The floor went home. The controls have to follow.
WFH seats with the containment clients demand: voice-friendly, watermarked, attributed, and provable.
- Client-contractual controls_
- PCI DSS_
- DPDP Act_
- Per-seat attribution_
BPO security was built physical: badge gates, no phones on the floor, paper-free rooms. Distributed and work-from-home operations dissolved that model, but client contracts didn't relax. Payment-line PCI clauses, data-handling commitments and audit rights all still apply, now to a seat in the agent's home.
Add voice: contact-centre workloads punish latency, so the security layer must not sit in the audio path at all.
The five or six places this actually changes something.
- The WFH seatCRM, dialer and knowledge tools delivered through the portal, with watermark, clipboard and download policy on by default and an inactivity timeout for the walked-away seat.
- Voice pathDirect, split-plane VoIP access: security without jitter, because the audio never detours through a security appliance.Secure VoIP
- Per-seat attributionNamed agent, bound device, logged session. Shared-station ambiguity ends.
- Payment linesMFA, tight scoping and logging supporting PCI-relevant flows.
- Surge staffingClientless onboarding for ramp classes: hundreds of seats in hours, and offboarding just as fast at ramp-down.
- Client evidencePer-programme access reports and session replay for client audits.
The numbers this vertical gets asked for.
- Voice architectureSplit-plane direct path: the security layer is not in the audio path
- Seat containmentWatermark, clipboard and download policy, plus inactivity timeout
- AttributionNamed agent bound to approved hardware on every logged session
- Ramp and de-rampClientless onboarding, group-based removal at programme end
- Programme evidencePer-programme access reports and session replay
Floor-grade control,at a home desk.
The three things a client asks about before signing off a WFH programme.
Seats get signed off
The WFH seat carries the containment the client contract already required of the floor.
Ramp at BPO speed
Ramp classes onboard in hours and de-ramp just as fast, because there is nothing to install or collect.
Voice survives
Call quality is unaffected, because the audio path never routes through the security layer.
The seat went home and the voice quality came with it.
The softphone was published like any other application, over a session that runs device to application rather than through a concentrator, so the delay a customer can hear never entered the path. Shift, geography and device decide whether the login opens at all.
- Voice published_
- Device to application_
- Place and hour_

Client-auditable seats,
wherever the agent sits.
- Identity signals
- Device signals
- Network signals
- Application signals
You can verify identity, device, network, and app on every request. One decision engine evaluates all four before a single packet reaches anything — not four separate tools.
The voice path is split-plane and direct. Audio goes device to service without detouring through us, so containment on the data path costs nothing on the call.
One console, not five. ZTNA, ZTAA, IAM, MFA, and SSO — retire the point products.
We are enterprise-grade compliant. Architecture aligned to NIST SP 800-207 and CSA SDP; supports the controls required by PCI DSS, HIPAA, GDPR, SOX, and ISO 27001.
Per-seat attribution on shared and personal hardware. A named agent, a bound device and a logged session: the three things a client audit asks for when the floor is a thousand homes.
- NIST SP 800-207
- ISO 27001
- CSA SDP
"decision": "allow"BPO / Contact Centres, answered.
Tap a question. If yours is not here, a specialist for this sector can answer it.
Talk to a specialistSee it running against your own apps.
A 30-minute walkthrough, tailored to your stack and deployment: cloud, on-premise or hybrid.
Book a demo




