Skip to main content

Help us improve the Digital Marketplace - send your feedback

TTEC CONSULTING (UK) LIMITED

TTEC Digital NiCE CXone Cloud Contact Centre

TTEC Digital NiCE CXone Cloud Contact Centre delivers a secure, scalable omnichannel platform with AI-driven automation, workforce engagement, and advanced analytics. It integrates seamlessly with CRM and WFM systems, enabling exceptional customer experiences, operational efficiency, and continuous innovation through regular updates and ISO-certified security compliance.

Features

  • Omnichannel support: Voice, chat, email, social, and SMS.
  • AI-driven automation for routing, self-service, and agent guidance.
  • Workforce engagement tools for scheduling and performance optimisation.
  • Advanced analytics dashboards for actionable insights and reporting.
  • Customisable intelligent routing for personalised customer experiences.
  • Secure architecture certified to ISO27001 and SOC2 standards.
  • Flexible API integration for CRM and WFM systems.
  • Enlighten AI for conversation analysis and automation.
  • Knowledge management with CXone Expert for self-service optimisation.
  • Scalable cloud platform for rapid capacity and feature upgrades.

Benefits

  • Exceptional customer and agent experiences across all interaction channels.
  • Serve customers in their preferred channels for seamless engagement.
  • Empower agents with workforce engagement tools for better performance.
  • Reduce operational costs and training time through automation and AI.
  • Free up agent time with self-service and guided workflows.
  • Future-proof technology with regular upgrades and feature enhancements.
  • Increase visibility and actionable insights via advanced analytics dashboards.
  • Centralise customer data in a single, intuitive interface.
  • Enable remote work effortlessly with secure, cloud-native architecture.
  • Rapid scalability and flexibility to meet changing business demands.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@ttecdigital.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 2 2 6 1 6 6 6 6 5 2 7 1 6 9

Contact

TTEC CONSULTING (UK) LIMITED Wayne Kay
Telephone: 0113 5432620
Email: gcloud@ttecdigital.com

About your service

Service categories

Applications

Customer relationship management

  • Marketing campaign management
  • Digital commerce
  • Sales force productivity and management
  • Customer service
  • Contact centre

Advertising

  • Advertising Placement
  • Advertising Measurement
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
NiCE CXone integrates with CRM platforms (e.g., Salesforce, Microsoft Dynamics), workforce management tools, and telephony systems. It extends functionality for customer engagement, analytics, and omnichannel routing while remaining fully operational as a standalone cloud contact centre solution.
Cloud deployment model
Public cloud
Service constraints
The service requires internet connectivity and supported browsers for access. Planned maintenance is scheduled outside business hours where possible and communicated in advance. Service availability depends on NiCE CXone cloud infrastructure; no on-premises deployment is supported. Integration may require compatible CRM or telephony systems. No hardware-specific constraints apply.
System requirements
  • Reliable broadband internet connection with minimum 1.5 Mbps bandwidth.
  • Modern web browser: Chrome, Edge, or Firefox latest versions.
  • Enabled JavaScript and cookies for full application functionality.
  • Headset with noise cancellation for optimal voice quality.
  • Supported operating systems: Windows 10+, macOS latest versions.
  • Minimum 4 GB RAM and dual-core processor recommended.
  • Access to NiCE CXone cloud environment via secure HTTPS.
  • Optional CRM integration requires valid Salesforce or Dynamics license.
  • VPN or secure network for remote agent connectivity.
  • No on-premises hardware; service is fully cloud-hosted.

User support

Email or online ticketing support
Yes
Support response times
SurroundCX™ escalation tiers and response times:

P1 – Critical
Impact: Service outage or severe business disruption.
Response: Acknowledge within 15 minutes, 24/7 coverage.

P2 – High
Impact: Major functionality impaired, but workaround exists.
Response: Acknowledge within 30 minutes, during business hours.

P3 – Standard
Impact: Minor issue or general inquiry.
Response: Acknowledge by 10:00 AM next business day.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
1. Support Levels Provided:
SurroundCX™ offers three support tiers: Essential, Plus, and Premium:
• Essential includes core monitoring, incident management, and standard platform support.
• Plus adds proactive health checks, configuration assistance, and enhanced reporting.
• Premium delivers strategic guidance, advanced analytics, priority case handling, and dedicated personnel.

2. Support Costs:
Pricing is subscription-based and varies by tier, user volume, and service complexity. Exact costs are defined in individual contracts and service-level agreements.

3. Dedicated Support Personnel:
Only Premium clients receive a dedicated Technical Account Manager for strategic oversight and a Cloud Support Engineer for technical troubleshooting and optimisation. Essential and Plus tiers rely on shared support resources.
Support available to third parties
No

Onboarding and offboarding

Getting started
We provide a comprehensive onboarding experience tailored to your team’s needs.

Training options include:
• Onsite Instructor-Led Training: Delivered by certified NiCE CXone specialists for hands-on learning in a focused environment.

• Remote Instructor-Led Training: Offers the same personalised approach without travel, ideal for distributed teams.

• Self-Paced eLearning: Access to virtual modules and refresher courses, allowing learners to progress at their own pace.

• Bootcamps and Workshops: Interactive sessions covering platform configuration, agent tools, and best practices.

• User Documentation & Knowledge Base: Detailed guides, FAQs, and quick-start resources for continuous learning.

• Role-Based Learning Paths: Prescribed tracks for agents, supervisors, and administrators to accelerate proficiency.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
  • PDF Guides – Downloadable step-by-step instructions.
  • HTML Web Pages – Interactive online help content.
  • Knowledge Base Articles – Searchable FAQs and troubleshooting tips.
  • Video Tutorials – Short, role-based training videos.
  • ELearning Modules – Self-paced interactive courses.
  • Quick Reference Cards – Printable cheat sheets for key tasks.
  • Slide Decks – Visual presentations for onboarding sessions.
  • Mobile App Help – Embedded guidance within the application.
  • Infographics – Visual summaries of workflows and best practices.
  • API Documentation – Developer-focused integration guides.
End-of-contract data extraction
When a TTEC Digital NiCE CXone Cloud Contact Centre contract ends, customers can extract their data using built-in export tools and APIs. The platform supports CSV exports via its online portal for core datasets like workforce management and interaction records. For advanced needs, Data Extraction APIs allow retrieval of quality management workflows, interaction metadata, and WFM payroll data. These APIs require authentication keys and permissions, and they return downloadable links (typically valid for 30 seconds) to files stored temporarily in secure locations. Alternatively, Data Download Reports can be scheduled or run on demand, delivering raw data in CSV, tab-delimited, or XML formats to authorised email addresses. Access to recordings and transcripts is possible through Media Playback APIs, which provide temporary URLs for download. All transfers use TLS encryption, and data remains available for a limited time post-extraction, so planning ahead is essential.
End-of-contract process
End of Contract Process:
At the end of the contract, TTEC Digital follows a structured off-boarding process to ensure security and compliance. All platform infrastructure is decommissioned, accounts are disabled, and Buyer documentation is archived. Quality Management (QM) data and reporting data for the contracted retention period are securely transferred via SFTP to the Buyer’s designated site and then permanently destroyed. No customer data is retained after completion.

Included in the Contract Price:
Secure decommissioning of Cloud infrastructure (hardware/software).
Account closure and documentation archiving.
Transfer of retained QM and reporting data to Buyer’s SFTP site.
Compliance with GDPR, ISO 27001, and UK Government security standards.

Additional Costs:
Migration of data beyond standard retention exports (e.g., bulk historical data).
Porting telephone numbers to a new provider.
Any costs associated with sourcing and onboarding a new provider.
Custom integrations or automation for data extraction beyond standard tools.

This approach ensures transparency, security, and continuity while giving the Buyer full control over their data and compliance obligations.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
NiCE CXone’s desktop service delivers a full-featured contact centre platform with advanced routing, real-time analytics, scripting, and multi-channel management, ideal for full-time agents and supervisors. The mobile service, by contrast, focuses on essential tools like call handling, messaging, and workforce management, optimised for flexibility and remote use via cellular or Wi-Fi. While both ensure secure access, mobile relies more on device-level protections and offers a streamlined interface without advanced configuration or reporting options. Desktop supports high-resource environments for comprehensive operations, whereas mobile prioritises portability and quick engagement, enabling agents to stay connected and productive on the go.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
The TTEC Digital web-based customer self-service support portal is accessed through redemption of a secure invitation code sent directly to authorised personnel within the client business. Once registered, clients can open new support cases, and view existing support cases, priority, status, assigned contacts, case owners, date of creation and any updates provided by the TTEC Digital support engineering team.
Accessibility standards
EN 301 549
Accessibility testing
NiCE CXone has undergone accessibility testing aligned with WCAG standards. We conducted interface evaluations using assistive technologies such as screen readers (JAWS, NVDA), voice recognition tools, and keyboard-only navigation. Testing focused on critical workflows including login, call handling, and reporting dashboards to ensure compatibility and usability. Feedback from users with visual and motor impairments informed improvements in focus indicators, ARIA labels, and color contrast. Mobile and desktop interfaces were validated for responsive design and consistent accessibility features. Ongoing audits and regression testing are performed during updates to maintain compliance and enhance user experience for individuals relying on assistive technology.
API
Yes
What users can and can't do using the API
1. How users can set up the service through the API:
Users can provision accounts, configure roles, and establish basic contact center settings via NiCE CXone REST APIs. Initial setup includes creating agent profiles, assigning skills, and enabling channels such as voice, chat, and email.

2. How users can make changes through the API:
APIs allow updates to routing rules, IVR scripts, and workforce management parameters. Users can modify queues, adjust agent permissions, and integrate third-party applications for CRM or analytics. Real-time data retrieval and reporting endpoints support operational adjustments.

3. Limitations to how users can set up or make changes through the API:
Certain advanced configurations, such as custom dashboards, compliance settings, and telephony carrier changes, require administrative access through the web interface. Bulk updates may be restricted by rate limits, and some integrations (e.g., proprietary CRM connectors) need vendor support. APIs do not provide full UI customisation or access to underlying infrastructure.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
1. What can be customised:
Users can tailor their SandcastleCX environment to match specific CX use cases, technology platforms (e.g., Genesys, AWS, Microsoft, Salesforce and NiCE), integrations, and features such as voice routing, CRM connectors, bots, and reporting dashboards.

2. How users can customise:
Customisation is achieved through a guided, hands-on sandbox experience. TTEC Digital CX architects configure the environment based on client requirements, enabling iterative testing of workflows, integrations, and advanced capabilities. Optional add-ons like Learning and Performance Management or IP solutions can extend functionality.

3. Who can customise:
Authorised client stakeholders, typically CX leaders, IT teams, and solution architects, collaborate with TTEC Digital experts to define priorities and adjust configurations during the trial period.

Scaling

Independence of resources
We ensure service stability through multi-tenant isolation and elastic scaling. Each customer operates within logically isolated environments, preventing resource contention. Our cloud architecture uses auto-scaling clusters that dynamically allocate compute and storage based on real-time demand. Load balancing distributes traffic evenly across nodes, while QoS policies prioritise critical processes to maintain performance. Continuous monitoring detects anomalies and triggers proactive adjustments before impact occurs. Additionally, redundant infrastructure and failover mechanisms guarantee high availability even during peak usage. These measures collectively ensure that one user’s demand never degrades another’s experience.

Analytics

Service usage metrics
Yes
Metrics types
Performance metrics: total calls handled, average handle time, service level adherence, agent productivity.
Individual agent performance: total calls handled, average handle time per agent, occupancy rate, customer satisfaction scores.

Performance customer service groups, providing metrics including average wait time, queue abandonment rate, service-level attainment, queue occupancy.

Call volume trends: users to analyse patterns and fluctuations in call volume to better allocate resources and staff.

Service level targets, providing metrics, including average speed of answer.

Percentage of customer inquiries/issues resolved on the first contact.

Rate at which callers abandon their calls while waiting in queue.

Performance of interactive voice response systems.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
TTEC Digital: Genesys, Microsoft, NiCE, Google, Shelf, ServiceNow – ttecdigital.com/services

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
We protect data at rest using AES-256 encryption across all storage layers, including databases, backups, and file systems. Encryption keys are managed through secure key vaults with strict rotation and access controls. Data is further safeguarded by role-based access permissions, ensuring only authorised personnel can retrieve sensitive information. Storage systems are hardened with disk-level encryption, and redundant copies are maintained in secure, geographically distributed environments. Regular integrity checks, vulnerability scans, and compliance audits (ISO 27001, SOC 2) ensure ongoing protection. These measures collectively guarantee confidentiality and resilience for all stored data.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export data from NiCE CXone using several secure methods. The platform supports self-service extraction via REST APIs, allowing customers to pull data programmatically for reporting or migration. Additionally, CSV and XML export formats are available for structured data downloads. For convenience, users can run Data Download reports or schedule them for automated delivery to approved email addresses. Interaction Analytics data can also be exported to Amazon S3 buckets for large-scale storage. For advanced needs, the Data Extraction API enables filtered exports of interaction metadata and quality management workflows. Professional services assistance is available for bulk or contract-end extractions.
Data export formats
  • CSV
  • Other
Other data export formats
  • CSV – Comma-separated values for tabular data.
  • XML – Structured markup for system integrations.
  • JSON – Lightweight format for APIs and analytics.
  • Excel (XLSX) – Spreadsheet-friendly data export.
  • PDF – Static reports for compliance or archiving.
  • TXT – Plain text for simple data sets.
  • HTML – Web-ready formatted reports.
  • ZIP – Compressed package for bulk data files.
  • S3 Object Storage – Export to Amazon S3 buckets.
  • Custom API Payloads – Configurable data structures via REST API.
Data import formats
  • CSV
  • Other
Other data import formats
  • CSV – Comma-separated values for structured datasets.
  • Excel (XLSX) – Spreadsheet format for bulk data.
  • JSON – Lightweight format for API-based imports.
  • XML – Structured markup for system integrations.
  • TXT – Plain text for simple data uploads.
  • ZIP – Compressed archives for multiple files.
  • PDF – Static documents for reference or compliance.
  • HTML – Web-formatted content for portal uploads.
  • S3 Object Storage – Direct upload from Amazon S3 buckets.
  • Custom API Payloads – Configurable structures via REST API.

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
We protect data in transit using end-to-end encryption and secure tunneling. All traffic between the buyer’s network and our platform is encrypted with TLS 1.2/1.3, ensuring confidentiality and integrity. We enforce mutual authentication via certificates to prevent unauthorised access. Additionally, IP whitelisting and VPN options provide controlled connectivity for sensitive environments. Data packets are monitored for anomalies using intrusion detection systems, and session keys are rotated regularly to mitigate interception risks. Combined with strict compliance to ISO 27001 and GDPR, these measures guarantee secure, tamper-proof communication between networks.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
We safeguard data within our network using segmentation and encryption at rest. Sensitive information is stored in encrypted databases using AES-256, and keys are managed through secure vaults with strict rotation policies. Access is controlled via role-based permissions and enforced through multi-factor authentication. Network traffic is monitored by intrusion detection and prevention systems, while firewalls and micro-segmentation limit lateral movement. Regular vulnerability scans and penetration tests ensure compliance with ISO 27001 and SOC 2 standards. These layered controls maintain confidentiality, integrity, and availability across all internal systems.

Availability and resilience

Guaranteed availability
We guarantee 99.99% uptime for the NiCE CXone platform, supported by a robust, multi-region cloud architecture with automatic failover and redundancy. This SLA covers all core services, including voice, digital channels, and analytics. Availability is measured monthly, excluding scheduled maintenance windows.

If availability falls below the guaranteed level, customers are eligible for service credits based on the percentage of downtime. Credits are applied to future invoices and calculated according to the SLA tiers outlined in the contract. For example, availability between 99.0%–99.99% may result in a credit of up to 10%, while below 99.0% may qualify for higher credits.

Our proactive monitoring, auto-scaling infrastructure, and disaster recovery protocols ensure resilience and continuity, minimising the risk of service disruption. These measures, combined with transparent reporting and compliance with ISO 27001 and SOC 2, provide confidence that your contact center remains operational even during peak demand or unexpected events.
Approach to resilience
Our NiCE CXone Contact Centre service is built on a multi-region, cloud-native architecture designed for high resilience and fault tolerance. Each component runs in redundant clusters across geographically separated data centers, ensuring continuity even during localised failures. Data is replicated in real time across regions, and automatic failover mechanisms redirect traffic seamlessly if a node or region becomes unavailable.

We employ load balancing, elastic scaling, and proactive health monitoring to maintain performance under varying demand. Disaster recovery plans include regular backups, integrity checks, and tested recovery procedures, meeting ISO 27001 and SOC 2 standards.

Physical and logical resilience measures, such as power redundancy, network diversity, and hardened facilities, protect against environmental and operational risks. For detailed datacentre configurations and resilience strategies, this information is available on request to authorised buyers under NDA.

These layered controls ensure service continuity, minimise downtime, and comply with the UK Government’s Cloud Security Principle on asset protection and resilience.
Outage reporting
Public Dashboard:
We provide a real-time status dashboard accessible via our support portal. It displays current service health, ongoing incidents, and historical uptime metrics. Users can check component-level availability and maintenance schedules at any time.

API:
An Incident Status API is available for integration with your monitoring tools. It delivers JSON-formatted outage data, including severity, affected services, and estimated resolution times, enabling automated alerts and dashboards.

Email Alerts:
Customers can subscribe to email notifications for outages, maintenance events, and resolution updates. Alerts include incident details, impact assessment, and recovery progress, ensuring timely communication to stakeholders.
Our reporting process aligns with ISO 27001 and SOC 2 standards, ensuring transparency and compliance.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
We authenticate users through secure, multi-layered controls. Access begins with username and password validation, enforced by strong complexity and rotation policies. We support Multi-Factor Authentication (MFA) using one-time codes or authenticator apps to prevent unauthorised access. For enterprise customers, Single Sign-On (SSO) via SAML 2.0 or OAuth integrates with identity providers like Azure AD. All sessions use TLS encryption and token-based authentication to maintain confidentiality. Role-based access controls ensure users only access resources aligned with their permissions. These measures collectively provide strong identity assurance and compliance with ISO 27001 and SOC 2 standards.
Access restrictions in management interfaces and support channels
Access Restrictions:
Administrative access is limited to authorised personnel using role-based permissions and least-privilege principles.

Authentication:
All access requires multi-factor authentication (MFA) and secure VPN connections for remote sessions.

Session Security:
Interfaces are protected by TLS encryption, session timeouts, and continuous monitoring for anomalies.

Support Channels:
Customer support interactions are authenticated, logged, and conducted through secure portals. Sensitive actions require identity verification and approval workflows.
These measures ensure only verified users can manage or support services securely.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
Less than 1 month
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
PCI DSS Level 1
SOC 2 Type 2
HIPAA
Cyber Essentials
Cyber Essentials Plus
Information security policies and processes
TTEC's Global Information Security (GIS) reports to the VP and Chief Security Officer. The GIS department is within TTEC’s Security, Resiliency and Governance organisation, reporting to TTEC's Chief Information Officer.
TTEC’s robust Global Privacy, Risk, Compliance, Network, and InfoSec programmes are based on the guiding principles of: Availability; Integrity; and Confidentiality. These principles are achieved through defined policies, industry controls, with infosec and privacy trainings, and through the governance structure within our corporate GIS, IT, Legal and Risk Executives.
TTEC’s policies/procedures comply with ISO 27002 compliance framework that standardise the following security elements:

•InfoSec Policy & Organisational Measures
•Asset/Data Classification
•Human Resource Security- Corrective Actions
•Physical/Environment Security
•Communication/Operation Management
•Access/Authentication/Password Management
•Data Encryption
•InfoSec Acquisition Development/Maintenance
•Endpoint Security
•Auditing, Logging, Monitoring
•Vulnerability, Penetration, Patch Management
•Network Security, Configuration Management
•Applications, SDLC, Change Management
•Incident Response Management
•Security, Fraud, Ethics Code Training- Accountability
•BCP/DR
•Global IT/Risk Management
•Regulatory Compliance

TTEC performs periodic and annual, internal, and external independent, third party, qualified, industry compliance audits of the TTEC organisational controls and technology environments. TTEC continues to achieve ongoing industry compliance accreditation with PCI DSS (SL-1), ISO 27001, SOC 2 Type II (SSAE 18), Cyber Essentials Basic & Plus, and more.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Component Tracking:
All service components are tracked throughout their lifecycle using a Configuration Management Database (CMDB). Each asset is assigned a unique identifier, with version history and dependencies recorded to maintain visibility and integrity.

Change Assessment:
Changes follow a formal Change Advisory Board (CAB) process. Every modification undergoes risk and security impact analysis, including vulnerability checks and compliance validation. Approved changes are implemented with rollback plans and logged for audit purposes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Threat Assessment:
We continuously monitor for vulnerabilities using automated scanning tools and perform risk-based analysis to assess potential threats to services.

Patch Deployment:
Critical patches are deployed within 24 hours, while high and medium-risk updates follow defined SLAs to ensure timely remediation.

Threat Intelligence Sources:
We leverage vendor advisories, CVE databases, CSA alerts, and threat intelligence feeds from trusted security partners to stay ahead of emerging risks.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Identifying Potential Compromises:
We use SIEM tools and real-time log analysis to detect anomalies, unauthorised access attempts, and suspicious patterns. Alerts are generated for predefined indicators of compromise.

Responding to Potential Compromises:
Incidents trigger an automated containment workflow, followed by manual investigation. Actions include isolating affected systems, revoking credentials, and applying patches.

Response Time:
Our Security Operations Centre (SOC) operates 24/7, with initial response within 15 minutes of detection and full remediation initiated immediately per severity level.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Pre-Defined Processes:
We maintain documented playbooks for common incidents, including service outages, security breaches, and performance degradation. These processes ensure rapid, consistent response.

User Reporting:
Users can report incidents via 24/7 support channels, including a dedicated portal, email, and phone hotline. Automated alerts also trigger internal escalation.

Incident Reports:
We provide detailed post-incident reports outlining root cause, impact, and corrective actions. Reports are shared through secure channels and archived for compliance.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
SandcastleCX™ provides a secure, customised sandbox for testing and exploring CX technologies, including CCaaS, CRM, AI, and analytics. It offers expert guidance, platform validation, and flexible trial access at no cost for standard use cases. Ideal for innovation and proof-of-concept projects, enabling rapid evaluation without production risk.
Link to free trial
https://youtu.be/hNmqTiNkIx8?si=9cRF7IADXikWKBm7

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2.2%
Between £500,001 and £1,000,000
4.2%
Between £1,000,001 and £2,500,000
6.2%
Between £2,500,001 and £5,000,000
8.2%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Coalfire Certification, Inc.
ISO/IEC 27001 accreditation date
Thursday 21 August 2025
What the ISO/IEC 27001 doesn’t cover
Certification available on request.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
PCI Security Standards Council
PCI DSS accreditation date
Friday 28 November 2025
What the PCI DSS doesn’t cover
Certification available on request.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
2807b81c-9543-492c-805b-f1fd3347313f
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
613c9a41-2540-4e86-811e-d9808a365c26
Other security certifications
Yes
Any other security certifications
  • SOC 2, Type II
  • HIPAA

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Content of the outreach activity is designed to suit the target cohort

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@ttecdigital.com. Tell them what format you need. It will help if you say what assistive technology you use.