Trust Center
Security & compliance, stated plainly
This page describes the controls we actually operate today — not aspirations, and not badges we have not earned. If you are evaluating Surveillant for an enterprise deployment and need something that is not covered here, email [email protected] and we will answer directly.
Last updated: July 28, 2026
Certification status
SOC 2 Type II — audit in progress
We have not yet completed a SOC 2 Type II audit, so we do not claim to be SOC 2 certified. Our infrastructure is built against the SOC 2 Trust Services Criteria (security, availability, confidentiality) and we are working toward a Type II examination. When an audit report exists, we will publish the auditor, the report date, and the observation window here, and make the report available under NDA.
GDPR — ready, with a DPA available
GDPR is a regulation, not a certificate — no vendor can be "GDPR certified". We act as a data processor for the video and account data you send us, we will sign a Data Processing Agreement on request, we support data deletion and export on request, and we maintain the subprocessor list below. Request a DPA at [email protected].
Controls in place today
Encryption in transit
All traffic to surveillant.ai is served over TLS. HTTP requests are redirected to HTTPS and application URLs are generated as HTTPS only.
Encryption at rest
Stored video objects and database volumes are encrypted at rest by the underlying storage provider (AES-256).
Credential handling
Account passwords are stored as salted bcrypt hashes and are never recoverable in plaintext — not by us, and not by support.
Access control
Role-based access control scopes what each user can see. Enterprise plans add SSO/SAML. Sessions are cookie-signed and expire.
Production access
Production access is limited to the engineers who operate the service, over key-based SSH. There is no shared production login.
Backups
Databases are backed up on an automated schedule with point-in-time recovery from the managed database provider.
Audit logging
Authentication events, clip access and sharing, and configuration changes are recorded and retained for review.
Tenant isolation
Every record is scoped to an owning account at the query layer; footage from one account is never served to another.
Subprocessors
Third parties that may process customer data on our behalf. We will notify customers under an active DPA before adding a new subprocessor.
| Provider | Purpose | Data |
|---|---|---|
| Cloudflare | CDN, DNS, TLS termination, DDoS protection | Request metadata, IP addresses |
| Application hosting provider | Compute and managed database for the application | Account data, video metadata, footage |
| Object storage provider | Encrypted storage of uploaded and recorded video | Video objects |
| Stripe | Payment processing and subscription billing | Billing contact and payment details (card data never touches our servers) |
| Email delivery provider | Transactional email: alerts, verification, notifications | Email address, alert contents |
| AI model provider | Video analytics inference on submitted frames/clips | Frames or clips submitted for analysis |
Need the named legal entity and hosting region for each provider for your vendor review? Email [email protected] and we will send the full list.
Your data
How long do you keep footage?
Retention is configurable per account. When a retention window expires, or when you delete a clip, the object is removed from active storage and drops out of backups as those backups age out.
Can I get my data deleted?
Yes. Delete your account from settings, or email [email protected] to request full erasure. We confirm deletion in writing and act within 30 days, as GDPR requires.
Can I export my data?
Yes. Clips and analysis results can be exported from the dashboard; contact us for a bulk export.
Do you train AI models on my footage?
No. Your footage is analyzed to produce your results. We do not use customer video to train models.
Where is my data stored?
Data residency options are available on Enterprise plans. Tell us the region your policy requires and we will confirm in writing before you sign.
Reporting a vulnerability
If you believe you have found a security issue, email us with the details and steps to reproduce. We will acknowledge within two business days and keep you updated until it is resolved. We will not pursue legal action against researchers who report in good faith and do not access other customers' data.
[email protected]