Snapshot AI
Snapshot AI is a cloud-hosted software service that analyses engineering activity data from existing development tools to provide leadership with clear visibility into team delivery, collaboration, and operational risks, without requiring changes to existing workflows.
Features
- Integration with source control and issue tracking systems
- Automated analysis of engineering activity data
- Generative AI summaries of team and individual work
- Role-based dashboards for engineering leaders
- Identification of delivery risks and workflow bottlenecks
- Historical trend analysis across teams and projects
- Secure, cloud-hosted access via web interface
- Configurable organisational and team-level views
- Read-only data ingestion with no workflow disruption
- Cross-tool correlation of code, tickets, and delivery signals
Benefits
- Improve visibility into engineering delivery across teams
- Reduce reliance on manual status reporting
- Identify delivery risks earlier in the development lifecycle
- Support better prioritisation using real work data
- Enable informed leadership discussions with shared context
- Save time compiling engineering performance insights
- Highlight collaboration and workflow inefficiencies
- Monitor progress without interrupting engineering workflows
- Provide consistent insight across tools and teams
- Support data-informed decisions without adding new processes
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 7 0 0 4 2 3 7 2 2 0 4 8 5 0
Contact
VESPER SOFTWARE LTD
Ahmet Kirimgeray Kirimli
Telephone: +44 7534 567864
Email: kirim@vesper.limited
About your service
- Service categories
-
Applications
Engineering
Other engineering
- Engineering Support Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Snapshot AI integrates with common software development and delivery tools, including source control and issue tracking systems such as GitHub, GitLab, Bitbucket, Jira, Linear, and similar platforms.
- Cloud deployment model
- Public cloud
- Service constraints
- None
- System requirements
-
- Modern web browser with JavaScript enabled
- Internet connectivity for secure web access
- User account with supported source control or issue tracking tools
- Read-only API access to integrated third-party systems
- Ability to allow outbound HTTPS connections
- Supported authentication method for user access
- Standard corporate firewall allowing HTTPS traffic
- No local software installation required
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- We aim to respond to support queries within one business day during business hours (Monday to Friday). Requests received outside business hours, including weekends, are handled on the next business day. Service-impacting issues are prioritised.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Standard support (included):
Email and phone support during business hours (Monday to Friday)
Initial response within one business day
Support for onboarding, basic configuration, usage questions, and general troubleshooting
Enhanced support (additional cost):
Optional access to a dedicated account manager
Optional access to technical specialists or cloud support engineers
Support for complex technical issues, integrations, advanced configuration, and ongoing technical guidance
Enhanced support arrangements are agreed contractually based on customer requirements
Cost:
Standard support is included in the subscription price
Dedicated account management and technical or cloud support are charged separately, with pricing agreed in advance
Account management / cloud support:
A dedicated account manager or cloud support engineer is not included by default
These roles are available as part of the enhanced support option - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Snapshot AI supports users through a structured onboarding process.
Users are onboarded through remote onboarding sessions led by the Snapshot AI team, covering initial setup, integrations, and key workflows. User documentation and written guidance are provided to support day-to-day use of the service.
Onsite training can be provided where required, subject to agreement and additional cost. This may include in-person sessions for administrators or user groups.
Ongoing support is available through email and phone support during business hours. Where required, additional training or technical support can be provided as part of an enhanced support option.
Snapshot AI does not require any on-premise installation. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At the end of the contract, users can extract their data from Snapshot AI.
Data can be exported in commonly used, machine-readable formats (for example CSV or JSON) covering customer-configured data, reports, and outputs generated by the service. Exports are initiated through the service interface or provided by Snapshot AI upon request.
Where required, Snapshot AI will support data extraction during the contract exit period to ensure customers can retrieve their data in a usable format. Following successful data export and completion of the exit process, customer data is securely deleted in line with contractual and data protection requirements. - End-of-contract process
-
At the end of the contract, Snapshot AI will support an orderly service exit.
Included in the contract price:
Continued access to the service until the contract end date
Support for exporting customer data in commonly used formats
Reasonable assistance during the contract exit period to enable data extraction
Secure deletion of customer data following confirmation that export has been completed, in line with contractual and data protection requirements
Additional costs (where required):
Extended access beyond the contract end date
Additional or bespoke data exports outside the standard scope
Enhanced technical support or engineering effort related to migration to another service
Onsite support or consultancy related to exit activities
Any additional exit support requirements and associated costs are agreed in advance with the customer. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Snapshot AI is accessed through a secure, browser-based web interface. Users log in to view dashboards, reports, and AI-generated insights, manage integrations, and configure organisational settings. The service also provides APIs for read-only data ingestion from supported third-party systems.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Snapshot AI has not yet undergone formal user testing with individuals who rely on assistive technologies.
Accessibility considerations are incorporated into the design and development process, including use of semantic HTML, keyboard navigation support, sufficient colour contrast, and compatibility with common screen readers and browser accessibility features.
Accessibility issues identified through user feedback or internal review are prioritised for remediation, and the service is reviewed periodically to improve accessibility in line with WCAG 2.2 AA principles. - API
- Yes
- What users can and can't do using the API
-
Snapshot AI provides APIs to support secure integration and authorised programmatic access to the service.
What users can do:
Users can use the API to connect Snapshot AI to supported third-party systems, authenticate integrations, and enable read-only ingestion of engineering activity data. The API can also be used to retrieve service outputs and metadata where appropriate, subject to role-based access controls.
How users set up the service:
Initial service setup, user management, and organisational configuration are completed through the web interface. API credentials and tokens can then be generated to enable integrations with supported systems.
How users make changes:
Changes to integrations, access permissions, and configuration are primarily managed through the web interface. The API supports limited configuration related to authorised integrations and data access.
Limitations:
The API does not provide unrestricted write access, does not modify customer source systems, and cannot be used to change core service settings or business logic. Certain administrative actions are intentionally restricted to the web interface for security and governance reasons. - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Snapshot AI supports controlled customisation of access and dashboards.
What can be customised:
Users can define and customise roles and permissions to control who can see specific data, dashboards, and insights. Dashboard layouts, views, and certain metrics can be customised to meet organisational needs.
How users can customise:
Role definitions and permission settings are configured through the service interface by authorised users. Dashboard customisation is carried out by the Snapshot AI team following a user request, based on agreed requirements, to ensure consistency, data integrity, and appropriate governance.
Who can customise:
Authorised administrative users can manage roles and access permissions within the service. Dashboard customisation is requested by authorised users and implemented by Snapshot AI as part of the service.
Scaling
- Independence of resources
-
Snapshot AI is delivered as a multi-tenant cloud service designed to minimise the impact of one customer’s usage on others.
The service uses logical tenant isolation, role-based access controls, and workload management to ensure customer data and processing are separated. Capacity is monitored and scaled as required to maintain consistent performance. Resource limits and prioritisation are applied to prevent individual workloads from adversely affecting overall service availability.
Snapshot AI continuously monitors service performance and addresses capacity or performance issues as they arise to ensure a stable experience for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Snapshot AI provides service usage metrics to help customers understand how the service is being used.
Metrics available include:
User activity and login information
Usage of dashboards, reports, and views
Data ingestion status from integrated systems
Coverage of teams, projects, and time periods analysed
High-level indicators of service activity and adoption over time
These metrics are available through the service interface and are intended to support transparency, operational oversight, and effective use of the service. Snapshot AI does not use service usage metrics to make automated decisions about users. - Reporting types
-
- API access
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can export their data from Snapshot AI by requesting an export from the Snapshot AI team.
Data is provided in commonly used, machine-readable formats such as CSV or JSON. Exports may include customer-configured data, reports, and outputs generated by the service. Where required, Snapshot AI supports data export during the contract term or as part of the contract exit process. - Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Guaranteed availability
Snapshot AI is designed to be highly available and resilient.
Availability commitment:
Snapshot AI targets 99.5% availability measured on a monthly basis, excluding planned maintenance.
Planned maintenance:
Planned maintenance is scheduled outside core business hours where possible and customers are notified in advance.
Service levels and monitoring:
Service availability is continuously monitored. Any service-impacting incidents are prioritised and addressed by the Snapshot AI operations team.
Service credits / refunds:
If the monthly availability falls below the stated target, customers may request service credits applied to future subscription fees, calculated proportionally based on the duration of the outage. Service credits are the sole and exclusive remedy for failure to meet availability targets. - Approach to resilience
-
Snapshot AI is designed to be resilient and to minimise the impact of component or infrastructure failures.
The service is hosted on third-party cloud infrastructure designed for high availability and resilience. Core components are deployed across multiple availability zones within a region to reduce single points of failure. Automated monitoring and alerting are used to detect and respond to service issues.
Data is protected through regular backups and recovery procedures, enabling restoration in the event of failure. Capacity is monitored and scaled as required to maintain service performance.
The underlying datacentres are operated by an established cloud provider with built-in physical security, power redundancy, network redundancy, and environmental controls. Detailed information about the infrastructure and resilience measures can be provided to buyers on request where required. - Outage reporting
-
Snapshot AI reports service outages and incidents through direct communication with customers.
Email alerts:
Customers are notified of service-impacting incidents and updates via email.
Account communication:
Where applicable, updates are coordinated through the customer’s primary contact or account manager.
Snapshot AI does not currently provide a public status dashboard or an API specifically for outage notifications. Incident information and resolution updates are communicated directly to affected customers.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to Snapshot AI management interfaces and support channels is restricted using role-based access controls and least-privilege principles. Administrative functions are limited to authorised users and staff with appropriate permissions. User access requires authentication, with additional controls such as multi-factor authentication where enabled. Support channels are restricted to authenticated customer contacts, and requests are verified before action is taken. Access rights are reviewed regularly and adjusted as roles change. All access to management functions is logged and monitored to support audit and incident investigation.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- SOC 2 Type I and II
- Information security policies and processes
-
Snapshot AI follows a formal information security management framework aligned with ISO/IEC 27001 and SOC 2 Type II requirements.
The organisation maintains documented information security policies covering areas including access control, data protection, secure development, incident management, change management, supplier risk, and business continuity. These policies are reviewed regularly and updated as required.
Overall responsibility for information security sits with a named senior leader at board level, who provides governance and oversight across all services. Day-to-day implementation is supported by designated security and engineering leads.
Compliance with policies is ensured through a combination of:
Role-based access controls and least-privilege principles
Secure software development practices and code review
Regular risk assessments and internal audits
Ongoing monitoring and logging of security-relevant events
Annual independent audits as part of ISO 27001 and SOC 2 Type II certification
Security incidents or policy breaches are reported through defined escalation and incident response processes, with corrective actions tracked to completion. Staff receive security awareness training and are expected to adhere to all relevant policies as part of their roles. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Snapshot AI follows configuration and change management processes aligned with ISO/IEC 27001 and SOC 2 Type II. Service components, including code and infrastructure configurations, are version-controlled and tracked throughout their lifecycle using configuration management and source control systems. All changes are assessed prior to deployment, including consideration of potential security and data protection impacts. Changes follow an approval process based on risk, with testing performed before release. Security-relevant changes are reviewed by engineering and security leads, and changes are logged to support audit, traceability, and rollback where required.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Snapshot AI operates a vulnerability management process aligned with ISO/IEC 27001 and SOC 2 Type II. Potential threats are identified through regular vulnerability scanning, penetration testing, code review, and monitoring of systems and dependencies. Vulnerabilities are assessed based on risk, impact, and likelihood, with prioritisation for issues affecting confidentiality, integrity, or availability. Security patches are deployed based on severity, with critical issues addressed as a priority and lower-risk items remediated through scheduled releases. Threat intelligence is sourced from cloud provider advisories, vulnerability databases, penetration testing reports, and industry best-practice guidance.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Snapshot AI operates protective monitoring aligned with ISO/IEC 27001 and SOC 2 Type II. Potential compromises are identified through centralised logging, automated alerts, and continuous monitoring of system activity, access patterns, and security events. Logs are reviewed and correlated to detect unusual or suspicious behaviour. When a potential compromise is identified, incident response procedures are initiated, including investigation, containment, and remediation as required. Security incidents are triaged promptly, with initial assessment and response initiated as soon as practicable, and critical incidents prioritised for immediate action and escalation.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Snapshot AI operates a formal incident management process aligned with ISO/IEC 27001 and SOC 2 Type II. Pre-defined procedures exist for common incident types, including security, availability, and data-related events. Users can report incidents via email or phone support channels, or through their designated contact where applicable. Incidents are triaged, prioritised, and managed according to severity, with escalation where required. Incident updates and resolution information are communicated directly to affected users, and post-incident reports are provided where appropriate, outlining impact, root cause, and corrective actions.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 8%
- Between £500,001 and £1,000,000
- 12%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 18%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- CFECert Certification Limited
- ISO/IEC 27001 accreditation date
- Friday 26 September 2025
- What the ISO/IEC 27001 doesn’t cover
-
The ISO/IEC 27001 certification applies only to the scope defined on the certificate.
Activities, systems or services that fall outside this defined scope are not covered. This may include customer-managed infrastructure, customer internal systems, third-party services not under our operational control, and end-user devices or environments.
Any services or environments not explicitly included in the ISMS scope are therefore excluded from certification coverage. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- SOC 2 Type I
- SOC 2 Type II
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-