TTEC Digital NiCE IEX Workforce Management (WFM)
TTEC Digital NiCE IEX Workforce Management optimises contact centre staffing through AI-driven forecasting, real-time adherence, and automated scheduling. It supports omnichannel environments, improves employee engagement, and enhances operational efficiency with configurable dashboards, self-service tools, and secure cloud architecture for scalable, compliant workforce management.
Features
- AI-powered forecasting for omni-channel contact centre environments.
- Intraday management with real-time adherence monitoring tools.
- Self-service scheduling, vacation bidding, and time-off management.
- Configurable dashboards for schedule and performance visibility.
- Automated schedule optimisation using machine learning algorithms.
- Integration with leading ACD and CRM platforms.
- Real-time alerts for staffing and call volume changes.
- Cloud-based scalability for seasonal or dynamic workforce needs.
- Historical and predictive reporting for workforce performance trends.
- Agent empowerment through mobile and web self-service tools.
Benefits
- Improves forecast accuracy, reducing costly overstaffing and overtime.
- Enhances employee engagement with flexible scheduling options.
- Boosts productivity through real-time adherence and performance insights.
- Supports compliance with labor laws and scheduling fairness.
- Reduces administrative workload via automated scheduling processes.
- Optimises staffing for digital and voice channels simultaneously.
- Improves customer experience by aligning resources to demand.
- Enables rapid intraday adjustments to meet service levels.
- Delivers actionable insights for strategic workforce planning.
- Scales easily to support growth and seasonal peaks.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 3 8 2 3 7 8 6 0 1 6 7 9 2 3
Contact
TTEC CONSULTING (UK) LIMITED
Wayne Kay
Telephone: 0113 5432620
Email: gcloud@ttecdigital.com
About your service
- Service categories
-
Applications
Customer relationship management
- Marketing campaign management
- Digital commerce
- Sales force productivity and management
- Customer service
- Contact centre
Advertising
- Advertising Placement
- Advertising Measurement
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Our service extends leading contact centre and CRM platforms, including NiCE CXone, Microsoft Dynamics 365, Genesys Cloud, Amazon Connect, and Calabrio WFM. It integrates seamlessly via APIs and adapters, enabling real-time adherence, historical reporting, and schedule synchronisation for unified workforce management across omnichannel environments.
- Cloud deployment model
- Public cloud
- Service constraints
- Planned maintenance occurs during agreed low-usage windows with prior notice. Service availability depends on stable internet connectivity and supported browsers (latest and previous versions). Performance may vary on outdated hardware or unsupported operating systems. Customer must ensure compliance with technical prerequisites, including API configurations. No offline mode; cloud access required.
- System requirements
-
- Modern web browser: Chrome, Edge, or Firefox latest versions.
- Stable internet connection: minimum 10 Mbps bandwidth recommended.
- Windows 10 or macOS 11 for desktop access.
- JavaScript and cookies enabled in browser settings.
- Access to NiCE CXone or supported ACD integration platform.
- Active directory or SSO for secure user authentication.
- Minimum 4 GB RAM for optimal application performance.
- Antivirus software for endpoint protection on client devices.
- API access credentials for CRM or telephony system integration.
- TLS 1.2 or higher for secure data transmission.
User support
- Email or online ticketing support
- Yes
- Support response times
-
SurroundCX™ escalation tiers and response times:
P1 – Critical
Impact: Service outage or severe business disruption.
Response: Acknowledge within 15 minutes, 24/7 coverage.
P2 – High
Impact: Major functionality impaired, but workaround exists.
Response: Acknowledge within 30 minutes, during business hours.
P3 – Standard
Impact: Minor issue or general inquiry.
Response: Acknowledge by 10:00 AM next business day. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
1. Support Levels Provided
SurroundCX™ offers three support tiers: Essential, Plus, and Premium:
• Essential includes core monitoring, incident management, and standard platform support.
• Plus adds proactive health checks, configuration assistance, and enhanced reporting.
• Premium delivers strategic guidance, advanced analytics, priority case handling, and dedicated personnel.
2. Support Costs
Pricing is subscription-based and varies by tier, user volume, and service complexity. Exact costs are defined in individual contracts and service-level agreements.
3. Dedicated Support Personnel
Only Premium clients receive a dedicated Technical Account Manager for strategic oversight and a Cloud Support Engineer for technical troubleshooting and optimisation. Essential and Plus tiers rely on shared support resources. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
We help users start using our service through a structured enablement programme combining training, documentation, and support:
• Onsite Training: For enterprise deployments, we offer “Train the Trainer” sessions at client locations, enabling internal teams to cascade knowledge effectively. These sessions include hands-on configuration, scheduling workflows, and performance monitoring.
• Online Training: Remote instructor-led courses and self-paced eLearning modules are available via the NiCE Learning Portal. These cover forecasting, scheduling, intraday management, and reporting, with practical exercises and role-based learning paths.
• User Documentation: Comprehensive PDF guides and quick-start manuals are provided, detailing setup steps, API usage, and troubleshooting. Documentation is accessible through the NiCE Help Centre and includes configuration guides for integrations like CXone and Webex CC.
• Additional Support: We provide access to a sandbox environment for safe experimentation, plus ongoing adoption support through webinars and community forums. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- PDF guides and service definition documents
- HTML-based online help portal
- Video tutorials and how-to playlists
- Interactive eLearning modules
- Quick-start user manuals
- API documentation in PDF format
- Knowledge base articles and FAQs
- Web-based release notes and updates
- Configuration and integration specification documents
- White papers and solution datasheets
- End-of-contract data extraction
-
When the contract ends, users can extract their data securely using multiple options:
• Self-Service Export: Customers can download data directly from the online portal in CSV format. This includes schedules, adherence reports, and historical performance data.
• API-Based Extraction: NiCE provides Data Extraction APIs for automated retrieval of WFM payroll data, interaction metadata, and reporting datasets. Users authenticate via OAuth and can schedule jobs to export data to secure storage (e.g., S3) for 24 hours.
• Managed Offboarding: For complex requirements, NiCE offers a time-and-materials service to handle large volumes, audio media, and metadata. Buyers can request fixed offboarding costs in their Call-Off Contracts, specifying formats and delivery methods.
• Security & Compliance: All data transfers use TLS 1.2+ encryption. Once extraction is complete, data can be deleted from NiCE systems upon customer request, ensuring compliance with GDPR and contractual obligations. - End-of-contract process
-
At the end of the contract, TTEC Digital NiCE IEX Workforce Management provides a secure and structured offboarding process.
Included in the Contract Price:
• Data Access Window: Customers retain access for a defined period (typically 30 days) to extract data.
• Standard Data Export: Self-service downloads of schedules, adherence reports, and historical performance data in CSV format.
• Secure Data Deletion: NiCE permanently deletes customer data upon request, ensuring GDPR and contractual compliance.
• Basic Support: Guidance on using self-service tools for data extraction.
Additional Cost Services:
• Managed Offboarding: For large or complex data sets (e.g., audio recordings, metadata), NiCE offers professional services billed on a time-and-materials basis.
• Custom Formats & Delivery: Requests for non-standard formats or encrypted physical media incur extra charges.
• Extended Access: Any extension beyond the standard data access window is chargeable.
• API Automation & Consulting: Assistance with bulk API exports or integration scripting is available at additional cost. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- Yes
- Compatible operating systems
-
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile app focuses on agent self-service, offering shift bidding, PTO requests, schedule viewing, and real-time notifications. It is optimised for quick, on-the-go interactions and supports limited offline functionality. The desktop version provides full administrative capabilities, including forecasting, scheduling, reporting, and configuration tasks. It offers advanced dashboards, analytics, and integration tools for workforce managers. While both share a consistent interface and core features, the desktop experience is designed for comprehensive management and planning, whereas the mobile app prioritises convenience and engagement for frontline staff.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- The TTEC Digital web-based customer self-service support portal is accessed through redemption of a secure invitation code sent directly to authorised personnel within the client business. Once registered, clients can open new support cases, and view existing support cases, priority, status, assigned contacts, case owners, date of creation and any updates provided by the TTEC Digital support engineering team.
- Accessibility standards
- EN 301 549
- Accessibility testing
- We conducted extensive interface testing to ensure compatibility with assistive technologies. Testing followed WCAG guidelines and leveraged the Voluntary Product Accessibility Template (VPAT) framework. We validated navigation and usability using screen readers such as NVDA, JAWS, and VoiceOver across desktop and mobile environments. Tests included keyboard-only navigation, ARIA tag verification, color contrast checks, and responsive font scaling. Automated audits using Axe complemented manual testing by accessibility specialists. Real-world usability was assessed with blind users to confirm logical reading order, form labeling, and dynamic content updates. We also verified compatibility with high-contrast modes and ensured focus management for interactive elements. These efforts guarantee that users relying on assistive technologies can access scheduling, reporting, and self-service features without barriers, supporting inclusivity and compliance with ADA and Section 508 standards.
- API
- Yes
- What users can and can't do using the API
-
How users can set up the service through the API:
Users can authenticate via RESTful SmartSync APIs using OAuth2 or JSESSIONID tokens. Initial setup includes creating API credentials, configuring endpoints, and enabling user synchronisation between CXone ACD and IEX WFM. APIs allow importing organisational entities (teams, skills) and exporting schedules for integration with external systems.
How users can make changes through the API:
Through WFM APIs, users can update agent schedules, retrieve real-time adherence data, and extract historical performance metrics. APIs support adding or modifying entities such as contact types and management units. Data extraction endpoints enable reporting and payroll integration.
Any limitations to how users can set up or make changes through the API:
APIs require technical expertise; NiCE does not support custom integration troubleshooting. Manual user sync is not supported, changes propagate automatically from CXone ACD. Some operations, like multi-tenant linking or altering OAuth clients during execution, are restricted. Rate limits and security policies apply. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
1. What can be customised:
Users can tailor their SandcastleCX™ environment to match specific CX use cases, technology platforms (e.g., Genesys, AWS, Microsoft, Salesforce and NiCE), integrations, and features such as voice routing, CRM connectors, bots, and reporting dashboards.
2. How users can customise:
Customisation is achieved through a guided, hands-on sandbox experience. TTEC Digital CX architects configure the environment based on client requirements, enabling iterative testing of workflows, integrations, and advanced capabilities. Optional add-ons like Learning and Performance Management or IP solutions can extend functionality.
3. Who can customise:
Authorised client stakeholders, typically CX leaders, IT teams, and solution architects, collaborate with TTEC Digital experts to define priorities and adjust configurations during the trial period.
Scaling
- Independence of resources
- We ensure service stability through multi-tenant isolation and elastic scaling. Each customer operates within logically isolated environments, preventing resource contention. Our cloud architecture uses auto-scaling clusters that dynamically allocate compute and storage based on real-time demand. Load balancing distributes traffic evenly across nodes, while QoS policies prioritise critical processes to maintain performance. Continuous monitoring detects anomalies and triggers proactive adjustments before impact occurs. Additionally, redundant infrastructure and failover mechanisms guarantee high availability even during peak usage. These measures collectively ensure that one user’s demand never degrades another’s experience.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Performance metrics: total calls handled, average handle time, service level adherence, agent productivity.
Individual agent performance: total calls handled, average handle time per agent, occupancy rate, customer satisfaction scores.
Performance customer service groups, providing metrics including average wait time, queue abandonment rate, service-level attainment, queue occupancy.
Call volume trends: users to analyse patterns and fluctuations in call volume to better allocate resources and staff.
Service level targets, providing metrics, including average speed of answer.
Percentage of customer inquiries/issues resolved on the first contact.
Rate at which callers abandon their calls while waiting in queue.
Performance of interactive voice response systems. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- TTEC Digital: Genesys, Microsoft, NiCE, Google, Shelf, ServiceNow – ttecdigital.com/services
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- We protect data at rest using AES-256 encryption across all storage layers, including databases, backups, and file systems. Encryption keys are managed through secure key vaults with strict rotation and access controls. Data is further safeguarded by role-based access permissions, ensuring only authorised personnel can retrieve sensitive information. Storage systems are hardened with disk-level encryption, and redundant copies are maintained in secure, geographically distributed environments. Regular integrity checks, vulnerability scans, and compliance audits (ISO 27001, SOC 2) ensure ongoing protection. These measures collectively guarantee confidentiality and resilience for all stored data.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users can export their data through multiple secure methods:
• Self-Service Portal: Download schedules, adherence reports, and historical performance data in CSV format directly from the web interface.
• API Integration: Use RESTful Data Extraction APIs to automate bulk exports of workforce data, including payroll and interaction metadata. Authentication is via OAuth2 for security.
• Managed Service: For large or complex datasets, NiCE offers professional offboarding support on a time-and-materials basis. All exports use TLS 1.2+ encryption, and customers can request permanent data deletion after extraction to ensure GDPR compliance. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLSX – Microsoft Excel spreadsheet format
- PDF – Portable Document Format for reports
- XML – Structured data for integrations
- JSON – Lightweight data exchange format
- TXT – Plain text for simple data sets
- HTML – Web-ready formatted reports
- DOCX – Microsoft Word document format
- ZIP – Compressed archive containing multiple files
- RTF – Rich Text Format for readable documents
- Excel Pivot Table (.xlsx) – For advanced analytics
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- CSV – Common for schedules and workforce data
- XLSX – Microsoft Excel spreadsheets
- XML – Structured data for system integration
- JSON – Lightweight data exchange format
- TXT – Plain text files
- ZIP – Compressed archives containing multiple files
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- We protect data in transit using end-to-end encryption and secure tunneling. All traffic between the buyer’s network and our platform is encrypted with TLS 1.2/1.3, ensuring confidentiality and integrity. We enforce mutual authentication via certificates to prevent unauthorised access. Additionally, IP whitelisting and VPN options provide controlled connectivity for sensitive environments. Data packets are monitored for anomalies using intrusion detection systems, and session keys are rotated regularly to mitigate interception risks. Combined with strict compliance to ISO 27001 and GDPR, these measures guarantee secure, tamper-proof communication between networks.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- We safeguard data within our network using segmentation and encryption at rest. Sensitive information is stored in encrypted databases using AES-256, and keys are managed through secure vaults with strict rotation policies. Access is controlled via role-based permissions and enforced through multi-factor authentication. Network traffic is monitored by intrusion detection and prevention systems, while firewalls and micro-segmentation limit lateral movement. Regular vulnerability scans and penetration tests ensure compliance with ISO 27001 and SOC 2 standards. These layered controls maintain confidentiality, integrity, and availability across all internal systems.
Availability and resilience
- Guaranteed availability
-
Guaranteed Availability:
Our NiCE IEX Workforce Management SaaS service is designed for 99.9% uptime per calendar month, excluding scheduled maintenance windows. Monitoring is continuous, and redundancy is built into our cloud architecture to minimise downtime.
Service Level Agreements:
• 99.9% uptime commitment measured monthly.
• Scheduled maintenance is communicated in advance and performed during low-usage periods.
• Real-time status updates are available via the NiCE Service Portal.
Refunds and Remedies:
If availability falls below the guaranteed level, customers are eligible for service credits applied to future invoices. Credit amounts are tiered based on the severity of the breach. Refunds are processed according to the terms outlined in the Call-Off Contract. - Approach to resilience
-
Our service is designed for resilience and continuity, aligned with the UK Government’s Cloud Security Principle 2.
Resilient Architecture:
NiCE IEX Workforce Management operates on a cloud-native infrastructure with geographically distributed data centres across multiple availability zones. This design ensures redundancy and failover capability in case of hardware or network failures. Data is replicated in real time to secondary sites, minimising risk of data loss.
Disaster Recovery:
We maintain a documented disaster recovery plan with automated failover and regular recovery testing. Recovery Point Objective (RPO) and Recovery Time Objective (RTO) targets are defined to ensure rapid restoration of service.
High Availability:
Load balancing and clustering are implemented to prevent single points of failure. Continuous monitoring and proactive health checks help maintain uptime and performance.
Data Protection:
All data is encrypted in transit and at rest using TLS 1.2+ and AES-256 standards. Backup copies are stored securely and tested regularly. - Outage reporting
-
Public Dashboard:
We provide a real-time status dashboard accessible via our support portal. It displays current service health, ongoing incidents, and historical uptime metrics. Users can check component-level availability and maintenance schedules at any time.
API:
An Incident Status API is available for integration with your monitoring tools. It delivers JSON-formatted outage data, including severity, affected services, and estimated resolution times, enabling automated alerts and dashboards.
Email Alerts:
Customers can subscribe to email notifications for outages, maintenance events, and resolution updates. Alerts include incident details, impact assessment, and recovery progress, ensuring timely communication to stakeholders.
Our reporting process aligns with ISO 27001 and SOC 2 standards, ensuring transparency and compliance.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- We authenticate users through secure, multi-layered controls. Access begins with username and password validation, enforced by strong complexity and rotation policies. We support Multi-Factor Authentication (MFA) using one-time codes or authenticator apps to prevent unauthorised access. For enterprise customers, Single Sign-On (SSO) via SAML 2.0 or OAuth integrates with identity providers like Azure AD. All sessions use TLS encryption and token-based authentication to maintain confidentiality. Role-based access controls ensure users only access resources aligned with their permissions. These measures collectively provide strong identity assurance and compliance with ISO 27001 and SOC 2 standards.
- Access restrictions in management interfaces and support channels
-
Access Restrictions:
Administrative access is limited to authorised personnel using role-based permissions and least-privilege principles.
Authentication:
All access requires multi-factor authentication (MFA) and secure VPN connections for remote sessions.
Session Security:
Interfaces are protected by TLS encryption, session timeouts, and continuous monitoring for anomalies.
Support Channels:
Customer support interactions are authenticated, logged, and conducted through secure portals. Sensitive actions require identity verification and approval workflows.
These measures ensure only verified users can manage or support services securely. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
PCI DSS Level 1
SOC 2 Type 2
HIPAA
Cyber Essentials
Cyber Essentials Plus - Information security policies and processes
-
TTEC's Global Information Security (GIS) reports to the VP and Chief Security Officer. The GIS department is within TTEC’s Security, Resiliency and Governance organisation, reporting to TTEC's Chief Information Officer.
TTEC’s robust Global Privacy, Risk, Compliance, Network, and InfoSec programmes are based on the guiding principles of: Availability; Integrity; and Confidentiality. These principles are achieved through defined policies, industry controls, with infosec and privacy trainings, and through the governance structure within our corporate GIS, IT, Legal and Risk Executives.
TTEC’s policies/procedures comply with ISO 27002 compliance framework that standardise the following security elements:
•InfoSec Policy & Organisational Measures
•Asset/Data Classification
•Human Resource Security- Corrective Actions
•Physical/Environment Security
•Communication/Operation Management
•Access/Authentication/Password Management
•Data Encryption
•InfoSec Acquisition Development/Maintenance
•Endpoint Security
•Auditing, Logging, Monitoring
•Vulnerability, Penetration, Patch Management
•Network Security, Configuration Management
•Applications, SDLC, Change Management
•Incident Response Management
•Security, Fraud, Ethics Code Training- Accountability
•BCP/DR
•Global IT/Risk Management
•Regulatory Compliance
TTEC performs periodic and annual, internal, and external independent, third party, qualified, industry compliance audits of the TTEC organisational controls and technology environments. TTEC continues to achieve ongoing industry compliance accreditation with PCI DSS (SL-1), ISO 27001, SOC 2 Type II (SSAE 18), Cyber Essentials Basic & Plus, and more. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Component Tracking:
All service components are tracked throughout their lifecycle using a Configuration Management Database (CMDB). Each asset is assigned a unique identifier, with version history and dependencies recorded to maintain visibility and integrity.
Change Assessment:
Changes follow a formal Change Advisory Board (CAB) process. Every modification undergoes risk and security impact analysis, including vulnerability checks and compliance validation. Approved changes are implemented with rollback plans and logged for audit purposes. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Threat Assessment:
We continuously monitor for vulnerabilities using automated scanning tools and perform risk-based analysis to assess potential threats to services.
Patch Deployment:
Critical patches are deployed within 24 hours, while high and medium-risk updates follow defined SLAs to ensure timely remediation.
Threat Intelligence Sources:
We leverage vendor advisories, CVE databases, CSA alerts, and threat intelligence feeds from trusted security partners to stay ahead of emerging risks. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Identifying Potential Compromises:
We use SIEM tools and real-time log analysis to detect anomalies, unauthorised access attempts, and suspicious patterns. Alerts are generated for predefined indicators of compromise.
Responding to Potential Compromises:
Incidents trigger an automated containment workflow, followed by manual investigation. Actions include isolating affected systems, revoking credentials, and applying patches.
Response Time:
Our Security Operations Centre (SOC) operates 24/7, with initial response within 15 minutes of detection and full remediation initiated immediately per severity level. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Pre-Defined Processes:
We maintain documented playbooks for common incidents, including service outages, security breaches, and performance degradation. These processes ensure rapid, consistent response.
User Reporting:
Users can report incidents via 24/7 support channels, including a dedicated portal, email, and phone hotline. Automated alerts also trigger internal escalation.
Incident Reports:
We provide detailed post-incident reports outlining root cause, impact, and corrective actions. Reports are shared through secure channels and archived for compliance. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- SandcastleCX™ provides a secure, customised sandbox for testing and exploring CX technologies, including CCaaS, CRM, AI, and analytics. It offers expert guidance, platform validation, and flexible trial access at no cost for standard use cases. Ideal for innovation and proof-of-concept projects, enabling rapid evaluation without production risk.
- Link to free trial
- https://youtu.be/hNmqTiNkIx8?si=9cRF7IADXikWKBm7
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.2%
- Between £500,001 and £1,000,000
- 4.2%
- Between £1,000,001 and £2,500,000
- 6.2%
- Between £2,500,001 and £5,000,000
- 8.2%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Coalfire Certification, Inc.
- ISO/IEC 27001 accreditation date
- Thursday 21 August 2025
- What the ISO/IEC 27001 doesn’t cover
- Certification available on request.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- PCI Security Standards Council
- PCI DSS accreditation date
- Friday 28 November 2025
- What the PCI DSS doesn’t cover
- Certification available on request.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2807b81c-9543-492c-805b-f1fd3347313f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 613c9a41-2540-4e86-811e-d9808a365c26
- Other security certifications
- Yes
- Any other security certifications
-
- SOC 2, Type II
- HIPAA
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Content of the outreach activity is designed to suit the target cohort
-