Hostcomm Ltd · Company 05113945

Certifications, and the evidence behind them.

Every compliance claim Hostcomm makes on this site is listed below with its issuer, its identifier and the date it was validated. Where a document can be published, it is linked. Where it can only be shared under NDA, that is said plainly rather than implied.

Last reviewed 2 September 2026. Reviewed quarterly, and within five working days of any certification change.

What Hostcomm holds.

Four certifications and registrations, each independently verifiable at the issuer.

Certification
Issued or assessed by
Reference
Scope
PCI DSS v4.0.1, Level 1 Service Provider
Securious Ltd, Qualified Security Assessor, Exeter. Lead assessor Darren Grey, QSA certificate 207-021. Validated 17 July 2026, valid to 17 July 2027.
Attestation of Compliance for Report on Compliance — Service Providers, PCI DSS v4.0.1
Payment IVR and agent-assisted payment capture. Card details are entered by the caller into the IVR and passed to the payment processor; they are not spoken to an agent, held on the platform, or written to a call recording.
ICO registration
Information Commissioner’s Office
Registered as both data controller and data processor. DPA available pre-contract.
G-Cloud 14
Crown Commercial Service, UK Digital Marketplace
Service ID 9579 0487 8523 780
Hostcomm Cloud Contact Centre & Predictive Dialler. View the listing, including published pricing and service definition.
Companies House
Companies House
05113945
Hostcomm Ltd, incorporated 2004. Registered office: The Old Convent, 8 Broad Street, Ottery St Mary, Exeter EX11 1BZ. View the register entry.

Ofcom’s abandoned call rule, and the controls that keep you inside it.

Predictive dialling is lawful in the UK, and it is bounded. The boundary is a published figure. The controls below are the ones you set to stay the right side of it.

3%

The maximum proportion of live calls that may be abandoned, measured per campaign over any 24-hour period, under Ofcom’s statement of policy on persistent misuse. An abandoned call must play an information message within two seconds, and a called number that abandons must not be dialled again by the same campaign for 72 hours except with a live agent.

Source: Ofcom, persistent misuse of an electronic communications network or service. Hostcomm provides the controls and the audit trail; the settings you run and compliance with them remain yours.

  • UK drop-rate calculation, not the US method

    The platform can calculate abandoned calls the way Ofcom defines it rather than by the US metric. It is enabled in system settings and then switched on per campaign, so a UK campaign is measured against the UK rule.

  • Per-campaign abandon rate target

    Set a target abandon rate on the campaign and the pacing adjusts the dial ratio to hold it, rather than reporting the breach afterwards.

  • Drop lockout time

    A per-campaign setting, in hours, that stops a number which received an abandoned call being redialled automatically. Set it to 72 hours to match Ofcom.

  • Information message on abandoned calls

    Abandoned calls play a recorded message identifying the caller and giving a number to opt out. Ofcom requires it within two seconds of the call being answered.

  • Answer-machine detection, and its cost

    AMD is available and its use is logged. Ofcom expects the detection decision inside two seconds and counts AMD false positives toward the abandoned call rate, so on tight campaigns the right answer is sometimes to turn it off.

  • CLI presented on every call

    A valid, dialable presentation number on every outbound call, answered during normal business hours. Rotating or withheld CLI breaches both Ofcom rules and UK carrier terms.

  • TPS and CTPS screening

    Lists are screened against the Telephone Preference Service and its corporate equivalent at load time or through the API, so opted-out numbers are not dialled.

  • Recordings analysed in the UK

    Where calls are transcribed or scored, that inference runs in AWS London on open-weight models via OnshoreAI. Recordings are not sent to a US AI provider to be read.

These are settings, not defaults. A dialler shipped with US metrics will happily run a UK campaign and report a compliant-looking drop rate calculated the wrong way. Hostcomm configures the UK calculation, the lockout time and the abandon target with you at onboarding, and the resulting rates, AMD decisions and opt-out requests are logged and exportable — the record you need if Ofcom asks.

Where your data is, precisely.

“UK hosted” means different things at different vendors. Here is what it means here.

Hosting region
Amazon Web Services London, eu-west-2. No processing or storage outside the United Kingdom.
Call recordings
Stored in eu-west-2, encrypted in transit and at rest. Retention is set per contract rather than by a standard period, because most customers apply their own policy, and recordings, transcripts and backups can each be held for different lengths of time. Your retention schedule is written into the DPA.
Voice carriage
Direct interconnect with BT Wholesale and other UK carriers. Calls are not routed via overseas wholesale partners.
Tenancy
Dedicated server and firewall per customer, not shared multi-tenant infrastructure.
AI processing
Inference runs in AWS London (eu-west-2) on open-weight models via OnshoreAI, Hostcomm’s UK-sovereign inference API. Transcription, interaction analytics, agent assist and AI voice agents are all served from it, so prompts and responses stay under UK jurisdiction. No US or EU transfer, and therefore no SCCs, no UK IDTA and no Transfer Risk Assessment.
Sub-processors
Listed in the DPA and notified in advance of any change.
Support access
UK-based support engineers only. No offshore tier one, and no administrative access from outside the UK.

Documents.

Both are available to anyone evaluating Hostcomm. Neither is published, because both describe assessed scope and infrastructure.

PCI DSS Attestation of Compliance

The signed AoC for Report on Compliance, Service Providers, PCI DSS v4.0.1, validated by Securious on 17 July 2026. It sets out the assessed scope and the underlying infrastructure, so it is shared under NDA rather than published. Ask and it is usually with you the same day.

Under NDA — request it

Data Processing Agreement

The DPA, including the sub-processor list, the security schedule and your retention schedule. Available before contract, not after — send it to your DPO while you are still evaluating.

Pre-contract — request it