Security and privacy
Privacy by architecture, not by policy.
There is no upload path to disable and no retention setting on a server you do not own. The footage stays in the building because there is nowhere else for it to go.
What is protected, and how
Phone to recorder. TLS 1.3, a pinned certificate and mutual TLS. The app authenticates the recorder and the recorder authenticates the app.
Secrets. Camera credentials and keys live in a sealed vault that is not on the bus. A subscriber cannot read them by subscribing.
Identity. Each class of process runs under its own uid, so the detector cannot do the recorder's job and neither can touch the vault.
Recordings. Files on your disk, under your retention rule, exported only when a person asks for a clip.
The pentest ledger is a document with open items
We keep a written security ledger: what was tested, what was found, what was fixed, and what is still open. It is the document we work from, and we would rather you read it than a badge. Whether the full ledger is published, and where, is being decided.
SLOT · PENDING D6
Reporting something
A disclosure address, a security.txt and a stated response expectation belong here. They are being settled and this page will carry them rather than a promise we have not agreed to.
SLOT · PENDING D6
What we do not claim
No ONVIF or Profile S/T conformance. No NDAA or TAA compliance. No UL or EN certification.
No claim of GDPR compliance. We can describe the architecture's privacy properties; we cannot certify yours.
No uptime or SLA figures, and no comparison against a named product we have not actually measured.