CameraForensics Ember
CameraForensics Ember (previously Labs) is a suite of tools designed to search, analysis and cluster collections of sensitive media (images and video). The architecture provides a vendor-agnostic hosting strategy to allow for the integration, evaluation, validation and deployment of best-in-class analysers and classifiers.
Features
- Search by description: Find media using natural language
- Automatic clustering using specific image features
- Similar image search
- Generative AI: detection of created and modified images
- Complete Exif searching across your media
- Detailed worldwide mapping
- Automatic Project VIC indexing
- Imports of CameraForensics OSINT data to identify online leads
- Flexible deployment options including local air-gapped installation
Benefits
- Rapidly analyse large media caches to establish investigative priorities
- Intuitive user interface with multiple search criteria options
- Organise large media caches based on visual and non-visual features
- Quickly extract new intelligence from unstructured media collections
- Deployable on public or private cloud infrastructure
- Can be delivered to air-gapped systems for sensitive media analysis
- Easily updated with the latest analysis techniques
- Automatic Project VIC categorisation for classification of CSAM
- Import OSINT data and hashlists to identify external leads
- Reduce manual assessment work, focus investigators time on new intelligence
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 8 7 8 4 4 6 0 5 3 2 9 9 4 9
Contact
CAMERAFORENSICS LTD
info@cameraforensics.com
Telephone: 07812165133
Email: alan@cameraforensics.com
About the service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Users access the service through an internet browser. No software download is required to access a cloud-instance. Local installation is also available - e.g. onto a HighSide system. Suitable hardware can be provided if required. For cloud-instances https internet connection is required and is subject to local firewall and access control policies. Connectivity is verified using TLS certification. Access control is via email accounts within pre-approved domains. The service is supported for recent releases of Edge, Chrome and Mozilla Firefox.
- System requirements
-
- Internet Browser: Chrome, Firefox or Edge
- Local firewall and access control policies that permit https connection
- All licencing required for analytics components is included
- Local installation requires appropriate hardware, including at least one GPU
- Hardware can be configured and delivered by CameraForensics if required
User support
- Email or online ticketing support
- Yes
- Support response times
- Our system is accessible 24/7 with an availability well in excess of 99.9% over the past 3 years. Second-line support will be provided via a dedicated email account. Users and/or their first line support will be able to raise issues which will be responded to by email or telephone during business hours (typically within 2 hours), or if reported out of hours, at the start of the next working day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Second-line support will be provided via a dedicated email account. This facilitates the reporting of issues at any time, and prompt response during business hours. This approach also has the advantage that it is independent of the status of the main system and therefore provides a robust mechanism for problem reporting. Users and/or their first line support will be able to raise issues which will be responded to by email or telephone during business hours, or if reported out of hours, at the start of the next working day. Where the CameraForensics team have proactively identified any issues the same reporting, fix and communication process will be used.
Monthly reporting, including standard metrics on the service performance against the SLA and issues raised and resolved, will be provided.
This level of support is included in the baseline service costs.
Provision of on-site support (e.g. training) can be provided at an additional per-event cost. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We design our powerful user interface to be efficient and intuitive, thereby minimising training requirements and making the tool suitable for infrequent use. There are inbuilt online help tips, which guide the user on how to get the most out of the system, and we employ tooltips to clarify elements that might not be immediately obvious.
Formal training can be delivered in-person or remotely. Some remote training for new users is included in the licence cost. Additional on-site training can be delivered (at extra cost) to develop expert users and local champions. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Retained information includes user account information. This can be provided on request to appropriate management account holders. Data is typically provided in CSV format.
- End-of-contract process
-
At the end of a contract period, the associated user and manager accounts are suspended.
Account data can be provided and/or deleted at the customer's request.
Accounts and keys can be preserved and reactivated under a new contract. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- Yes
- Compatible operating systems
- Linux or Unix
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Our powerful user interface is efficient and intuitive, thereby minimising training requirements and making the tool suitable for infrequent use. Searching is straightforward yet powerful, allowing users to user different combinations of text-based search queries and image fragments or descriptors as appropriate.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service interface is tested using a combination of automated checks and user testing.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Professional performance testing and measurement software Gatling is used to test the system. This enables us to define testing criteria and ramp up users to beyond a life-like usage profile to stress-test the system.
Analytics
- Service usage metrics
- Yes
- Metrics types
- For cloud-based installations Ember can provide records of active users, logins, system interactions etc including a timestamp for each of the various events. This data are available to nominated client administrator accounts. If necessary, collection of this data can be disabled to meet user security or privacy requirements. All data described can easily be exported in a format to be agreed with the user (e.g. CSV) for subsequent loading and analysis in other systems.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- No
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
- Data related to customer accounts can be provided on request. This includes activity and search criteria per user account. Operational data is extracted through a variety of approaches depending on the user requirements and system configuration - by default extraction via csv and/or json is available.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Json
- Data import formats
-
- CSV
- Other
- Other data import formats
- A wide range of image and video formats are accepted
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Our system is accessible 24/7 with an availability well in excess of 99.9% over the past 3 years. In our experience of operating the system to date the most serious incidents encountered have been resolved within 2 hours.
- Approach to resilience
- We are dependent on hosting services and connectivity provided by world-class third party suppliers, under standard commercial terms. The hosting services include full backup and failover contingencies which provide robust assurance that underpins our service commitments.
- Outage reporting
- Service status, outages and planned maintenance are communicated via a “splash screen” at the login page, and by automated response to queries to our second-line support via email. Significant outages are reported via email to nominated client leads.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through a combination of least privilege principles, role-based access control (RBAC), multi-factor authentication (MFA), and strict network segregation.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We have an ISO27001-compliant Information Security Management System which has been externally audited. Currently in a pre-certification status with certification expected by end of March 2026
- Information security policies and processes
- We operate an ISO27001-compliant Information Management System. Management Reviews of the ISMS are held six times a year by Company Directors to ensure that the ISMS -remains aligned with organisational goals -complies with relevant standards and regulations, -adapts to changes in both internal and external environments.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- The overarching Change Management Policy establishes the high-level framework that applies to all software development, service delivery, and infrastructure resources. It mandates that all changes must be: Planned - Assessed - Authorized - Tested - Documented - Communicated. Changes to software and applications follow the Secure Development Process, utilising a CI/CD approach to ensure quality and security. The Network Service Configuration Process mandates that configuration should be defined in code and deployed using automated processes, minimising manual intervention. Production servers are deployed and configured using Ansible playbooks.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- The vulnerability management process at CameraForensics is a comprehensive framework designed to identify, evaluate, prioritise, and mitigate security weaknesses across IT infrastructure, software development, and end-point devices. The organisation employs a multi-layered approach to detecting vulnerabilities, integrating automated tools into both the operational environment and the software development lifecycle (SDLC). The Patch Management Process dictates how updates are applied across different asset types to ensure compliance with defined timelines for critical updates. CameraForensics obtains information about potential threats and vulnerabilities from a combination of automated technical tools, internal research, external vendor guidance, and human reporting.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The protective monitoring processes are primarily detailed in our Logging and Monitoring Process, which establishes specific procedures based on the type of infrastructure component being monitored. Monitoring is applied servers used for container-based services, production services, The Application Load Balancer handling traffic to the organisation's domain and all management events within the infrastructure. Regulators are notified within their mandated timescales (typically 72 hours. For buyers the service level agreement defines contact via phone or email with a target time of within 4 hours. Nominated user representatives are notified via website notices or email with an escalation target of 2 hours.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management framework is designed to detect, report, and resolve information security incidents promptly. The process prioritises the protection of confidentiality, integrity, and availability of assets while ensuring compliance with legal and contractual obligations. User reporting is provided for via the user support mechanisms defined elsewhere. Incident reports are provided post-event in an internal format (minor) or Buyer-defined reporting (major).
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 1f3bf8bb-9ef5-4855-8d0c-5aeebe1b1dba
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- 3b8bda26-e465-42ce-a7d7-de49237029b3
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors