Skip to main content

Help us improve the Digital Marketplace - send your feedback

Wavenet

Zoom UC/CX

Zoom is an all-in-one collaboration platform that makes connecting easier, more immersive, and more dynamic for people and businesses. Our team chat, phone, meetings, omnichannel contact centre, whiteboard, workspace, and AI solutions help hybrid teams collaborate and get more done.

Features

  • AI-powered collaboration platform that streamlines your communications and improves productivity.
  • Artificial intelligence seamlessly embedded throughout the entire platform experience.
  • Simple video conferencing and messaging across all devices.
  • Comprehensive cloud phone system built for organizations of any size.
  • Omnichannel contact centre delivering fast, accurate, personalised customer experiences.
  • Instant messaging designed to simplify and accelerate user communications.
  • Employee experience platform driving stronger communication and engagement.
  • Integrated software room system for audio, video, and wireless sharing.
  • Unified platform for creating virtual events, webinars, and digital experiences.
  • Developer platform with 2,500+ ready-to-use integrations for seamless connectivity.

Benefits

  • Unified cloud communication platform designed for simplicity and reliability.
  • AI Companion integrated across platform at no extra cost.
  • Single, centralised admin console enables fast deployment and effortless scalability.
  • Affordable subscription pricing with transparent licensing for all users.
  • Hundreds of updates delivered annually to enhance platform performance.
  • Intuitive interface ensures quick adoption and seamless user experience.
  • Powerful dashboards simplify administration and user activity reporting.
  • MSI management streamlines deployment of development releases efficiently.
  • Technical support available 365x24x7.
  • High-availability platform ensuring uninterrupted communication, collaboration, and continuity.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at publicsector@wavenet.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 2 8 1 7 0 1 4 5 5 4 4 8 2 2

Contact

Wavenet Joe Ewins
Telephone: 0333 234 0011
Email: publicsector@wavenet.co.uk

About your service

Service categories

Applications

Customer relationship management

  • Customer service
  • Contact centre
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Not Applicable
System requirements
  • Internet connection—broadband wired or wireless, including 3G and 4G.
  • Speakers and microphone—built-in, USB, or wireless
  • Bluetooth connectivity supported.
  • Webcam or HD webcam—built-in or USB plug-in optional.
  • See more here: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0060748

User support

Email or online ticketing support
Yes
Support response times
P1 - Total loss of communications of a site. Requires immediate action to be taken to restore services. Response Time 1 Hour.
P2 - Loss of more than 50% of operational equipment. Requires urgent action to be taken to restore services. Response Time 4 Hours.
P3 - Loss of less than 50% of operational equipment. Is service affecting but not an emergency. Response Time 8 Hours.
P4 - Request not affecting communications. Requests for information or enhancements. Response Time 24 Hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Wavenet standard support hours are Monday to Friday, 8:00 AM to 18:00 PM. Our fault handling service is available 24 hours a day and 7 days a week, including Public and Bank Holidays. Wavenet offer out of hours support for Zoom Phone & Zoom Contact Centre Services for P1 incidents.
Support available to third parties
No

Onboarding and offboarding

Getting started
Upon signing the contract, services are provisioned, an account created, and your administrator will be provided with access instructions and credentials. Our Project Services teams will collaborate with you to facilitate the adoption of our service, providing guidance and training for setup, configuration, and efficient use. They adhere to PMI methodology and PRINCE2 principles, ensuring a structured approach from contract signing to transition to our Support teams. The onboarding process, guided by the Project Services team, implements project lifecycle processes and governance throughout.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
If information or data in your Zoom account needs to be maintained for any reason, including legal preservation obligations, it is the responsibility of the Zoom Account Owner to download and preserve that data as needed.  Resources and support articles for downloading and saving that data are provided on the Zoom support site.
End-of-contract process
Upon termination of the customer's contract, Zoom will deactivate all user IDs associated to that billing account and delete any saved recordings. Zoom has a data retention standard that details how data is deleted when a customer terminates service (i.e., purged on day 31). Furthermore, our Data Protection Standard states how Zoom must sanitise media. Zoom has a process for records retention to ensure that Personal Information is retained for no longer than necessary to fulfil the obligations or meet legal retention requirements.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
See the link below for a comparison of features between the Zoom desktop clients, mobile apps, web client, and Zoom Web App:
https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB006552
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Zoom offers consolidated administration through the Zoom web portal, allowing account administrators to efficiently manage a geographically distributed organization from a single interface. End users can also access their setting via the same portal, which administrators can configure with granular controls. Customers often choose Zoom for the simplicity and intuitiveness of the Zoom web portal, enabling IT teams to quickly adopt automated workflows and integrate seamlessly with existing systems.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Zoom conducts accessibility testing for new features through an in house team of dedicated accessibility professionals.
API
Yes
What users can and can't do using the API
The Zoom API is the primary means for developers to access a collection of resources from Zoom. Apps can read and write to the resources and mirror some of the most popular features available in Zoom Web Portal such as creating a new meeting, creating, adding and removing users, viewing reports and dashboards on various usage, and so on using the Zoom API. Depending on your app’s use case, you can choose from our various APIs and implement the features accordingly. All APIs under the Zoom API are based on REST architecture and are accessed via HTTPS at specified URLs. The base URL for all requests is https://api.zoom.us/v2/. The complete URL varies depending on the endpoint of the resource being accessed. For instance, you can list all users on an account via a GET request to this URL: https://api.zoom.us/v2/users/. Within our API reference pages, you can send test requests and view responses. You can also view the code for the request in various languages such as Python, Node, Java and more. With each release, we add additional APIs and enhancements to meet the needs of our customers.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Zoom offers a number of opportunities to customise the service. Zoom’s App Marketplace brings together integrations, apps, and bots built by Zoom, third-party developers, and oftentimes our own customers, making it easy for Zoom users to extend the power of Zoom for any business need. The Zoom App Marketplace hosts over 2,500 apps and integrations for our solutions. In addition, Zoom’s APIs allow for a robust extension of the core Zoom product and apps can read and write to the resources and mirror some of the most popular features available in the Zoom Web Portal such as creating, adding and removing users, viewing reports and dashboards on various usage, and so on. Experienced developers can choose to leverage Zoom’s SDKs to incorporate the Zoom experience into their own application. Lastly, role-based access control enables the creation of custom user roles that have a set of permissions that allows access only to the pages a user needs to view or edit.

Scaling

Independence of resources
Zoom’s unique architecture allows us to quickly and easily scale to meet demand. We maintain excess capacity in all aspects of our infrastructure to accommodate growing business, healthcare, and education needs and to meet peak usage requirements. Our proven infrastructure supports billions of meeting minutes a month and our architecture is built to handle growing levels of activity, as our unified communications platform is architected from the ground up to address the most technologically difficult aspect of communications: video. Our modern cloud architecture gives our platform its trademark reliability, quality, and scalability.

Analytics

Service usage metrics
Yes
Metrics types
The Zoom Dashboard allows administrators on the account to view information ranging from overall usage to live data relating to Zoom solutions. This data can be used to analyse issues that may have occurred as well better understand how users are intreacting with the Zoom platform within your organisation.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Zoom

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Reports and recordings can be exported via the Zoom web portal as required.
Data export formats
  • CSV
  • Other
Other data export formats
  • MP4.
  • MP3.
  • M4A.
  • VTT.
  • JSON.
Data import formats
  • CSV
  • Other
Other data import formats
SAML

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
Zoom’s infrastructure for real-time video, audio, and data runs on dedicated servers within SSAE 16 and SOC 2 compliant data centres. Zoom sessions are temporary, operating similarly to mobile conversations over public networks. Data in transit between Zoom clients and data centres is secured using Secure Real-time Transport Protocol for media and TLS 1.2 with 256-bit AES-GCM encryption. Data at rest within Zoom’s data centres is protected with 256-bit AES-GCM encryption, ensuring end-to-end security, confidentiality, and integrity across all communications and stored content.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection within supplier network
Zoom follows OWASP standards to maintain robust internal security processes.

Availability and resilience

Guaranteed availability
SLAs are addressed in Zoom's Master Services Agreement (MSA) and may include 99.9% uptime, excluding excused downtime (maintenance).
Approach to resilience
Zoom web services leverage AWS high availability infrastructure with multi-region configuration operating in Active/Standby mode. For real-time communications, Zoom leverages multiple Tier 1 data centres running in Active/Active mode.
Outage reporting
Zoom posts any general incident announcement and other announcements including scheduled maintenance, outages, updates, through our status page at status.zoom.us. For incidents affecting a specific customer, Zoom will notify the account owner and administrator(s) through email or as specified in fully executed agreement.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Zoom offers Single Sign-On, based on SAML 2.0, for a secure and quick login using company credentials, eliminating the need for a separate Zoom password. SSO works with platforms like Okta and Microsoft Entra ID.
Access restrictions in management interfaces and support channels
Management interfaces are accessed via user name and password derived from integration via SSO or user name and password stored in a salted hash. Interfaces are accessed based upon role based access control (RBAC).
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials, Cyber Essentials Plus, SOC2 Type 2, GDPR, TRUSTe Certified Privacy
Information security policies and processes
Zoom's security policies are derived from ISO 27001 framework.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Change triggers for unique processes and controls are: Code, Database, Infrastructure, Data.

Weekly meetings held to request changes that need to be performed during maintenance windows. Change requests are presented, validated, and scheduled. Changes are approved by the Change Manager. Implementation in production should not be by the same individual who developed the change. When staffing levels do not permit this separation, management oversight and approval of the change and testing process ensure appropriate processes are followed. Dev and test environments are physically and logically segregated from production. No customer data is used in testing.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Zoom has a formal Vulnerability Management Plan in place. Zoom performs monthly vulnerability and web application scanning using an external party (Qualys). Scan reports are reviewed by our Security and technical teams and discussed with the engineering and development teams. Validated findings are tracked in our JIRA system throughout remediation.

Zoom has a monthly patch cadence. Zoom will patch all applications, workstations, and servers (virtual or physical) with all current operating system, database, and application patches deployed in our computing environment according to a schedule predicated on the criticality of the patch. Maintenance/patching typically will have no service downtime.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We have monthly vulnerability and web application scans. Findings are reviewed and validated by our technical and engineering team. Vulnerability rated on severity level and tracked using our JIRA system. Vulnerability fixes are release from our engineering team and follow our formal change management process for deployment to production. Zoom also has DDoS monitoring and Managed service in place. Affected traffic are diverted and filtered through a scrubbing centre.

Zoom responds to incidents as defined within our SOC2 report available on the Zoom Trust Centre at https://www.zoom.com/en/trust
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Zoom communicates the incident response policy to internal and external users and instructs users to contact their supervisor and the information security representative if they become aware of a possible security breach. When a potential security incident is detected, a defined incident management process is initiated by authorised personnel. Incidents are tracked through the tracking application, which includes the corrective actions implemented in accordance with the defined policies and procedures.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
  • Public Services Network (PSN)
  • Police National Network (PNN)
  • Joint Academic Network (JANET)
  • Scottish Wide Area Network (SWAN)
  • Health and Social Care Network (HSCN)
  • Other
Other public sector networks
NHS Network (N3)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
3%
Between £2,500,001 and £5,000,000
4%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
United Registrar of Systems
ISO/IEC 27001 accreditation date
Thursday 18 July 2024
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
United Registrar of Systems
ISO 9001 accreditation date
Monday 12 August 2024
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
39aabf05-4ab8-4ee7-adcd-3318af1f9d2f
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
6cc5c85d-03f1-446c-9e9d-7338dfb9f0ce
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Plans for positive actions with community groups.
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at publicsector@wavenet.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.