Security and privacy
Enterprise-grade security, designed specifically for the most sensitive environment imaginable: a room full of children.
Data minimisation
Only privacy-filtered video is transmitted; raw footage never leaves the edge device.
No facial recognition database is maintained. Identity matching uses privacy-preserving embeddings.
Parental access data is limited to their own child's filtered feed only.
Metadata is stripped from all transmitted frames. No location, device, or network data is attached.
Biometric enrolment data is stored on-device only and cannot be exported.
Storage & retention
On-site encrypted storage with a strict 48-hour rolling buffer.
AES-256 encryption at rest with hardware-managed keys.
Automatic cryptographic erasure after the retention window.
No cloud backup, no archive, no remote storage of any footage.
Encryption keys rotate every 24 hours via the hardware security module.
Access controls
Multi-factor authentication required for all parent and nursery accounts.
Role-based access: managers, staff, and parents each have distinct permission levels.
Per-session token rotation prevents replay attacks.
Session timeouts automatically end feed access after inactivity.
All account actions are logged with full attribution.
Incident response
Automated alerting for hardware tamper detection and anomalous access patterns.
Defined escalation procedures for data breach scenarios.
48-hour incident disclosure commitment to affected parties.
On-device audit logs are tamper-proof and preserved separately from video data.
Regular penetration testing and third-party security audits.
What we don't do
Clarity about what we explicitly do not do is just as important as what we do.
No cloud CCTV
We do not operate a cloud-based CCTV service. All video processing and storage is on-premise.
No facial databases
We do not build, maintain, or sell facial recognition databases. Identity matching is local and ephemeral.
No remote access to raw feeds
Nobody, including our own team, can access unmasked video remotely. Raw footage stays on the edge device.
No data monetisation
We do not sell, share, or monetise any data collected by the system. Full stop.
Architecture summary
Edge Computing
On-premise AI inference
Encryption
AES-256 + TLS 1.3
Retention
48-hour auto-delete