Trust Services Criteria
SOC 2 Scope, Handled Video Surveillance
Surveillant is built on security controls mapped to all five SOC 2 Trust Services Criteria. We hold no SOC 2 attestation today and will not imply otherwise. Deploy video surveillance that strengthens your own SOC 2 compliance posture rather than creating new audit headaches.
Every Vendor Impacts Your SOC 2 Scope
When your organization undergoes SOC 2 audits, every third-party vendor that touches your data or infrastructure falls under scrutiny. Video surveillance systems that store footage in the cloud, process biometric data, or integrate with access control systems become part of your compliance boundary. If your surveillance vendor cannot demonstrate adequate controls, your own SOC 2 report suffers.
Most surveillance platforms were designed long before SOC 2 became a standard expectation for SaaS and technology companies. They lack the access controls, encryption standards, monitoring capabilities, and audit logging that SOC 2 Trust Services Criteria demand. This forces security teams to implement compensating controls or accept risk findings that complicate their audit reports.
The challenge multiplies at scale. Organizations managing surveillance across multiple offices, data centers, and co-location facilities need a platform that provides consistent compliance controls everywhere, not a patchwork of local recording systems with varying security postures.
Surveillance That Strengthens Your SOC 2
Surveillant operates on documented security controls, mapped across Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria. When your auditors review our platform as a subservice organization, they find comprehensive controls already in place, simplifying your own compliance narrative rather than complicating it.
Our architecture provides the technical controls SOC 2 auditors expect to see. All data is encrypted in transit and at rest. Access is governed by role-based permissions integrated with your identity provider. Every system action generates immutable audit logs. Availability is maintained through redundant infrastructure with documented disaster recovery procedures.
We hold no SOC 2 attestation and no ISO 27001 certificate today, and we will not imply otherwise. What we do provide is written control documentation, a subprocessor list and completed security questionnaires, giving your auditors the vendor documentation they need without protracted information-gathering exercises. Our compliance team works directly with your audit firm to address any complementary user entity control requirements efficiently.
Trust Services Controls
Controls Mapped to SOC 2 Trust Services Criteria
Every Surveillant capability is designed with SOC 2 requirements in mind, providing the technical controls your auditors need to see.
Security Controls
End-to-end encryption, network segmentation, intrusion detection, and vulnerability management protect your surveillance data against unauthorized access and system threats.
Availability Monitoring
Redundant cloud infrastructure with automated failover, uptime monitoring, and documented disaster recovery procedures ensure continuous surveillance availability for your operations.
Processing Integrity
Video processing pipelines include integrity verification at every stage. Tamper detection and checksums ensure footage has not been altered from capture through storage and retrieval.
Confidentiality Controls
AES-256 encryption at rest, TLS 1.3 in transit, and role-based access controls ensure video data confidentiality. Data classification and handling procedures protect sensitive footage throughout its lifecycle.
Privacy Safeguards
Configurable data retention, automated purge schedules, and privacy-aware processing ensure personal information captured in video footage is handled according to your privacy commitments.
Audit Documentation
Access our documented security controls, subprocessor list, and completed security questionnaires. We hold no SOC 2 attestation today and will not imply otherwise; our compliance team supports your audit process directly with your audit firm.
Audit Ready
Simplify Your SOC 2 Audit
Choosing a surveillance vendor with documented security controls eliminates compliance gaps and reduces the burden on your security team during audit preparation.
Controls mapped across all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
documented security controls across an extended period, not just at a point in time.
Availability commitments are agreed in writing during enterprise onboarding, supported by documented disaster recovery procedures that map to the availability criteria.
Every system action, user access, and configuration change is logged immutably for complete auditability and accountability.
Trust Services Criteria
Choose a Surveillance Vendor Your Auditors Trust
Deploy video surveillance that strengthens your compliance posture. Request our control documentation and start free today.