Vodafone storm
Single-stack, omni-channel Contact Centre as a Service (CCaaS), providing AI backed Customer Experience communications solutions. Offering Inbound and Outbound Voice, Video, SMS, Webchat, WhatsApp, Social Media, E-Mail, Work Items (Case Management). APIs for integrations available, including Databases, CRM and Microsoft Teams. Automation, NLP, Transcription, Summarisation, Sentiment Analysis, Agent Assist available.
Features
- Omni-channel contact centre solution with AI backed services
- 99.999% availability and unlimited scalability, with UK data sovereignty
- AI powered Agent Assist: Transcription, Summarisation and Knowledge Management
- Advanced IVR: Speech Recognition, Natural Language Processing, skills-based routing
- Intelligent Automation with Artificial Intelligence (AI), data capture and integration
- Detailed real-time and historical reporting and enhanced analytics
- Fully customisable Customer Data Platform (CDP), Customer Relationship Management (CRM)
- Fully embedded Unified Communications (back office) and Microsoft Teams integration
- Workforce Management (WFM) and Workforce Optimisation (WFO)
- Carrier grade voice service. Secure, private connectivity also available
Benefits
- Voice and digital interactions easily managed via a single interface
- Hours saved daily through AI and generative AI agent assist
- Automation and Machine Agents free up human agent availability
- Reduction in queue times and abandonment rates, increasing customer satisfaction
- Allow agents to work from anywhere, securely
- Evergreen solution ensures future proofing and availability of latest technology
- Personalised interactions through Customer Data Platform and integrations
- Easily adapt and optimise performance using detailed Management Information (MI)
- Reduce costs though increased productivity, with easily demonstrable ROI
- One provider for full Contact Centre, voice and connectivity solution
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 4 9 8 5 9 7 6 6 8 8 0 8 2 9
Contact
VODAFONE LIMITED
Frameworks Team
Telephone: 07775671027
Email: frameworks_team@vodafone.com
About your service
- Service categories
-
Applications
Customer relationship management
- Contact centre
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- N/A. Evergreen solution, managed in Active/Active state, allowing for maintenance and updates to take place without disruption.
- System requirements
-
- Internet Access (can be provided as part of the solution)
- Microsoft Edge (latest version recommended)
- Google Chrome (latest version recommended)
- Mozilla Firefox (latest version recommended)
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is provided 24/7/365. Tickets are categorised based on their impact and response times are dependent on assigned severity: P1 - 15 mins, P2 - 30 mins, P3 - 4 Hours, P4 - 1 day
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- .
- Web chat accessibility testing
- .
- Onsite support
- Yes, at extra cost
- Support levels
-
ITIL-based 24/7/365 support included as standard, with UK-based service teams.
Tickets are categorised according to service impact (P1 - P4) as defined in standard service level agreement, please see terms and conditions.
Service Management, enhanced levels of change & problem management and dedicated support services can be provided at extra cost. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Instructor-led training is provided by solution experts and is tailored to the solution specification delivered for each buyer. This can be onsite or online via webinar.
Online help and user guides are available for each interface. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Buyers can extract data themselves using the Vodafone storm interface. However, this can be a service provided by Vodafone at extra cost.
- End-of-contract process
- Buyer CDRs, recordings and configuration is available to all the buyers users with appropriate logins to extract, as part of the contract. Extra charges may be incurred if the extraction is provided by Vodafone. Decommissioning of the buyer partition and removal/destruction of data is carried out as part of the contract upon termination.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Online through web browser, or via PDF documents which are provided during onboarding.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The Mobile client is designed for back office users only.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- All interfaces are browser based. Includes an Agent desktop, a supervisor interface and admin interfaces.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- No official and documented testing as been conducted at this point in time.
- API
- Yes
- What users can and can't do using the API
-
API documentation can be provided covering all elements of the storm solution. Documentation outlines all SOAP and REST APIs available.
API 'key' is required per customer.
Bespoke and off-the-shelf API's are available, subject to agreed specification. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Features and functionality can be fully customised, either by using the FLOW tool to amend service flows (by the user), or by bespoke development (by the supplier).
The Vodafone storm solution is an 'off the shelf' solution allowing customisation through deep levels of configuration capability down to the user and service.
Scaling
- Independence of resources
-
Storm is Europe’s largest cloud-based Communications Integration platform, providing users with access to massive capacity. The platform can be scaled to accommodate services for any size of business and live services can be instantly scaled up when required without impacting service for other users.
Vodafone storm provides buyers with access to an effectively unlimited number of ports in the cloud, with the platform able to accommodate tens of thousands of simultaneous calls through the Vodafone carrier-grade network.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Fully flexible and customisable real-time and historical reporting across any channel within the platform. Real-time notification alerts on service performance, trend analytics and service levels. Recording and Screen Recording capabilities with transcription, sentiment analysis, speech analytics alongside AI-assisted scorecards and associated reporting.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Content Guru
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Buyers can export all data within the reporting dashboard, either as ad-hoc, manual exports or regular exports via FTP or email. It can be used to extract multiple different areas of data, based on customisable criteria such as time periods.
Recordings can also be imported / exported via .WAV file format. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- WAV
- API
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- WAV
- API
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Vodafone storm has a core Platform SLA of 99.999%.
Service Credits are available for failure to meet this. - Approach to resilience
- The Vodafone storm platform is maintained across multiple geo-redundant, secure data centre sites. All constituent data centres supporting the platform are connected by resilient 1GB links, which are continuously subject to monitoring. All data centres and servers are kept in an active-active configuration, with the resilient connections between them enabling the ongoing synchronization of all services and data.
- Outage reporting
- Email alerts are provided by the Service Desk.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Each organisation’s Vodafone storm solution requires the purchase of one or two administrator licences. Administrators require these separate licences to access admin privileges. As with all users, these require storm's multi-factor authentication, or Single Sign On (SAML2.0 based). Administrator seats are assigned to named users. Supervisors can be given restricted access to above-standard features, and this is fully-configurable by administrators.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
Cyber Essentials Plus
PCI-DSS Level 1
SOC 2 Type 2
ISO27701
ISO22301 - Information security policies and processes
- Adheres to ISO 27001. All data centres are accredited to IL-3 standard. The building is protected by physical security barriers and card access points, visitors are logged. User logins are RSA-authenticated, requiring PINs (minimum 4 digits) followed by an RSA SecurID that refreshes every 60 seconds. VPN access is restricted to the necessary employees. All successful or failed accesses to certain areas, such as audit trails or cardholder data, are logged. System logs are reviewed several times daily by engineers. Errors or exceptions are logged in an xcl file. Items are assigned owners according to expertise, and investigated. This file is reviewed by an Engineering Manager, ensuring all investigated items are progressed or closed. Access to the raw data is restricted to the Engineering Manager, ensuring a copy of the audit cannot have been tampered with. All servers within the CDE are time-synchronised to ensure consistency, and synchronised every 15 mins. A security manager ensures policies are adhered to and is the point of contact for all security incidents. All employees are given security policy with compulsory security training. Heads of departments attend ISMS reviews. Security incidents are recorded in the Security Audit Report maintained by the Security Manager
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Hardware or software changes on Vodafone storm may be of the following types: Standard changes, changes to services requested by clients & emergency changes. In all cases, a Hardware/Software Change Request form must be completed before the work is carried out. Requests for hardware and software changes are submitted to the Vodafone Change Control team to audit. Vodafone storm teams ensure all changes conform to release notes. All work is undertaken in pre-production and must be tested and signed-off by a senior engineer and Change Control team. Customers are notified. Jira / Remedy is used to approve and track changes.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- The vendor employs an approved third party scanning vendor to perform internal and external vulnerability scanning. Based on the information provided on a regular basis by the third party, the vendor's security team review and action the necessary patching. All patches are tested in the lab environment prior to live roll-out. Frequency of deployments are based on criticality of patches and schedule of planned work.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Vodafone storm is monitored continuously day and night, on a 24/7 basis. The processes include interrogation of data logs and real-time alerts based on system performance. Potential compromises are actioned immediately by the support team, using established processes.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Vodafone has standard documented procedures for incident management. User reports incidents to the Engineering Services team as part of the standard ticketing procedure. Incident reports are issued as per the agreed SLAs.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Friday 16 August 2024
- What the ISO/IEC 27001 doesn’t cover
-
The Information Security Management System covers Vodafone UK mobile, Fixed and UCS Services and the Business Units that enable and support those Services. Locations are identified by the Services and Business Units that they support. All Annex A controls have been deemed applicable in accordance with the Design, Build and Run model & the Statement of Applicability Version 0.1.
The Data Centre locations are covered by the Vodafone Group ISO27001:2022 certificate.
issued by LRQA - 08/07/25.
Information Security Management System of Vodafone Group functions covering:The Provision, Maintenance and Operations for
Cyber Defence, Data Centres, Network, Infrastructure and Application services for Local Markets and Vodafone Business; Office IT
services, Shared Service Centres and relevant Business Processes.Vodafone Business services includes International Network
Connectivity, Unified Communications, Internet of Things, Cloud & Hosting and Customer Service Desks. This is in accordance with
Statement of Applicability version 19.
Therefore all elements of the proposed services are covered by these certifications. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Tuesday 15 September 2026
- What the ISO 9001 doesn’t cover
- Vodafone UK certificate does not cover Vodafone Group, this is covered by a Vodafone Group ISO9001 certification.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- NCC Group Security Services Ltd
- PCI DSS accreditation date
- Monday 7 July 2025
- What the PCI DSS doesn’t cover
- This does not cover UC, AWS or Azure. This are covered by separate certification.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E7b3eb7f-32e7-436f-9d63-b023df698463
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Af87bed1-45db-4396-b5a5-0703ffdc35ce
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-