Fees for acquiring new numbers and porting existing numbers (one-time or periodic per-number).
Maintenance and support:
Maintenance window coverage, software updates, bug fixes, and access to support portals.
Support tiers (Standard, Premium/Enterprise) with different response times and SLAs.
Professional services (optional):
Custom development, integration work, data migration, and advanced training.
Hardware costs (if any):
SBCs, gateways, or edge devices if required for on-prem components or hybrid deployments.
Taxes and regulatory charges:
Regional taxes or telecom regulatory fees that may apply.
Training
New-user onboarding
Admin training: guidance on the admin portal, user provisioning, role-based access, and configuration of basic call flows.
End-user training: how-to sessions or resources for handling calls, voicemail, IVR navigation, and basic reporting.
Self-service resources: access to knowledge base, product documentation, and how-to articles.
Delivery formats
Live training sessions: instructor-led webinars or on-site workshops (where available).
Recorded sessions: on-demand video tutorials covering common use cases (IVR, routing, integrations, reporting).
Live Q&A and office hours: periodic sessions with product experts for real-time questions. Note: Availability can depend on the product tier and region.
Onboarding support
Implementation assistance: guidance during discovery, design, provisioning, and go-live planning.
Data migration help: assistance with porting numbers, user directories, and essential data mappings.
Proof of concept / pilot guidance: setup help to validate key workflows before full rollout.
Documentation and enablement
Admin guides for configuration and maintenance tasks.
Developer docs for integrations, webhooks, and API usage.
Support tiers: Standard, Premium, or Enterprise support with defined SLAs.
SLA considerations typically include:
Response time targets (e.g., P1/P2 issues)
Availability windows
Access to a dedicated account or technical contact (at higher tiers)
Community and partner channels
Partner ecosystem: certified partners for extended onboarding, customization, and integration services.
Community forums or user groups may be available in some regions.
Security Measures
Data in transit and at rest
Encryption: TLS for data in transit; encryption options for stored media and data at rest where applicable.
DTLS/SRTP: for secure media transport in SIP communications (where supported).
Access control and identity
RBAC (Role-Based Access Control): granular permissions for admins, agents, and supervisors.
Multi-factor authentication (MFA): optional/enforced for privileged access.
Directory integration: support for SSO (SAML/OIDC) with existing identity providers.
Data handling and retention
Call recording policies: configurable retention windows, access controls, and consent handling.
Data minimization: configurable data collection aligned with usage and compliance needs.
Compliance and auditability
Audit logs: activity logs for admin actions and configuration changes.
Data residency options: regional data storage choices where available.
Regulatory alignment: capabilities to support PCI-DSS, HIPAA, GDPR, or other region-specific requirements (confirm with vendor for your jurisdiction).
Updates
Update frequency
Regular minor releases: monthly or quarterly updates with bug fixes, performance improvements, and small enhancements.
Major releases: less frequent, typically aligned with feature-rich upgrades or architectural changes.
What updates cover
Bug fixes: stability and security patches.
Security updates: patches for newly discovered vulnerabilities.
Feature enhancements: new capabilities, improvements to existing flows, and new integrations.
Deprecations: sunset of old features or APIs with advance notice.
Delivery and deployment
Managed rollout: updates may be pushed automatically for cloud deployments, with options for controlled or phased rollouts.
Self-service upgrade options (if applicable): some environments may allow admins to trigger upgrades within the admin portal.
Change management and communication
Release notes: published with each update detailing new features, fixes, and any changes that could affect configurations.
Backward compatibility: guidance on deprecated features and suggested migration paths. Pre-release access: beta or preview programs may be available for select customers.
Impact on customers
Testing windows: recommendations to test updates in a staging environment prior to production cutover.
Upgrade planning: timeline and change communication to minimize disruption.
Data Ownership and Portability
Data ownership
In most arrangements, your organization retains ownership of its own data (calls metadata, recordings, contact data, logs) generated or stored within the Anveo platform.
Anveo typically acts as a data processor/service provider for the data on your behalf, under a data processing agreement (DPA) or equivalent terms.
Data access and control
Data access controls should be governed by RBAC in the Admin Console, with audit logging for admin actions.
Data portability (export)
Availability of data export capabilities (e.g., CSV, JSON, or API access) for:
Call data, recordings (subject to retention policies and legal/privacy constraints)
Contacts, queues, IVR configurations
Reports and analytics
Portability windows and formats are often defined in the DPA or contract addendum.
Data retention and deletion
Retention policies for call recordings, logs, and analytics data should be configurable (e.g., 30/90/180 days or longer).
Retention and deletion rights: you should be able to request data deletion at end-of-contract or per data retention policy, with a defined Deletion/Erasure procedure.
Data localization
Some vendors offer data residency options (data stored in specific regions or jurisdictions). Availability depends on edition and region.
Scaling Up / Down
Scaling model
Most cloud telephony platforms are subscription-based with per-seat/user or per-channel pricing, plus usage-based components.
Scaling up/down is typically managed via:
Administrative adjustments in the portal (add/remove users, adjust plan tiers)
API-driven provisioning for automated scaling
Indicated minimums/maximums per tier, and potential seat-based or concurrent-channel caps
Lead times and processes
Changes in user counts, feature tiers, or number of numbers usually can be done quickly (same-day or next-business-day provisioning for many cloud providers).
Larger changes (significant capacity, data migrations, or complex integrations) may require a change order or a brief planning window.
Pricing implications
Scaling up often increases monthly fees (per-user/seat, concurrent calls, or included minutes).
Scaling down may reduce ongoing costs but watch for minimum commitments or contracted term implications.
Some contracts include volume discounts or tiered pricing; verify how thresholds are calculated and when discounts apply.
The terms & conditions for contract renewal and cancellation
Renewal structure
Question to ask: Auto-renewal terms, renewal notice period, and price renewal policy (fixed price, CPI adjustments, or negotiated pricing).
Data point to capture: Whether pricing escalators apply and how they are calculated.
Cancellation rights
Question to ask: Termination rights, notice period, and whether mid-term termination is allowed without penalty (and under what conditions).
Termination for cause or convenience
Question to ask: Rights to terminate for cause (breach, non-performance) and any cure
periods; rights to terminate for convenience (if any) and associated penalties.
Data return and deletion on termination
Question to ask: Timelines and formats for data export post-termination; data deletion
timelines from active systems and backups; any obligation to retain data for regulatory reasons.
Transition assistance
Question to ask: Do they offer offboarding assistance, migration support to another provider, or professional services to facilitate transition
Fees and refunds
Question to ask: Any early termination fees, non-refundable onboarding costs, or service credits for downtime exceeding SLA.
Compliance
Security and privacy certifications
Question to ask: Which standards are certified (e.g., ISO 27001, ISO 27701, SOC 2 Type II, SOC 1 Type II, PCI-DSS where applicable, HIPAA/HITECH for healthcare use).
Data handling: How data is classified, protected, and controlled; data retention and deletion practices.
Regulatory compliance
Question to ask: Do they support GDPR, CCPA/CPRA, LGPD, HIPAA, PCI-DSS, UK GDPR, and other region-specific requirements? Do they offer data processing agreements and standard contractual clauses (SCCs) if needed for international data transfers
Audit rights
Question to ask: Can customers request independent audits or access to audit reports? Are audits performed by第三方 auditors or integrated with customer-facing attestations
Security controls
Question to ask: Details on access control (RBAC, MFA, SSO/SAML/OIDC), encryption in transit and at rest, key management, and incident response
Business continuity and disaster recovery
Question to ask: RPO/RTO targets, DR testing frequency, and whether DR is in the same region or a separate region; failover testing results.
Data breach notification
Question to ask: Timeframe for breach notification, process, and coverage (third-party notifications, regulatory reporting).