threat, assessing impact, and initiating remediation according to predefined incident response procedures. Response times are prioritised by severity, with critical incidents addressed immediately, high-risk within hours, and lower-risk according to SLA timelines. All incidents are documented, escalated to leadership, and reviewed post-resolution to strengthen future protections and maintain compliance.
Incident management type
Supplier-defined controls
Incident management approach
Opus operates a predefined incident process with automatic logging, severity assignment, and SLA‑driven response thresholds. Common events are handled through standardised workflows in the Incident Management System (IMS). Users report incidents via email (auto‑converted to P4), by phone—bypassing auto‑attendants for rapid logging—or through the Opus Customer Portal, which also provides real‑time status visibility. Incidents are monitored on wallboards, with Level 1–2 cases triggering immediate alerts and escalation to senior managers. Incident reports and acknowledgements are automatically issued by email, with full tracking available through the portal.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Prospects can request a personalised demo or pilot with Five9, while larger organisations can access a custom Proof of Concept (PoC) to test key features and integrations in a controlled, managed environment, providing hands-on insight and demonstrating real value before committing.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Approachable Certification
ISO/IEC 27001 accreditation date
Tuesday 27 July 2027
What the ISO/IEC 27001 doesn’t cover
Everything is covered
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Approachable Certification
ISO 9001 accreditation date
Friday 1 December 2023
What the ISO 9001 doesn’t cover
Everything is covered
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
De7de48a-322f-4b14-b4ee-6069f39992ee
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Plans for positive actions with community groups.
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bid@opustech.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.