Skip to main content

Help us improve the Digital Marketplace - send your feedback

VESPER SOFTWARE LTD

Snapshot AI

Snapshot AI is a cloud-hosted software service that analyses engineering activity data from existing development tools to provide leadership with clear visibility into team delivery, collaboration, and operational risks, without requiring changes to existing workflows.

Features

  • Integration with source control and issue tracking systems
  • Automated analysis of engineering activity data
  • Generative AI summaries of team and individual work
  • Role-based dashboards for engineering leaders
  • Identification of delivery risks and workflow bottlenecks
  • Historical trend analysis across teams and projects
  • Secure, cloud-hosted access via web interface
  • Configurable organisational and team-level views
  • Read-only data ingestion with no workflow disruption
  • Cross-tool correlation of code, tickets, and delivery signals

Benefits

  • Improve visibility into engineering delivery across teams
  • Reduce reliance on manual status reporting
  • Identify delivery risks earlier in the development lifecycle
  • Support better prioritisation using real work data
  • Enable informed leadership discussions with shared context
  • Save time compiling engineering performance insights
  • Highlight collaboration and workflow inefficiencies
  • Monitor progress without interrupting engineering workflows
  • Provide consistent insight across tools and teams
  • Support data-informed decisions without adding new processes

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at kirim@vesper.limited. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 7 0 0 4 2 3 7 2 2 0 4 8 5 0

Contact

VESPER SOFTWARE LTD Ahmet Kirimgeray Kirimli
Telephone: +44 7534 567864
Email: kirim@vesper.limited

About your service

Service categories

Applications

Engineering

Other engineering

  • Engineering Support Applications
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Snapshot AI integrates with common software development and delivery tools, including source control and issue tracking systems such as GitHub, GitLab, Bitbucket, Jira, Linear, and similar platforms.
Cloud deployment model
Public cloud
Service constraints
None
System requirements
  • Modern web browser with JavaScript enabled
  • Internet connectivity for secure web access
  • User account with supported source control or issue tracking tools
  • Read-only API access to integrated third-party systems
  • Ability to allow outbound HTTPS connections
  • Supported authentication method for user access
  • Standard corporate firewall allowing HTTPS traffic
  • No local software installation required

User support

Email or online ticketing support
Yes, at extra cost
Support response times
We aim to respond to support queries within one business day during business hours (Monday to Friday). Requests received outside business hours, including weekends, are handled on the next business day. Service-impacting issues are prioritised.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Standard support (included):

Email and phone support during business hours (Monday to Friday)

Initial response within one business day

Support for onboarding, basic configuration, usage questions, and general troubleshooting

Enhanced support (additional cost):

Optional access to a dedicated account manager

Optional access to technical specialists or cloud support engineers

Support for complex technical issues, integrations, advanced configuration, and ongoing technical guidance

Enhanced support arrangements are agreed contractually based on customer requirements

Cost:

Standard support is included in the subscription price

Dedicated account management and technical or cloud support are charged separately, with pricing agreed in advance

Account management / cloud support:

A dedicated account manager or cloud support engineer is not included by default

These roles are available as part of the enhanced support option
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Snapshot AI supports users through a structured onboarding process.

Users are onboarded through remote onboarding sessions led by the Snapshot AI team, covering initial setup, integrations, and key workflows. User documentation and written guidance are provided to support day-to-day use of the service.

Onsite training can be provided where required, subject to agreement and additional cost. This may include in-person sessions for administrators or user groups.

Ongoing support is available through email and phone support during business hours. Where required, additional training or technical support can be provided as part of an enhanced support option.

Snapshot AI does not require any on-premise installation.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of the contract, users can extract their data from Snapshot AI.

Data can be exported in commonly used, machine-readable formats (for example CSV or JSON) covering customer-configured data, reports, and outputs generated by the service. Exports are initiated through the service interface or provided by Snapshot AI upon request.

Where required, Snapshot AI will support data extraction during the contract exit period to ensure customers can retrieve their data in a usable format. Following successful data export and completion of the exit process, customer data is securely deleted in line with contractual and data protection requirements.
End-of-contract process
At the end of the contract, Snapshot AI will support an orderly service exit.

Included in the contract price:

Continued access to the service until the contract end date

Support for exporting customer data in commonly used formats

Reasonable assistance during the contract exit period to enable data extraction

Secure deletion of customer data following confirmation that export has been completed, in line with contractual and data protection requirements

Additional costs (where required):

Extended access beyond the contract end date

Additional or bespoke data exports outside the standard scope

Enhanced technical support or engineering effort related to migration to another service

Onsite support or consultancy related to exit activities

Any additional exit support requirements and associated costs are agreed in advance with the customer.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Snapshot AI is accessed through a secure, browser-based web interface. Users log in to view dashboards, reports, and AI-generated insights, manage integrations, and configure organisational settings. The service also provides APIs for read-only data ingestion from supported third-party systems.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Snapshot AI has not yet undergone formal user testing with individuals who rely on assistive technologies.

Accessibility considerations are incorporated into the design and development process, including use of semantic HTML, keyboard navigation support, sufficient colour contrast, and compatibility with common screen readers and browser accessibility features.

Accessibility issues identified through user feedback or internal review are prioritised for remediation, and the service is reviewed periodically to improve accessibility in line with WCAG 2.2 AA principles.
API
Yes
What users can and can't do using the API
Snapshot AI provides APIs to support secure integration and authorised programmatic access to the service.

What users can do:
Users can use the API to connect Snapshot AI to supported third-party systems, authenticate integrations, and enable read-only ingestion of engineering activity data. The API can also be used to retrieve service outputs and metadata where appropriate, subject to role-based access controls.

How users set up the service:
Initial service setup, user management, and organisational configuration are completed through the web interface. API credentials and tokens can then be generated to enable integrations with supported systems.

How users make changes:
Changes to integrations, access permissions, and configuration are primarily managed through the web interface. The API supports limited configuration related to authorised integrations and data access.

Limitations:
The API does not provide unrestricted write access, does not modify customer source systems, and cannot be used to change core service settings or business logic. Certain administrative actions are intentionally restricted to the web interface for security and governance reasons.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Snapshot AI supports controlled customisation of access and dashboards.

What can be customised:
Users can define and customise roles and permissions to control who can see specific data, dashboards, and insights. Dashboard layouts, views, and certain metrics can be customised to meet organisational needs.

How users can customise:
Role definitions and permission settings are configured through the service interface by authorised users. Dashboard customisation is carried out by the Snapshot AI team following a user request, based on agreed requirements, to ensure consistency, data integrity, and appropriate governance.

Who can customise:
Authorised administrative users can manage roles and access permissions within the service. Dashboard customisation is requested by authorised users and implemented by Snapshot AI as part of the service.

Scaling

Independence of resources
Snapshot AI is delivered as a multi-tenant cloud service designed to minimise the impact of one customer’s usage on others.

The service uses logical tenant isolation, role-based access controls, and workload management to ensure customer data and processing are separated. Capacity is monitored and scaled as required to maintain consistent performance. Resource limits and prioritisation are applied to prevent individual workloads from adversely affecting overall service availability.

Snapshot AI continuously monitors service performance and addresses capacity or performance issues as they arise to ensure a stable experience for all users.

Analytics

Service usage metrics
Yes
Metrics types
Snapshot AI provides service usage metrics to help customers understand how the service is being used.

Metrics available include:

User activity and login information

Usage of dashboards, reports, and views

Data ingestion status from integrated systems

Coverage of teams, projects, and time periods analysed

High-level indicators of service activity and adoption over time

These metrics are available through the service interface and are intended to support transparency, operational oversight, and effective use of the service. Snapshot AI does not use service usage metrics to make automated decisions about users.
Reporting types
  • API access
  • Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data from Snapshot AI by requesting an export from the Snapshot AI team.

Data is provided in commonly used, machine-readable formats such as CSV or JSON. Exports may include customer-configured data, reports, and outputs generated by the service. Where required, Snapshot AI supports data export during the contract term or as part of the contract exit process.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • Other
Other data import formats
JSON

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Guaranteed availability

Snapshot AI is designed to be highly available and resilient.

Availability commitment:
Snapshot AI targets 99.5% availability measured on a monthly basis, excluding planned maintenance.

Planned maintenance:
Planned maintenance is scheduled outside core business hours where possible and customers are notified in advance.

Service levels and monitoring:
Service availability is continuously monitored. Any service-impacting incidents are prioritised and addressed by the Snapshot AI operations team.

Service credits / refunds:
If the monthly availability falls below the stated target, customers may request service credits applied to future subscription fees, calculated proportionally based on the duration of the outage. Service credits are the sole and exclusive remedy for failure to meet availability targets.
Approach to resilience
Snapshot AI is designed to be resilient and to minimise the impact of component or infrastructure failures.

The service is hosted on third-party cloud infrastructure designed for high availability and resilience. Core components are deployed across multiple availability zones within a region to reduce single points of failure. Automated monitoring and alerting are used to detect and respond to service issues.

Data is protected through regular backups and recovery procedures, enabling restoration in the event of failure. Capacity is monitored and scaled as required to maintain service performance.

The underlying datacentres are operated by an established cloud provider with built-in physical security, power redundancy, network redundancy, and environmental controls. Detailed information about the infrastructure and resilience measures can be provided to buyers on request where required.
Outage reporting
Snapshot AI reports service outages and incidents through direct communication with customers.

Email alerts:
Customers are notified of service-impacting incidents and updates via email.

Account communication:
Where applicable, updates are coordinated through the customer’s primary contact or account manager.

Snapshot AI does not currently provide a public status dashboard or an API specifically for outage notifications. Incident information and resolution updates are communicated directly to affected customers.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to Snapshot AI management interfaces and support channels is restricted using role-based access controls and least-privilege principles. Administrative functions are limited to authorised users and staff with appropriate permissions. User access requires authentication, with additional controls such as multi-factor authentication where enabled. Support channels are restricted to authenticated customer contacts, and requests are verified before action is taken. Access rights are reviewed regularly and adjusted as roles change. All access to management functions is logged and monitored to support audit and incident investigation.
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
SOC 2 Type I and II
Information security policies and processes
Snapshot AI follows a formal information security management framework aligned with ISO/IEC 27001 and SOC 2 Type II requirements.

The organisation maintains documented information security policies covering areas including access control, data protection, secure development, incident management, change management, supplier risk, and business continuity. These policies are reviewed regularly and updated as required.

Overall responsibility for information security sits with a named senior leader at board level, who provides governance and oversight across all services. Day-to-day implementation is supported by designated security and engineering leads.

Compliance with policies is ensured through a combination of:

Role-based access controls and least-privilege principles

Secure software development practices and code review

Regular risk assessments and internal audits

Ongoing monitoring and logging of security-relevant events

Annual independent audits as part of ISO 27001 and SOC 2 Type II certification

Security incidents or policy breaches are reported through defined escalation and incident response processes, with corrective actions tracked to completion. Staff receive security awareness training and are expected to adhere to all relevant policies as part of their roles.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Snapshot AI follows configuration and change management processes aligned with ISO/IEC 27001 and SOC 2 Type II. Service components, including code and infrastructure configurations, are version-controlled and tracked throughout their lifecycle using configuration management and source control systems. All changes are assessed prior to deployment, including consideration of potential security and data protection impacts. Changes follow an approval process based on risk, with testing performed before release. Security-relevant changes are reviewed by engineering and security leads, and changes are logged to support audit, traceability, and rollback where required.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Snapshot AI operates a vulnerability management process aligned with ISO/IEC 27001 and SOC 2 Type II. Potential threats are identified through regular vulnerability scanning, penetration testing, code review, and monitoring of systems and dependencies. Vulnerabilities are assessed based on risk, impact, and likelihood, with prioritisation for issues affecting confidentiality, integrity, or availability. Security patches are deployed based on severity, with critical issues addressed as a priority and lower-risk items remediated through scheduled releases. Threat intelligence is sourced from cloud provider advisories, vulnerability databases, penetration testing reports, and industry best-practice guidance.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Snapshot AI operates protective monitoring aligned with ISO/IEC 27001 and SOC 2 Type II. Potential compromises are identified through centralised logging, automated alerts, and continuous monitoring of system activity, access patterns, and security events. Logs are reviewed and correlated to detect unusual or suspicious behaviour. When a potential compromise is identified, incident response procedures are initiated, including investigation, containment, and remediation as required. Security incidents are triaged promptly, with initial assessment and response initiated as soon as practicable, and critical incidents prioritised for immediate action and escalation.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Snapshot AI operates a formal incident management process aligned with ISO/IEC 27001 and SOC 2 Type II. Pre-defined procedures exist for common incident types, including security, availability, and data-related events. Users can report incidents via email or phone support channels, or through their designated contact where applicable. Incidents are triaged, prioritised, and managed according to severity, with escalation where required. Incident updates and resolution information are communicated directly to affected users, and post-incident reports are provided where appropriate, outlining impact, root cause, and corrective actions.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
8%
Between £500,001 and £1,000,000
12%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
18%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
CFECert Certification Limited
ISO/IEC 27001 accreditation date
Friday 26 September 2025
What the ISO/IEC 27001 doesn’t cover
The ISO/IEC 27001 certification applies only to the scope defined on the certificate.

Activities, systems or services that fall outside this defined scope are not covered. This may include customer-managed infrastructure, customer internal systems, third-party services not under our operational control, and end-user devices or environments.

Any services or environments not explicitly included in the ISMS scope are therefore excluded from certification coverage.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • SOC 2 Type I
  • SOC 2 Type II

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at kirim@vesper.limited. Tell them what format you need. It will help if you say what assistive technology you use.