Security & deployment

Cloud native. Your data stays yours.

Snaptiq runs on managed Microsoft Azure services, with access decided by the platform itself, media behind short-lived signed links, and a software supply chain documented down to the component.

Private, managed infrastructure

Managed containers, a managed PostgreSQL database and private storage, reached with managed identities rather than stored keys. Media is served only through short-lived signed links, issued after the platform checks who is asking.

Access enforced by the platform

Role permissions and decision gates are enforced in the platform’s workflow engine, not just hidden in the interface. Sign in with OpenID Connect single sign-on or a password with authenticator-app MFA; CAC sign-in for government deployments is in development.

A full audit trail

Every transition, approval and refused action is recorded against the user, the time and the version it concerned.

Software bill of materials

CycloneDX SBOMs for every image, a dependency and license inventory, and container vulnerability scanning with remediation records.

A certified team

HyerTek, which builds and operates Snaptiq, holds ISO 27001, ISO 20000-1 and ISO 9001:2015 certifications and CMMC 2.0 Level 2, independently validated by a C3PAO. About HyerTek

AI under your control

AI services are opt-in, one capability at a time, and every call is metered. Using a non-Azure AI video service needs a per-project permission recorded on the audit trail.

Ownership

Who owns what.

Your source documents, the content produced from them and the traceability record belong to you. Snaptiq is HyerTek’s platform, licensed to you to produce and govern that content.

Deliverables are open formats — MP4, VTT, CSV, Office documents, JSON and QTI — with written instructions to rebuild the video without Snaptiq. No proprietary player, continuous cloud sign-in or recurring fee is needed to use what you’ve received.

Deployment options

Cloud & architecture

  • Dedicated deployment, managed by HyerTek, in an environment of its own
  • Government cloud: the same platform deploys into your own subscription with a change of cloud and region
  • No on-premises footprint, by design

Feature availability

What runs in each environment.

Snaptiq runs in commercial and government cloud. A few features depend on services that aren’t offered at every Impact Level, so they change or switch off in government deployments. Everything else is the same everywhere.

FeatureCommercialGovernment · IL4Government · IL5
AI-generated videoGenerated shots from Google Veo on Vertex AIAvailableWith setupRequires Google Assured Workloads (IL4), enabled per deploymentNot availableUse curated footage, screen recordings or narrated cards
Avatar presentersStock and custom presenters reading the narrationAvailableNot availableSpeech is available; avatar is notNot availableSpeech is available; avatar is not
Automatic video analysisTranscript, on-screen text and suggested scene ranges for uploaded footageAvailableAvailableNot availableAuthors map footage to scenes by hand
Email notificationsReview notices, account links and finished-work messagesAvailableWith setupThrough your approved SMTP relayWith setupThrough your approved SMTP relay

Available in every environment

  • AI drafting of briefs, objectives, requirements, storyboards, narration and questions
  • Narration with a pronunciation lexicon
  • Reading PDF and Word sources
  • Curated footage, screen recordings and narrated cards
  • Traceability, decision gates, approvals and the audit trail
  • Change detection and scene-level rework when a source is revised
  • Question bank and exports (QTI, Moodle XML, GIFT, Excel, Word)
  • SCORM 1.2, SCORM 2004 and cmi5 packages
  • Captions, transcripts and audio-described versions
  • Single sign-on and MFA (CAC in development); classification banner on screens and exported video

Impact Level authorization is granted to each deployment by its authorizing official. Government (IL4 and IL5) deployments are in preparation; this table shows which Snaptiq features are planned to run in each environment, based on the Azure and Google services each one relies on.

Plainly stated

What we don’t claim.

Security reviewers read the fine print, so here it is up front.

  • We build Snaptiq to map to the security controls government cloud environments require, to reduce the time and effort of your Risk Management Framework (RMF) process. Snaptiq does not currently hold a FedRAMP authorization or an agency Authority to Operate (ATO). Every agency has its own configuration requirements, so we support your ATO with architecture, SBOM, vulnerability scanning and configuration documentation, and when we deploy Snaptiq in your cloud, we work alongside your security team to get the configuration right for your environment.
  • Snaptiq is not authorized for classified information.
  • Section 508: delivery requires a recorded Section 508 conformance check, but the platform does not itself test conformance, and we don’t yet publish a VPAT.

Need the documentation for a review? Get in touch and we’ll send the architecture overview, SBOM and latest scan results.

Talk to us about your security requirements.

We’ll walk your security team through the architecture, the data flows and the supply-chain documentation.