Skip to main content

Help us improve the Digital Marketplace - send your feedback

CAMERAFORENSICS LTD

CameraForensics Site Fingerprinting

Tackling illegal online material is hard because sites are quickly re-established after takedown. The Site Fingerprinting system combats this by crawling target domains and linked sites to extract a unique "fingerprint" from over 20 characteristics. This allows investigators to identify and classify recurring sites, even if superficially modified.

Features

  • Identifies sites that are quickly re-established after takedown
  • Robustly links sites that are superficially modified
  • Automated classification of sites of interest
  • Ability to navigate complex ring sites and gateway configurations
  • Handles multiple users and prevents duplication of effort
  • Extensible to other use cases with customisable criteria (on quote)

Benefits

  • Helps to prioritise investigator workload, resources and focus
  • Provides robust classifications that are easy to verify
  • Increases throughput of takedown requests
  • Deconfliction ensures work is not repeated
  • Saves time and effort by highlighting sites already discovered
  • Reduces investigator exposure to harmful material
  • Proven impact on the distribution of illegal and harmful material

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at alan@cameraforensics.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 0 3 9 1 3 2 8 5 2 9 6 5 4 4

Contact

CAMERAFORENSICS LTD info@cameraforensics.com
Telephone: 07812165133
Email: alan@cameraforensics.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Police
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service runs via recent Chromium-based browsers (Chrome, Edge) and requires a suitable external internet connection. No other software or local downloads required. https internet connection is required and is subject to local firewall and access control policies. Connectivity is verified using TLS certification.
System requirements
  • The service is accessed via a Chromium based web browser
  • Local firewall and access control policies that permit https connection

User support

Email or online ticketing support
Yes
Support response times
Our system is accessible 24/7 with an availability well in excess of 99.9% over the past 3 years. Second-line support will be provided via a dedicated email account. Users and/or their first line support will be able to raise issues which will be responded to by email or telephone during business hours (typically within 2 hours), or if reported out of hours, at the start of the next working day.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Second-line support is provided via a dedicated email account. This facilitates the reporting of issues at any time, and prompt response during business hours. This approach also has the advantage that it is independent of the status of the main system and therefore provides a robust mechanism for problem reporting. Users and/or their first line support will be able to raise issues which will be responded to by email or telephone during business hours, or if reported out of hours, at the start of the next working day. Where the CameraForensics team have proactively identified any issues the same reporting, fix and communication process will be used. Monthly reporting, including standard metrics on the service performance against the SLA and issues raised and resolved, will be provided. This level of support is included in the baseline service costs. Provision of on-site support (e.g. training) can be provided at an additional per-event cost.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We design our powerful user interface to be efficient and intuitive, thereby minimising training requirements and making the tool suitable for infrequent use. There are inbuilt online help tips, which guide the user on how to get the most out of the system, and we employ tooltips to clarify elements that might not be immediately obvious. Additional on-site training can be delivered (at extra cost) to develop expert users and local champions.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Retained information includes user search histories and search parameters included in the standard audit log. The logs for a given user or organisation can be provided on request to appropriate management account holders. Data is typically provided in CSV format.
End-of-contract process
At the end of a contract period, the associated user and manager accounts are suspended. API keys are disabled. Account data can be provided and/or deleted at the customer's request. Accounts and keys can be preserved and reactivated under a new contract.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Our powerful user interface is efficient and intuitive, thereby minimising training requirements and making the tool suitable for infrequent use. Searching is straightforward yet powerful, allowing users to user different combinations of text-based search queries and image fragments or descriptors as appropriate.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service interface is tested using a combination of automated checks and user testing.
API
No
Customisation available
No

Scaling

Independence of resources
Professional performance testing and measurement software Gatling is used to test the system. This enables us to define testing criteria and ramp up users to beyond a life-like usage profile to stress-test the system.

Analytics

Service usage metrics
Yes
Metrics types
The system records active users and logins This data are available to nominated client administrator accounts. If necessary, collection of this data can be disabled to meet user security or privacy requirements. All data described can easily be exported in a format to be agreed with the user (e.g. CSV) for subsequent loading and analysis in other systems.
Reporting types
Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
No
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Data related to customer accounts can be provided on request. This includes activity and search criteria per user account.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Our system is accessible 24/7 with an availability well in excess of 99.9% over the past 3 years. In our experience of operating the system to date the most serious incidents encountered have been resolved within 2 hours.
Approach to resilience
We are dependent on hosting services and connectivity provided by world-class third party suppliers, under standard commercial terms. The hosting services include full backup and failover contingencies which provide robust assurance that underpins our service commitments.
Outage reporting
Service status, outages and planned maintenance are communicated via a “splash screen” at the login page, and by automated response to queries to our second-line support via email. Significant outages are reported via email to nominated client leads.

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through a combination of least privilege principles, role-based access control (RBAC), multi-factor authentication (MFA), and strict network segregation.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We have an ISO27001-compliant Information Security Management System which has been externally audited. Currently in a pre-certification status with certification expected by end of March 2026
Information security policies and processes
We operate an ISO27001-compliant Information Management System. Management Reviews of the ISMS are held six times a year by Company Directors to ensure that the ISMS
- remains aligned with organisational goals
- complies with relevant standards and regulations,
- adapts to changes in both internal and external environments.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
The overarching Change Management Policy establishes the high-level framework that applies to all software development, service delivery, and infrastructure resources. It mandates that all changes must be: Planned - Assessed - Authorized - Tested - Documented - Communicated. Changes to software and applications follow the Secure Development Process, utilising a CI/CD approach to ensure quality and security. The Network Service Configuration Process mandates that configuration should be defined in code and deployed using automated processes, minimising manual intervention. Production servers are deployed and configured using Ansible playbooks.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
The vulnerability management process at CameraForensics is a comprehensive framework designed to identify, evaluate, prioritise, and mitigate security weaknesses across IT infrastructure, software development, and end-point devices. The organisation employs a multi-layered approach to detecting vulnerabilities, integrating automated tools into both the operational environment and the software development lifecycle (SDLC). The Patch Management Process dictates how updates are applied across different asset types to ensure compliance with defined timelines for critical updates. CameraForensics obtains information about potential threats and vulnerabilities from a combination of automated technical tools, internal research, external vendor guidance, and human reporting.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
The protective monitoring processes are primarily detailed in our Logging and Monitoring Process, which establishes specific procedures based on the type of infrastructure component being monitored. Monitoring is applied servers used for container-based services, production services, The Application Load Balancer handling traffic to the organisation's domain and all management events within the infrastructure. Regulators are notified within their mandated timescales (typically 72 hours. For buyers the service level agreement defines contact via phone or email with a target time of within 4 hours. Nominated user representatives are notified via website notices or email with an escalation target of 2 hours.
Incident management type
Supplier-defined controls
Incident management approach
Our incident management framework is designed to detect, report, and resolve information security incidents promptly. The process prioritises the protection of confidentiality, integrity, and availability of assets while ensuring compliance with legal and contractual obligations. User reporting is provided for via the user support mechanisms defined elsewhere. Incident reports are provided post-event in an internal format (minor) or Buyer-defined reporting (major).
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
3%
Between £1,000,001 and £2,500,000
4%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
1f3bf8bb-9ef5-4855-8d0c-5aeebe1b1dba
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
3b8bda26-e465-42ce-a7d7-de49237029b3
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at alan@cameraforensics.com. Tell them what format you need. It will help if you say what assistive technology you use.