Securing SaaS-Based Virtual Call Centers and Virtual PBXs

Virtual Call Center and Virtual PBX solutions that are based on SaaS are secure and resilient.Customer communications is the lifeblood of your business.  The integrity of your business communications system is critical to your company’s success.  A cloud-based business communications solution can deliver all the features and benefits of a “big company” call center at a fraction of the price of a conventional solution, but can it provide the security and dependability you’ve come to expect in a premises-based solution?

When evaluating a SaaS-based solution it is important to investigate the platform’s security and reliability features.  A complete solution provides three levels of protection – protection at the data center level, protection at the network level, and protection at the application level.

Data center level protection ensures the application is housed in a safe and dependable environment.  Application level protection ensures the service is highly available (not susceptible to hardware failures) and secure (not susceptible to hackers and unauthorized users). Network level protection ensures your company’s traffic is transported in a secure and reliable fashion.

OnState understands the integrity of your customer communications system is vital to your business.  Our cloud-based service provides the multi-level protection you need to safeguard your business-critical communications.  We host our service in a secure and reliable Equinix IBX data center,  exploit VMware to achieve application reliability and scalability, and leverage redundant interfaces to multiple Tier 1 providers to ensure network availability.  We have access and egress agreements with over a dozen providers and deliver service in over 40 countries.

cloud security

SAS 70 Type II Data Center • >99.999% availability • 24 x 365 physical security • Fire detection and suppression, flood control, earthquake protection • Redundant power, UPS, and HVAC

With OnState’s SaaS-based solution you can enjoy all the features and benefits of an enterprise-class call center system without sacrificing the security or reliability to which you are accustomed.

Data Center Level Protection
OnState is hosted in a secure SAS 70 Type II Equinix IBX data center. With over 2000 global enterprise, service provider, and content company customers, Equinix is the partner of choice for the world’s most demanding businesses and most-trafficked sites.  Leading companies like Google, IBM, and Yahoo! have all selected Equinix as their outsourced IT infrastructure provider.

Equinix has built the most reliable facilities in the industry and consistently delivers 99.999% uptime.  Their world-class, network-neutral data centers provide:

  • Physical security to control, monitor, and record access to the facility
  • Fire detection and suppression, flood control and earthquake protection to safeguard against natural disasters
  • Redundant power, UPS and HVAC to maximize system uptime
  • Redundant connections to Tier 1 providers to protect against network failures
  • On-site protection from the U.S. National Guard during certain security threat level conditions

SAS 70 (Statement on Auditing Standards No. 70) is an internationally-recognized auditing standard developed by the American Institute of Certified Public Accountants (AICPA).  In order to attain SAS Type II compliance Equinix has passed an in-depth audit covering security monitoring, change management, problem management, backup controls, physical and environmental safeguards and logical access.

Application Level Protection
OnState leverages VMware for high availability and scalability.  The application is instantiated on a virtual machine that spans multiple physical servers and storage devices.  The service is unaffected by individual component failures.  Inherent VMware fault tolerance features protect against physical failures, including network card failures, storage path failures, and other hardware failures.  Core components such as SIP servers and media servers are replicated and Acme Packet Session Border Controllers are also used to provide load-balancing and fail-over capabilities for SIP traffic.  In addition, by migrating virtual machines, routine maintenance functions (hardware upgrades, software upgrades, etc) can be performed without service disruption.

The virtual machine concept can be extended across multiple Equinix data centers to protect against catastrophic events. These geographically-disparate data centers are located on separate flood planes, electrical grids, and earthquake zones. saas security

Carrier-Class, Geographically-Distributed Architecture • Fully-distributed VMWare implementation • Geogrpahically-dispersed data ceters • Separate flood planes, electrical grids, fault lines • Multiple redundant interconnects • Continuous availability

OnState features a browser-based Administrative interface for monitoring, configuring and controlling users and services. The interface utilizes encrypted passwords for secure authentication and authorization. Only authorized administrators can create and manage user accounts, define policies and system settings, or produce usage and performance reports. By enforcing strict access control policies OnState safeguards the integrity of confidential customer data and protects against toll fraud and service theft.

OnState employs comprehensive CheckPoint security systems and practices to defend against intruders and hackers. Our servers are protected by multiple levels of firewalls to guard against malicious attacks. To reduce security risks, we limit or disable unused operating system services. In addition we scan our software for security vulnerabilities and employ a variety of threat evasion techniques to protect against denial of service attacks and other malicious threats.

Network Level Protection
Unlike conventional hosted voice solutions, OnState works with a variety of networks (PSTN, VoIP/SIP, and Internet) so you can choose the network technologies and service providers which best meet your needs – including your security and SLA requirements.

A flexible service, OnState is easily integrated into just about any environment. You can connect OnState to a PBX using PSTN trunking or SIP trunking. PSTN trunks offer time-tested reliability and security. Many of today's SIP trunk providers offer SLAs and security features that rival those of conventional analog or PRI circuits.

OnState supports stand-alone SIP endpoints, Skype clients and GoogleTalk clients for remote users and for smaller offices without PBXs. Most SIP endpoints support SRTP (Secure Real-time Transport Protocol) or other security protocols to provide encryption and guarantee privacy. Similarly, GoogleTalk and Skype feature inherent encryption capabilities to provide privacy and protect against eavesdropping. virtual workforce environments

Conclusion
Customer communications is the lifeblood of your business. OnState delivers the multilayer security you need to protect your business-critical communications. With OnState you can enjoy all the advantages of an enterprise-class call center solution without sacrificing security or reliability – all for a fixed monthly fee, with no upfront equipment purchases.

1.617.934.0381
1.866.532.5036

OnState | Web-based call center, locates your staff ANYWHERE, with low pay-as-you-go pricing

Copyright 2010 OnState Communications all rights reserved.