Privacy & security

Enterprise-grade from the first pilot

Real-world data means real people and real premises. Consent, custody and confidentiality are designed into the protocol before a single frame is captured — not retrofitted when your security team asks.

How we work

Six commitments on every engagement

Consent Management

Every participant and every site owner gives informed, documented consent before recording begins — in a language they actually read.

  • Written consent in the local language
  • Purpose of use explained before signing
  • Separate site-owner permission for premises
  • Withdrawal honoured, with data removed

Encryption

Data is encrypted from the moment it leaves the capture device until it lands in your bucket.

  • Encrypted at rest on capture media
  • Encrypted in transit on every hop
  • Keys held separately from the data
  • No unencrypted intermediate copies

Access Control

Least privilege by default. Nobody has standing access to a dataset they are not working on.

  • Role-based permissions per project
  • Named accounts, no shared logins
  • Access revoked when a role ends
  • Full audit log of every read

Chain of Custody

Every recording is traceable from the operator who captured it to the moment you receive it.

  • Integrity hashing at capture
  • Verified, resumable upload
  • Custody logged at each handoff
  • Tamper evidence on the record

Documented Processes

Written SOPs for collection, handling and delivery — so a security review has something concrete to read.

  • Standard operating procedures per protocol
  • Operator training and sign-off records
  • Incident response and escalation path
  • Vendor security questionnaires completed

Custom Agreements

Confidentiality, IP and data-handling terms written for your project, not a generic template.

  • Project-specific NDAs
  • IP assignment on delivered datasets
  • Exclusivity terms where you need them
  • Defined retention and deletion windows

Data lifecycle

Where your data is at every stage

Six stages, each with a defined owner, a defined control and a defined record.

01

Capture

Recorded to encrypted media on a supervised device. Hashed on the spot so later tampering is detectable.

02

Upload

Encrypted, resumable transfer from the field. Custody is logged at handoff and the local copy is wiped on confirmation.

03

Quality Assurance

Reviewed only by named QA staff assigned to your project, inside an access-controlled environment.

04

Processing

Metadata generation and any agreed redaction — face or plate blurring, audio removal, location coarsening.

05

Delivery

Pushed to your cloud storage or collected from ours, in the format and structure agreed at scoping.

06

Retention & Deletion

Held only for the agreed window, then destroyed with a written confirmation of deletion.

Consent

The people in your data agreed to be there

This is the part most data vendors gloss over, and the part that becomes your problem later. We treat participant consent as a deliverable, not a formality — and we can evidence it for every episode in a dataset.

Ask for a sample consent pack
  • Informed before recordingParticipants are told what is captured, what it will be used for, and who receives it — before any device is switched on.
  • In a language they readConsent forms are provided in the participant's own language, explained verbally where literacy is a barrier.
  • Fairly compensatedParticipants are paid for their time at agreed rates. Consent is never a condition of employment.
  • Site permission held separatelyFactory, store and household owners give their own documented permission for the premises.
  • RevocableA participant can withdraw. We locate their episodes and remove them, and tell you what changed.
  • Bystanders consideredProtocols are designed to keep non-participants out of frame; where unavoidable, we redact.

De-identification

What we can strip before delivery

Some models need faces, most do not. We agree the redaction profile at scoping so you receive exactly the signal you need and nothing you would rather not hold.

Face blurring

Participants and bystanders obscured while hands, tools and objects stay sharp.

Voice removal

Audio dropped entirely, or speech removed while task sounds are preserved.

Text & signage

Documents, screens, badges, plates and branded signage masked on request.

Location coarsening

GPS reduced to region, or removed, where precise position is not needed.

Identifier separation

Operator and site IDs pseudonymised, with the mapping held apart from the data.

Site anonymisation

Company-identifying detail removed so a customer's premises cannot be traced.

Compliance posture

Where we stand today

We would rather tell you exactly what we have than imply more. Here is our current position, and what we are building toward.

In place

Available now

  • Documented SOPs for collection and handling
  • Written consent records for every participant
  • Encryption at rest and in transit
  • Role-based access control with audit logs
  • Project-specific NDAs and IP assignment
  • Completed vendor security questionnaires
  • Processes designed around India's DPDP Act, 2023

On the roadmap

  • Independent third-party security audit
  • Formal certification programme
  • Customer-facing audit dashboard
  • Automated redaction at ingest
  • Regional data residency options

We do not currently hold SOC 2 or ISO 27001 certification. If your procurement process requires one, tell us early and we will discuss timelines rather than work around it.

Send us your security questionnaire

We would rather answer it before the pilot than during it. Send the document your security team uses and we will complete it and come back with anything we cannot meet.