Security and Compliance
Security and compliance
built into our platform
Security, privacy and compliance are fundamental to the services Evolve IP delivers.
Our cloud platforms and operational controls are designed to help partners support customers with demanding security, regulatory and data protection requirements.
Through recognised standards, independent assessments and established compliance frameworks, we provide partners with greater confidence when taking Evolve IP solutions to market.
Our security and compliance framework

ISO/IEC 27001
ISO/IEC 27001 is an internationally recognised standard for information security management systems.
It provides a structured framework for identifying information security risks, implementing appropriate controls and continually improving the way sensitive information is protected.
For partners and customers, ISO 27001 certification provides independent assurance that information security is managed through documented and auditable processes.

HITRUST CSF
The HITRUST Common Security Framework brings together requirements from a wide range of recognised security and privacy standards.
It is particularly relevant to businesses handling sensitive healthcare information and provides a structured approach to managing security, privacy and regulatory risk.
HITRUST incorporates requirements drawn from frameworks and regulations including HIPAA, ISO 27001, NIST and PCI DSS.

HIPAA
The Health Insurance Portability and Accountability Act establishes requirements for protecting sensitive healthcare information in the United States.
Evolve IP solutions can support customers with HIPAA-related requirements through appropriate technical, administrative and physical safeguards.
This is particularly relevant to partners working with healthcare providers and businesses that process protected health information.

PCI DSS
The Payment Card Industry Data Security Standard provides security requirements for businesses that store, process or transmit payment card information.
PCI DSS-aligned controls help reduce the risk of cardholder data being compromised and support customers that handle payment information through communications or contact centre environments.
This is especially relevant to partners supporting retail, hospitality, financial services and customer service operations.

SOC 2
SOC 2 is an independent reporting framework used to assess controls relating to areas such as security, availability, confidentiality, processing integrity and privacy.
A SOC 2 Type II report evaluates both the design of controls and how effectively those controls have operated over a defined period.
It provides partners and customers with additional assurance around the controls used to protect systems and information. A Microsoft listing previously recorded a SOC 2 Type II status for the Evolve Contact Suite, although the current scope and report date should be confirmed before publication.
Helping partners address complex customer requirements
Security and compliance questions can often slow down or complicate technology decisions.
Evolve IP gives partners access to established controls, specialist expertise and supporting documentation to help them respond to customer due diligence and build confidence throughout the sales process.
Whether supporting healthcare, financial services, retail, education or another regulated sector, our team can help partners understand which standards and controls apply to each opportunity.
