Synthesia
Synthesia is a secure AI video platform for public sector training, onboarding and communications. Teams create accessible, multilingual videos from text using AI avatars - no cameras or studios required. Ideal for learning and AI skills, internal communications and digital transformation at scale.
Features
- AI Avatars (Stock, Personal & Custom)
- AI Video Assistant
- Text-to-Video Generator
- AI Voices & Voice Cloning
- 1-Click Translation & AI Dubbing
- Templates & Brand Kits
- Script-Driven Editing Model
- Interactivity
- Collaboration & Governance
- Analytics & Publishing
Benefits
- Massive Time Savings
- Lower Production Costs
- Learning AI Skills
- AI Enablement
- Easy Updates & Version Control
- Anyone Can Create Professional Videos
- Brand Consistency at Scale
- Higher Engagement & Learning Impact
- Enterprise-Ready & Secure
- Future-Proof Platform
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 3 9 8 3 7 7 9 9 2 7 3 6 4 9
Contact
Synthesia Limited
Stuart Reid
Telephone: 00000000000
Email: questionnaires@synthesia.io
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Generative AI Software Services
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
The service is provided as a fully managed, cloud-based SaaS offering and does not require customers to install or maintain any hardware or software. Buyers access the service via a modern web browser and standard internet connectivity.
Planned maintenance is performed as part of normal service operations and is designed to be non-disruptive wherever possible. Where maintenance may have a user-visible impact, customers are notified in advance through appropriate communications.
Support is not limited to specific hardware configurations, as the service is device-agnostic.
There are no other material constraints that buyers need to plan for beyond standard SaaS considerations. - System requirements
-
- A working internet connection
- An up to date web browser (Chrome or Edge)
User support
- Email or online ticketing support
- Yes
- Support response times
-
Priority 1 (Urgent/System Outage) - We aim to respond within 1 hour - We aim to provide a resolution plan within 4 hours
Priority 2 (High/Critical Component Failure) - We aim to respond within 2 hour - We aim to provide a resolution plan within 8 hours
Priority 3 (Normal/Problematic Behaviour) - We aim to respond within 4 hours - We aim to provide a resolution plan within 24 hours
Priority 4 (Low/Non-Critical Failure/Query) - We aim to respond within 8 hours - We aim to provide a resolution plan within 48 hours - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
-
At Synthesia, our web chat is provided via an embedded Intercom widget in our Help Center and product. Users can start a conversation from any modern desktop or mobile browser, use standard OS/browser accessibility features (e.g., zoom, high-contrast modes, reduced motion), exchange plain-text messages, request to move the conversation to email, and ask to be routed from the initial automated triage/bot to a human agent. We can provide conversation transcripts by email on request and will make reasonable accommodations.
We do not currently assert formal conformance to WCAG 2.x or EN 301 549 for the chat experience. Some aspects—such as detailed screen-reader preferences, live captioning, or fine-grained control over fonts/spacing/focus styling—are defined by the third-party widget and not user-configurable beyond browser/OS settings. If the chat is not accessible for any reason, customers can always reach us at support@synthesia.io, and we will coordinate an alternative accessible channel. - Web chat accessibility testing
- N/A
- Onsite support
- No
- Support levels
-
At Synthesia, standard support is included with all paid plans at no additional cost. Customers can contact us via in-product web chat (Intercom widget) and email at support@synthesia.io; our Help Center and product documentation are also available for self-service.
For larger deployments, we offer an Enterprise tier that includes priority routing and a named Customer Success/Account Manager for ongoing reviews and coordination. Engineering specialists are engaged through our escalation process when required, but we do not provide a standing, named cloud support engineer by default. Where bespoke enablement is needed, we can scope ad-hoc professional services by mutual agreement (SOW). - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Synthesia provides a comprehensive onboarding experience designed for rapid, scalable adoption. Where applicable, each customer is assigned a dedicated Customer Success Manager (CSM) who facilitates a kick-off call to define success criteria and establish a tailored onboarding plan. The CSM also delivers ongoing support, including best practice sharing, regular check-ins, and feedback on early video outputs.
To accelerate platform mastery, Synthesia offers bespoke training programmes; ranging from ad-hoc sessions to structured enablement tailored to specific roles and workflows. For large-scale implementations, a consultative design approach is available, covering discovery, solution design, technical alignment, and measurement.
Strategic “Power of Possible” workshops are offered to help stakeholders explore high-value use cases and drive internal alignment.
Users can access a rich set of self-serve learning resources, including video tutorials, webinars, articles, and guided courses through the Synthesia Knowledge Base and Academy. This ensures both technical and non-technical users can quickly become proficient.
This multi-layered onboarding model ensures a smooth, impactful rollout across global teams. . - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- We have a documented process for returning and purging data upon service termination. All video data generated on the platform can be downloaded or exported via the API in MP4 format prior to termination of the contract. If there is a request to delete specific video data or delete all video data on termination of an account, we will delete all copies permanently and provide confirmation of deletion. After termination of an account, if there is no request for deletion, the information will automatically be deleted within 90 days. During this 90-day period following the end of the relationship, we can assist customers in retrieving any generated videos in MP4 format.
- End-of-contract process
-
At the end of the contract term, customer access to the service is disabled unless the contract is renewed or extended.
Customers may export or retrieve their data using the service’s standard export functionality during the contract term and for a limited period following contract termination, subject to contractual terms.
After the post-termination data retrieval period, customer data is securely deleted in accordance with the supplier’s data retention and deletion policies and applicable data protection laws. No customer data is retained beyond this point unless required by law.
There is no automatic contract renewal unless explicitly agreed by both parties. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- We are currently in the process of ensuring that our platform and documentation are accessible.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- A guide to our API, detailing set up guides and details of what the Synthesia API allows you to do can be found here: https://docs.synthesia.io/reference/introduction
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- Our solution automatically scales to meet increased demand through AWS elastic compute resources. Video generation can scale on demand, and load balancers distribute traffic to increase reliability and availability. The backend API uses AWS elastic compute and can scale to match demand. We have a redundant architecture with resources distributed across geographically dispersed data centers to support continuous availability.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Synthesia provides administrators with several tools to monitor platform usage and user engagement, supporting performance tracking and adoption management:
In-Studio Video Analytics: Available on published videos, including:
- Unique viewers count
- Total views
- Total watch time
- Average watch time
- View rate and completion rate
Please see:
https://help.synthesia.io/en/articles/8271938-how-can-i-view-and-understand-video-analytics-in-synthesia
https://www.synthesia.io/post/video-metrics - Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Our solution supports comprehensive data import and export functionalities across multiple file formats. For export, data can be retrieved via our API or as MP4 files. For import, we support various file types including image/jpeg, image/png, image/svg+xml, video/mp4, and video/webm. Additionally, all structured and unstructured data is available upon request in industry-standard formats such as .doc, .xls, .pdf, logs, and flat files.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- .mp4
- .doc
- .xls
- Logs
- Flat files
- Data import formats
- Other
- Other data import formats
-
- .jpeg
- .png
- .mp4
- Webm
- Svg+xml
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Synthesia commits to using commercially reasonable efforts to make the service available 24/7 x 365. We provide ongoing visibility and reporting of our operational performance to customers on our status page, available at http://status.synthesia.io/, which allows for continuous monitoring of our uptime performance.
- Approach to resilience
-
The service is designed as a cloud-native, highly available SaaS platform with resilience built into its architecture, operations, and supporting processes.
The service is hosted on major cloud infrastructure providers that deliver resilient datacentre environments with built-in redundancy across power, networking, and physical security controls. Services are deployed across multiple availability zones within a region to reduce the risk of single points of failure.
Application components are designed to be fault tolerant, with automated health monitoring, scaling, and recovery mechanisms to maintain availability in the event of component or infrastructure failures. Data is stored on resilient storage systems that provide redundancy and durability, and regular backups are performed to support recovery from data loss or corruption.
Operational resilience is supported by continuous monitoring, alerting, and incident response processes. Planned maintenance is managed to minimise disruption and, where user impact is expected, customers are notified in advance.
Further details on datacentre architecture, redundancy, and resilience controls are available to buyers on request, subject to appropriate confidentiality arrangements. - Outage reporting
- Any outages will be reported on our public dashboard (https://status.synthesia.io/) and communicate via email alerts where users have subscribed to updates.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
At Synthesia, we restrict access as follows:
Management interfaces: Okta SSO (with MFA) and RBAC; access provisioned by IT/People Ops on least-privilege, reviewed quarterly, and revoked within 1 day on termination. Database/system access is brokered via StrongDM. Admin activity is audited via AWS CloudTrail → Datadog/Hunters with 24×7 response by CrowdStrike Falcon Complete.
Support channels: Intercom and Jira Service Management use scoped roles; access to customer data is need-to-know and logged. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- ISO42001, SOC2 Type 2, IS027701
- Information security policies and processes
-
At Synthesia, we run a formal, annually reviewed security program with executive oversight, independently assessed under SOC 2 Type II & ISO27001. We enforce least-privilege RBAC with quarterly access reviews, Okta SSO and strong authentication for workforce access, background checks, and mandatory security training. Data is protected with AES-256 at rest and TLS 1.2+ in transit. Security telemetry (including AWS CloudTrail) is centralized in Datadog with 4-year retention, and endpoints are protected by CrowdStrike Falcon EDR/DLP with 24×7 managed detection and response. We maintain a tested incident response plan.
Our secure SDLC includes segregated environments, change control, peer review, and CI/CD security gates: Semgrep (code/dependency/container) and weekly OWASP ZAP DAST, plus continuous vulnerability management, independent penetration testing, and a private bug bounty. Vendor risk is managed through DPAs, due diligence, and periodic reviews. Customer data follows a controlled lifecycle—customer-directed retention, export on request, and deletion within 90 days after request or termination. We apply Responsible AI governance and do not use Customer Data to train our models. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We have a formal change control process for managing changes to our systems. Our change management process includes steps for impact analysis, authorization verification, testing, and approval. All changes go through internal code review for release and must pass through multiple environments before reaching production. Emergency changes are managed through formal procedures, and changes can be rolled back following a well-established process if needed.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We have implemented a vulnerability management program to detect and remediate system vulnerabilities in our infrastructure. Our remediation process follows a risk-based timeline: critical vulnerabilities are addressed within 14 days, and high-risk vulnerabilities are remediated within 30 days. Medium vulnerabilities are remediated within 60 days, and low within 90 days.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
The service implements continuous protective monitoring to detect, respond to, and mitigate potential security compromises across the application and supporting infrastructure.
Potential compromises are identified through centralised monitoring of application logs, system events, cloud control-plane activity, and security telemetry. Automated alerts and detection rules are used to identify anomalous behaviour, unauthorised access attempts, or indicators of compromise.
When a potential compromise is detected, alerts are triaged by the security team and investigated in line with documented incident response procedures. Response actions may include isolating affected components, restricting access, rotating credentials, and applying remediation measures to contain and resolve the issue. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We have a documented Incident Response Plan to manage incidents. The plan is reviewed at least annually. All incidents are documented in our Security Incident Register. All actions taken during an incident are documented and the whole process reviewed once the emergency is over. For incidents where Synthesia is the Data Controller, regulatory authorities and affected individuals will be notified without undue delay, but in no more than 72 hours. For incidents where Synthesia is the Data Processor, Synthesia will notify the Data Controller as stipulated in the applicable DPA.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Conditional Managed Trial period available - 2 week duration
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- A-Lign
- ISO/IEC 27001 accreditation date
- Monday 18 August 2025
- What the ISO/IEC 27001 doesn’t cover
- All controls in scope
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3e68484c-a9ce-4629-9c26-fb33575b5346
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 42001
- SOC 2 Type II
- ISO 27701
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
-