Skip to main content

Help us improve the Digital Marketplace - send your feedback

Vizzia

Non-Actively monitored CCTV control room system

Cloud-based Video Management System (VMS) for recorded surveillance with AI-triggered alerts, enabling efficient retrospective review and evidence retrieval without 24/7 operator presence.

Features

  • Cloud-native platform, no on-premise servers
  • Continuous cloud recording with configurable retention
  • AI-powered smart alerts: motion, intrusion, loitering
  • 4G/5G camera connectivity enabling rapid deployment
  • Filter recorded footage by time, event, AI-detected activity
  • Full audit trail with tamper-proof video stream logging
  • Evidence export: download clips in court-admissible formats with metadata
  • Operator activity logging for SIA compliance
  • Role-based access control
  • Multi-site federated architecture: manage cameras across multiple locations

Benefits

  • Eliminate 24/7 staffing costs while maintaining surveillance coverage
  • Reduce investigation time with AI-powered smart search
  • Deploy new camera sites in 48 hours
  • Redeploy cameras to adapt to emerging and moving hotspots
  • Lower cost of ownership: no server hardware or VMS licences
  • Access footage securely from any authorised location
  • Prosecution-ready evidence with complete chain of custody documentation

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at alain.lauriano@vizzia.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 9 9 4 5 9 5 4 1 7 6 3 0 5 2

Contact

Vizzia Alain Lauriano
Telephone: +447537163873
Email: alain.lauriano@vizzia.com

About your service

Service categories

Application Development and Deployment

AI platforms

AI software services

  • Anomaly Detection AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Cloud based quick-deploy Videosurveillance.
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
None
System requirements
Whitelisting 2 specific URLs.

User support

Email or online ticketing support
Yes
Support response times
Within 24 hours
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
Customer support for onboarding, access to new features, debugging, updates
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Online training, user documentation and on-site training.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
They may extract CSV data and images by downloading files.
End-of-contract process
Its a case by case subject.
But all contracts bundle : Hardware & software licence. All included.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our onboarding and offboarding documentation is provided in accessible digital formats (web pages and downloadable documents) and is written with clear structure (headings, short sections, consistent navigation). We aim to follow accessibility best practices, including meaningful link text, descriptive titles, and avoiding images as the only way to convey information. Where screenshots or visuals are used, we provide accompanying text explanations. Documentation is usable with keyboard navigation and common screen readers where supported by the publishing platform. If a user requires an alternative format or additional assistance, our Customer Success team can provide adapted versions and support (e.g., text-only or structured documents) on request.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • IOS
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Full-featured.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Vizzia.app
Accessibility standards
None or don’t know
Description of accessibility
Full access
Accessibility testing
None
API
No
Customisation available
Yes
Description of customisation
Agents may precisely customize the PDF forms that are filled by our tool, by editing docx templates and uploading them.

Scaling

Independence of resources
AWS (or GCP) hyperscaller serverless native capabilities

Analytics

Service usage metrics
Yes
Metrics types
Service metrics include number of Fixed Penalty Notice issued by user, total amount collected or type, date and location of recorded incidents.
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
They may extract csv files of all actions, for tracability purposes.
They may also donload csv files of all stats.
Data export formats
CSV
Data import formats
  • CSV
  • Other
Other data import formats
Docx

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We target high availability for the Service and provide a monthly uptime commitment of 99.9% (“Monthly Uptime Percentage”), excluding scheduled maintenance and force majeure. Uptime is measured at the service boundary (API and/or web application) and calculated as: (total minutes in month − downtime minutes) / total minutes in month. “Downtime” means the Service is unavailable to all users due to a service-side issue.

Planned maintenance is communicated in advance where possible and performed outside peak hours; emergency maintenance may occur to address security or stability issues.
Approach to resilience
Our service is designed for resilience using AWS best practices and managed services. We deploy across multiple Availability Zones within a region, with load balancing and automatic failover to reduce single points of failure. Compute is horizontally scalable with health checks and auto-healing. Data stores use managed replication and automated backups; backups are encrypted and tested via regular restore drills. We separate concerns (stateless services, decoupled components using queues/events where appropriate) to contain failures and enable graceful degradation.

We use infrastructure-as-code, controlled rollouts (blue/green or canary where applicable), and continuous monitoring/alerting to detect issues early. DDoS protection and network controls are provided through AWS-native services (e.g., edge protection, WAF, security groups). We routinely patch and update dependencies, and we maintain runbooks and an incident response process with post-incident reviews to drive continuous improvement.

Specific datacentre/region architecture details can be provided on request.
Outage reporting
We use email alerts. The general availability is shown ad vizzia.app

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using least privilege and role-based access control (RBAC). All administrative access requires SSO/MFA and is granted only to named users on a need-to-know basis, with approvals and periodic access reviews. Privileged actions are logged and monitored, with separate admin accounts and strong password policies. Support tooling is restricted to authorised support staff, with customer data access time-bound, auditable, and approved where required. We do not accept sensitive credentials via support channels; secure workflows are used for any required data exchange, and accounts are promptly revoked on role change or departure.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We are in the process of being ISO 27001 Certified. End of 2026.
Information security policies and processes
We operate documented security policies aligned with ISO 27001-style controls and AWS best practices (IAM/MFA, least privilege, secure SDLC, vulnerability/patch management, encryption, logging/monitoring, incident response, backups/BCP, supplier management). A designated security owner reports risk and incidents to leadership. Compliance is enforced via onboarding/training, change management, code reviews, access reviews, continuous monitoring, and tracked remediation of findings.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We manage configuration and change via Infrastructure-as-Code and controlled CI/CD pipelines. All service components are versioned (code, IaC, container images) and tracked through their lifecycle in Git, with peer review and approval. Changes follow a ticketed process, include risk/security impact assessment, and require testing (automated checks, security scanning) before deployment. Deployments are staged (dev/staging/production) with canary/rollback capability and change logs. Production access is restricted and audited; configuration is monitored for drift and alerts are raised on unauthorised changes. Critical changes follow enhanced approval and maintenance windows.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We run continuous vulnerability management across code, dependencies and infrastructure. Threats are assessed using automated scanning (SAST/SCA, container image scanning e.g. ECR/Inspector, and infrastructure checks), AWS security findings (Security Hub/GuardDuty), and risk triage based on CVSS, exposure and asset criticality. We monitor upstream advisories (vendor CVEs, AWS Security Bulletins, NCSC/NVD) and subscribe to alerts for key components. Patches are deployed via CI/CD with tested rollouts and rollback. Target remediation times: Critical ≤72 hours, High ≤14 days, Medium ≤30 days (or sooner if exploitable/exposed). Findings are tracked to closure.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use layered protective monitoring across AWS and Datadog. We centralise logs and metrics (CloudTrail, VPC Flow Logs, GuardDuty/Security Hub findings, load balancer and application logs) into Datadog/CloudWatch and alert on suspicious activity (failed auth spikes, privilege changes, unusual traffic/data access, anomaly detection). Alerts are triaged by on-call engineering/security. On suspected compromise we follow an incident runbook: contain (revoke/rotate credentials, isolate resources), investigate (log review, timeline), eradicate, recover, and document actions. Critical alerts are acknowledged within 15 minutes with initial containment within 1 hour, followed by a post-incident review.
Incident management type
Supplier-defined controls
Incident management approach
We follow documented incident processes with playbooks for common events. Incidents are triaged by severity, assigned an owner, and tracked in Jira via our internal ticketing interface. Response is coordinated by on-call engineering/security with our fully staffed Customer Success and Ops teams for investigation, containment, recovery and communications. Users report incidents through Customer Success (email/ticketing). For major incidents we provide timely updates, and on request we share an incident report (timeline, impact, root cause, remediation). Corrective actions are tracked to closure in Jira.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at alain.lauriano@vizzia.com. Tell them what format you need. It will help if you say what assistive technology you use.