GDPR-clean architecture
No personal data collected under Article 4. DPA available on request. APP-aligned. ICO design-by-default tick.
No video to ransom. No face database to leak. No third-party identity broker. The privacy architecture is also a security posture - the strongest control is the data you never collected.
Sensor → platform. Mutual auth (mTLS) on managed deployments.
Aggregated counts only. Per-tenant KMS key.
Frames never reach a network interface.
No personal data collected under Article 4. DPA available on request. APP-aligned. ICO design-by-default tick.
Initial Type I scoping starts H1 2027. Vanta is selected for evidence collection. Drata under evaluation.
Following SOC 2 Type II, the ISO 27001 path is queued. Tied to enterprise customer demand, not a calendar.
We treat vulnerability reports with respect. Acknowledgement within 24h, fix or mitigation within 30 days for critical issues. Reasonable disclosure timelines negotiated case-by-case.