Infrastructure Deployment: The first step involves setting up the core conferencing system, whether this is a direct subscription to the VidyoCloud service or a hybrid deployment that includes installing local infrastructure software like the VidyoPortal for centralized management.
System Configuration and Integration: Administrators use the VidyoPortal to configure system policies, manage user privileges, and integrate the system with existing enterprise tools. This phase includes connecting the solution to systems like LDAP or Active Directory for secure user authentication. For compatibility, VidyoGateway components may be deployed to connect with existing H.323 and SIP devices.
Client Software Distribution: The VidyoConnect client must be distributed and installed on user endpoints (desktop or mobile). For consistency, system administrators can use the MSI installer and set installation parameters to deploy a uniform configuration across all PCs.
User Onboarding and Training: The final phase focuses on adoption. Users are given access to their personal virtual rooms and provided with a unified user experience across all devices. Training resources and a training interface are made available to quickly onboard the workforce.
Customisation
Administrative Custom Invocation: This advanced feature allows administrators to leverage a middleware solution to launch the application using specific parameters. This provides deep control over endpoint behavior, such as automatically logging in users, disabling or enabling in-call features like chat, search, or content sharing, or enforcing default settings like muting the microphone or camera upon joining a call.
Custom User Interface (UI) and Workflow Integration: The platform supports the use of iFrames (pre-call, in-call, and post-call) to embed the video experience directly within a business's application or web portal. This enables a seamless, branded user flow without having to leave the primary business application.
In-Call User Customization: End-users have control over their personal meeting experience. They can select their desired Conference Profile (e.g., Full-Features Experience for audio/video/content or Voice+Content for audio-only), adjust the Outbound Video Bitrate Setting to balance quality and bandwidth, and even use features like custom or blurred backgrounds.
Client Layout Customization: The conferencing layout itself is customizable, allowing users to control the view of participants on their mobile devices, supporting different on-screen participant limits for phones versus tablets.
Subscription and Licensing Fees: The fundamental cost is for named user subscriptions, available under different plans (e.g., Team Plan, Enterprise Plan) for one, two, or three-year terms. These fees are typically paid at the start of the term and are often non-refundable. The number of named user subscriptions purchased determines the deployment size.
Maintenance and Software Updates: These charges are integrated into the annual subscription fee. The service includes continuous product updates, fixes, and maintenance for the VidyoCloud service and the included endpoints without requiring separate fees.
Support Charges: Enterprise-level support is also part of the annual subscription. The level of support provided is detailed in the VidyoConnect Service & Support Policy.
Setup or Integration Fees: Separate setup fees are not commonly publicized as a distinct charge outside of the subscription. Furthermore, essential integration clients like the Outlook Calendar Add-In are provided with no additional charges once a valid subscription is in place.
Add-on Packages: For organizations requiring greater capacity, there are optional charges for add-on services. These include purchasing more international dial-in numbers, increasing the number of concurrent voice callers, or buying large blocks of additional VidyoVoice minutes beyond the standard allowance included with each user subscription.
Training
Self-Service Documentation and Guides: Comprehensive User Guides provide step-by-step instructions for all pre-call, in-call, and mobile functionalities. This includes details on how to join meetings, search for contacts or rooms, and manage various in-call features.
Online Training Resources: Focused training sessions and introductory videos are often made available to help new users quickly grasp the essentials. These materials are typically segmented by role, such as a 15-minute training session for desktop meeting organizers or a shorter session for mobile users.
Simplified Client Installation: The process of downloading and installing the client, especially for mobile users via the App Store or Google Play, is streamlined. The application guides users through initial steps like accepting the license agreement and granting access to the camera and microphone.
Direct Support Channels: End-users with service coverage (often "Plus" coverage) can contact a Vidyo Support Team directly via phone or email for technical assistance. Users without this direct support are typically advised to contact their authorized Vidyo Reseller for help.
Security Measures
Secure Communication Encryption:
Media Encryption: All media streams (audio and video) use SRTP (Secure Real-time Transport Protocol) encryption with AES-128 encryption to secure the content being transmitted during a call.
Signaling Encryption: Communication between the endpoints and the server components is secured using TLS (Transport Layer Security) with strong encryption ciphers.
Rigorous Authentication and Access Control:
Secure Login: The login process is protected by establishing an encrypted HTTPS channel and utilizing an industry-standard Public Key Infrastructure (PKI) to verify server identity before login credentials are sent.
Enterprise Integration: The platform supports robust enterprise authentication protocols like SAML 2.0 and integration with LDAP/Active Directory. Using SAML is highly recommended as it authenticates users via external identity providers, meaning credential data is not stored or exposed on the VidyoConnect service.
Password Protection: For users not using SAML/LDAP, passwords in the database are hashed and salted using PBKDF2 to ensure they cannot be revealed even in the event of a security breach.
Proactive Security Management:
The platform actively monitors for vulnerabilities, utilizing resources like the NIST National Security Database and industry-leading security scanning tools (e.g., Tenable's Nessus) before and after updates.
The architecture ensures that all Vidyo endpoints connect through the cloud and are not directly accessible from another endpoint's IP address, protecting them from unauthorized direct access on public networks.
Updates
Update Frequency: Updates are released frequently, with a pattern of major and minor versions throughout the year. Release notes for the desktop client, for example, often show several updates (bug fixes, feature additions, and security patches) within a single quarter.
Management of Updates: The subscription service includes the management of product updates and fixes for the VidyoConnect service and its endpoints. For a cloud-based deployment, this is handled by the vendor (Vidyo), which manages the cloud-based infrastructure.
Deployment and Distribution: Updates are typically made available for the client software and for any on-premise infrastructure software components (like the VidyoPortal). Organizations with on-premise components may need to manage the rollout of these updates, though the service provides the necessary product updates and fixes on a continuous basis.
User Action for Updates: End-users are generally advised to keep their applications up to date to ensure they have the latest features and critical security patches. For desktop users, the update process is often managed centrally via the enterprise's IT department, which distributes the latest client versions.
Data Ownership and Portability
Customer Data Ownership: The customer explicitly owns and retains all exclusive title and rights to the Customer Data and any information or material that the customer and its users submit or process using the services. The customer is solely responsible for the quality, integrity, security, and legality of all this data.
Vendor Intellectual Property: The vendor retains all exclusive title and rights to the service itself, including the underlying technology, software, documentation, and any improvements or modifications made to the platform.
Data Portability and Retrieval:customer data ownership implies the right to portability. Upon the termination of services, a well-structured contract would outline the customer's right to retrieve all their data, including any data derived from it, although the method and format for bulk data export are governed by the specific subscription terms and conditions.
Customer Responsibility for Backup: The customer agrees to separately back up all Customer Data, indicating that while the vendor secures the data, the ultimate responsibility for data retention and redundancy rests with the customer.
Scaling Up / Down
Scaling Up (Increase in Users): Scaling the service to meet increased demand is accomplished by purchasing additional named user subscriptions to achieve the desired deployment size. The platform is designed for enterprise scaling, and the subscription model allows organizations to add capacity as needed.
Subscription Term Lock-in: Subscriptions are offered in fixed terms (e.g., one, two, or three-year terms) and are paid annually. This contractual lock-in provides cost stability but limits the ability to scale down or cancel service mid-term.
Non-Refundable Fees: The annual service subscription fees are typically non-refundable. This means that if an organization's needs decrease mid-year, the organization will not receive a refund for unused user licenses for that pre-paid term.
End of Term Review: The most flexible time for an organization to scale down its commitment is at the end of the subscription term. If the subscription is not renewed, the user accounts and access to the services will terminate.
The terms & conditions for contract renewal and cancellation
Automatic Contract Renewal: The services are typically contracted for an Initial Term and will automatically renew for the same period (the Renewal Term) unless the customer takes specific action to terminate the agreement.
Cancellation Notice Requirement: To prevent the automatic renewal of the contract, the customer is generally required to provide the vendor with a written notice of termination a specified number of days (commonly sixty (60) days) before the end of the current term. Failure to provide this timely notice will result in the contract automatically extending.
Non-Cancellable Fees: The obligation for the customer to pay for all ordered services is non-cancellable. Once the service is paid for, all sums are non-refundable, even if the customer chooses to stop using the service before the term expires.
Vendor's Right to Increase Fees: The vendor reserves the right to increase fees upon the anniversary of the agreement, provided they give the customer a thirty (30) calendar days' prior written notice of the price change.
Compliance
Health Insurance Portability and Accountability Act (HIPAA): The platform is designed with features, like strong encryption, that help customers maintain HIPAA compliance. This is particularly relevant for healthcare organizations using the software for telehealth and virtual consultations that involve protected health information (PHI).
Service Organization Control 2 (SOC 2): The service is hosted in secure data centers that have SOC 2 audit reports available for review. Achieving SOC 2 compliance demonstrates that the vendor's controls over its information security meet the criteria for security, availability, processing integrity, confidentiality, and privacy.
Federal Information Processing Standards (FIPS 140-2): The software utilizes FIPS 140-2 certified libraries for its encryption methods. This is a U.S. government standard that validates the security and cryptographic modules used by the system, often required for government and high-security enterprises.
ISO 27001 Framework: The vendor's information security governance policy is structured to follow the domains of the ISO 27001 information security framework. This standard provides a global guideline for managing information security risks.
Data Protection Regulations (GDPR Readiness): The application is designed to comply with global data privacy regulations. Users are prompted to read and accept the updated User Terms and Conditions and Privacy Policy upon their first login in accordance with data privacy regulations such as the European Union's GDPR.