Security and data

A vision platform sees people. That sets the bar.

VisaRoxy is deployed on sites where staff, contractors, drivers and sometimes the public are in frame. This page states what the platform processes, where it runs, what it stores, and what we do not claim.

Position

Four commitments the architecture enforces.

Each one is a property of how the platform is built rather than a policy statement. That distinction is the point.

Video stays put

Inference runs in the environment you nominate. Video does not have to leave your network.

Events, not archives

The platform stores event records and short event clips, not continuous recordings of every stream.

Exclusion before inference

Privacy zones are removed from the frame before the model sees it, not blurred on the way out.

No invented certifications

VisaRoxy holds no compliance certification and claims none. Posture is agreed per deployment.

Data categories

What the platform actually handles.

Six categories, with different sensitivity and different retention behaviour. Keeping them separate is what allows an analyst to work with counts without being granted access to video.

Video frames
Decoded from camera streams for analysis. Frames are processed in memory and are not written to disk as a continuous record. This is the category that most often contains identifiable people, which is why it is the one the deployment model is designed around.
Event records
Structured metadata describing what was observed: event name, zone, severity, duration, timestamp, camera, agent. Contains no image data and no identity. This is the category that most downstream systems consume.
Event clips
A short window of video around a confirmed event, written only when an agent's action set asks for one. Held for the site's clip retention window and then removed. Clips are access-controlled separately from event metadata.
Configuration
Zones, rules, thresholds, schedules, escalation paths and agent definitions. Site-confidential rather than personal, and versioned so a change can be traced to the person who made it.
Identity and access
Operator accounts, role assignments and session records. Where single sign-on is configured, authentication happens against your directory and VisaRoxy holds the role mapping rather than the credential.
Audit log
Rule changes, configuration edits, clip exports, access grants and administrative actions, each attributed to a named user with a timestamp. This is the record that answers "who changed this, and when".

Data flow

Where the video goes, in three deployment models.

The single most useful question a security reviewer can ask about a vision platform is where the frames are processed. VisaRoxy answers it per site, and the answer is a deployment choice rather than a setting.

  • Edge applianceFrames are decoded and analysed on hardware inside the site network. Video never traverses the WAN. Events and clips stay local unless a destination is configured outside the site.
  • Your private cloudFrames travel from the site to a tenancy your organisation controls. Your existing cloud security controls, network policy and logging apply to the runtime.
  • Managed tenancyFrames travel to a tenancy operated by VisaRoxy for your deployment. The smallest operational lift, and the model that needs the most scrutiny from your security team.

Whichever model is chosen, outbound event delivery is explicit: events are sent only to endpoints you nominate and approve, and every delivery attempt is recorded against the event.

Deployment: dc-north

Edge appliance · on site network

Video on site
  • Camera Stream published on the site LAN Never leaves the network
  • Runtime Decode, exclude, detect, track, evaluate On the edge appliance
  • Store Event records and short clips Local storage, site retention window
  • Outbound Event metadata to approved endpoints 4 destinations on the allow-list
  • Updates Signed application updates Applied by site engineering

Illustrative interface with sample data.

Minimisation

Collecting less is the control that works.

Access control and encryption protect data you hold. The stronger move is not holding it. Three design decisions in VisaRoxy come from that principle.

The first is that privacy zones are applied before inference. An excluded area is removed from the frame before detection runs, which means the model never receives those pixels and there is no stage at which they could be recovered. Blurring an area on output is a different guarantee, because the underlying frame still existed and still passed through the pipeline.

The second is that the default store is events rather than video. A platform that keeps a thirty-day archive of every stream has created a large, sensitive dataset that most operational questions do not need. VisaRoxy keeps the event and the clip around it, which is enough to answer what happened and who responded, and far less than a continuous record.

The third is that agents work with classes, zones and durations rather than identities. VisaRoxy is not a face recognition product and is not designed to determine who a person is. An agent can tell you that a vehicle was in a walkway for eleven seconds; it cannot tell you who was driving, because that information is not produced anywhere in the pipeline.

Workforce considerations

Sites deploying vision usually have consultation obligations to the people who work under those cameras. That is a site responsibility, and we would rather help a customer prepare for it than have them discover it after go-live. Deployment documentation is written to be shareable with a works council or employee representative body.

Access and retention

Who can see what, and for how long.

Both are configuration rather than fixed behaviour, because a site's obligations differ. The defaults are restrictive and the site widens them deliberately.

Access and retention controls, and what each one is for.
Control How it works Why it matters
Role-based access Roles determine whether a user can view events, view clips, edit rules, or administer the deployment. A supervisor can tune a threshold without being able to export video.
Single sign-on Federation against the site's directory, so access follows joiners, movers and leavers. Removes the second place where stale accounts accumulate.
Clip access separate from metadata Event counts and durations are readable without the clip permission. Analysts and BI tools work on numbers without a video grant.
Retention windows Configured per site and per camera group, for event records and for clips independently. Specific periods are agreed with the customer rather than fixed by the product.
Deletion Events, clips and records can be removed on request, and retention windows expire automatically. Supports a subject request or an internal instruction to erase.
Audit log Rule changes, exports, access grants and administrative actions are attributed to a named user with a timestamp. Answers who changed a rule or exported a clip, and when.

Compliance

What we do not claim.

Certification badges are cheap to display and expensive to earn. VisaRoxy does not display any, and this section explains the position rather than dressing it up.

VisaRoxy does not hold or claim SOC 2, ISO 27001, HIPAA, GDPR or any other certification or compliance attestation. Compliance posture for a deployment is agreed with the customer's security team. If a certification is a prerequisite for your procurement, that is a legitimate position and it is better to establish it on the first call than after a pilot.

What the platform does provide is the material a security review needs: a defined data-flow model with a per-site choice of where frames are processed, a documented event payload so what leaves the deployment can be enumerated, role-based access with an attributable audit log, configurable retention, and privacy zones that exclude areas before inference rather than after.

Where an operator is in a regulated sector, the deployment configuration follows the operator's requirements. Retention windows, access model, deployment topology and update process are all set per deployment, which means the same platform can meet a utility's requirements and a retailer's without either inheriting the other's assumptions.

For your security questionnaire

Bring the questionnaire to the walkthrough. Architecture, data flow and retention questions can be answered directly, and anything that depends on your deployment choice will be documented rather than assumed.

Put your security team in the room early.

The deployment topology and retention model are easier to agree before a pilot than after one. Bring the people who will have to sign it off.