01 · Technology · Security

There's less attack surface when there's less data.

No video to ransom. No face database to leak. No third-party identity broker. The privacy architecture is also a security posture - the strongest control is the data you never collected.

02 · Encryption

In transit. At rest. End-to-end.

In transit
TLS 1.3

Sensor → platform. Mutual auth (mTLS) on managed deployments.

At rest
AES-256

Aggregated counts only. Per-tenant KMS key.

Sensor → SoC
MIPI · physical

Frames never reach a network interface.

03 · Sub-processors

The list, in plain English.

Provider Purpose Region Data
AWS (Sydney) Product platform, full stack: compute, storage, data pipeline (ap-southeast-2) AU Aggregated counts & sensor telemetry
Vercel Marketing website only: hosting, CDN & cookieless analytics AU · syd1 Web traffic; anonymous usage & performance metrics
Google (Workspace) Lead capture (Sheets) & demo scheduling (Calendar) AU Contact-form submissions, booking details
GitHub Source code repository US No customer data
04 · Compliance posture

Where we are. Where we're going.

NOW

GDPR-clean architecture

No personal data collected under Article 4. DPA available on request. APP-aligned. ICO design-by-default tick.

2027

SOC 2 Type I targeted

Initial Type I scoping starts H1 2027. Vanta is selected for evidence collection. Drata under evaluation.

2028

ISO 27001 path

Following SOC 2 Type II, the ISO 27001 path is queued. Tied to enterprise customer demand, not a calendar.

05 · Responsible disclosure

Found something? Send it to security@.

We treat vulnerability reports with respect. Acknowledgement within 24h, fix or mitigation within 30 days for critical issues. Reasonable disclosure timelines negotiated case-by-case.

security@occivar.com PGP key on request
06 · Send us your toughest review

Procurement and IT-security teams welcome.