Compliance by design
ROGER365.io is based on the Microsoft Azure serverless architecture principles making it scalable, secure and future proof/flexible by design. ROGER365.io only uses Microsoft industry standard technology and uses Microsoft API’s for seamless integrations.
Microsoft Azure data centers are setting the norm as the industry standard and by having the solution based on the latest technology ROGER365.io benefits by the 90 Microsoft compliance certifications.
User Access
There is one administrator portal to configuration connections and systems. Access to this administrator portal is done via the ROGER365.io Enterprise application within the Microsoft Azure Active Directory. There is no storage of username/ password at all. All token-based access via Azure AD. No client software, seamless integration with Microsoft Teams. Different roles can be assigned to users, such as those accessible through the supervisor or reporting tab in the Contact Center application, utilizing Role-Based Access Control (RBAC) within the administrator portal, where administrators have the flexibility to create and assign roles to other users. ROGER365.io comes equipped with an Audit Log, providing users the ability to easily track any changes made within the system. This feature ensures transparency and accountability, especially during disaster recoveries or post-incident reviews.
Data encryption and separation
Each customer has their own database. The data in the database is “encrypted at rest”. ROGER365.io does not store the communication data. All communications is transferred from touchpoint to Microsoft Teams and back.
Database only contains minimum metadata required to keep the system working. For example, webchat can be anonymous, but mobile phone is used being able to identify and reply WhatsApp messages. This data will be anonymized 24 hours after the communication window closes.
It is optional to store transcript or store conversation date but must switch on by customer. When subscription ends the customers’, database is completely deleted from the ROGER365.io, no data stays within the platform.
The reason to enable this feature can be that you want to push the conversation into another system (log systems) like Microsoft Dynamics or Salesforce when the conversation is closed. The transcript is also used to do sentiment analysis.
ISO 27001 Certified
ROGER365.io B.V. is proud to hold ISO/IEC 27001:2022/AMD1:2024 certification, the latest version of the globally recognized standard for information security management. This independent certification (registration number DGT2717211090) confirms that every aspect of how we develop, deliver, operate, and support the ROGER365 platform meets the highest standards for protecting your data. From risk management and access control to incident response and business continuity, security is embedded into everything we do. Customers and partners can download our certificate and request the Statement of Applicability (SoA) for compliance and due diligence purposes.
Microssoft 365 App Compliance Certified
ROGER365.io is certified under the Microsoft 365 App Compliance Program, Microsoft’s framework for validating the security, privacy, and compliance posture of applications built on the Microsoft 365 platform. This certification gives enterprise customers and IT administrators independent assurance that ROGER365.io meets Microsoft’s standards across two key domains: Operational Security and Data Handling & Privacy. Being part of this program reflects our ongoing commitment to transparency and trust, so your security team can deploy ROGER365.io with confidence through the Microsoft Teams admin center or Microsoft Teams app store.
Connection to Microsoft Teams
ROGER365.io only uses Microsoft industry standard technology. Integration within Microsoft Teams is done via the Microsoft bot framework and the Graph API. ROGER365.io admin portal access is done via a verified Enterprise application within the Microsoft Azure Active Directory.
Connection with TouchPoints and Teams Calling Environment
TouchPoints are connections to external communication networks like Facebook, WhatsApp or SMS providers. All the connections are based on the lasted API’s, authentication and authorization technologies provided by the service providers that offer these communication channels. All communication is encrypted and cannot be seen at any time by any third-party. For Contact Center functionality ROGER365.io uses the official Contact Center Architecture utilizing the Communications API’s.
Questions?
Please reach out to us if you have concerns or questions. We can share with you our company procedures and other required documentation when necessary.