Trust Center

Security & compliance, stated plainly

This page describes the controls we actually operate today — not aspirations, and not badges we have not earned. If you are evaluating Surveillant for an enterprise deployment and need something that is not covered here, email [email protected] and we will answer directly.

Last updated: July 28, 2026

Certification status

SOC 2 Type II — audit in progress

We have not yet completed a SOC 2 Type II audit, so we do not claim to be SOC 2 certified. Our infrastructure is built against the SOC 2 Trust Services Criteria (security, availability, confidentiality) and we are working toward a Type II examination. When an audit report exists, we will publish the auditor, the report date, and the observation window here, and make the report available under NDA.

GDPR — ready, with a DPA available

GDPR is a regulation, not a certificate — no vendor can be "GDPR certified". We act as a data processor for the video and account data you send us, we will sign a Data Processing Agreement on request, we support data deletion and export on request, and we maintain the subprocessor list below. Request a DPA at [email protected].

Controls in place today

Encryption in transit

All traffic to surveillant.ai is served over TLS. HTTP requests are redirected to HTTPS and application URLs are generated as HTTPS only.

Encryption at rest

Stored video objects and database volumes are encrypted at rest by the underlying storage provider (AES-256).

Credential handling

Account passwords are stored as salted bcrypt hashes and are never recoverable in plaintext — not by us, and not by support.

Access control

Role-based access control scopes what each user can see. Enterprise plans add SSO/SAML. Sessions are cookie-signed and expire.

Production access

Production access is limited to the engineers who operate the service, over key-based SSH. There is no shared production login.

Backups

Databases are backed up on an automated schedule with point-in-time recovery from the managed database provider.

Audit logging

Authentication events, clip access and sharing, and configuration changes are recorded and retained for review.

Tenant isolation

Every record is scoped to an owning account at the query layer; footage from one account is never served to another.

Subprocessors

Third parties that may process customer data on our behalf. We will notify customers under an active DPA before adding a new subprocessor.

Provider Purpose Data
Cloudflare CDN, DNS, TLS termination, DDoS protection Request metadata, IP addresses
Application hosting provider Compute and managed database for the application Account data, video metadata, footage
Object storage provider Encrypted storage of uploaded and recorded video Video objects
Stripe Payment processing and subscription billing Billing contact and payment details (card data never touches our servers)
Email delivery provider Transactional email: alerts, verification, notifications Email address, alert contents
AI model provider Video analytics inference on submitted frames/clips Frames or clips submitted for analysis

Need the named legal entity and hosting region for each provider for your vendor review? Email [email protected] and we will send the full list.

Your data

How long do you keep footage?

Retention is configurable per account. When a retention window expires, or when you delete a clip, the object is removed from active storage and drops out of backups as those backups age out.

Can I get my data deleted?

Yes. Delete your account from settings, or email [email protected] to request full erasure. We confirm deletion in writing and act within 30 days, as GDPR requires.

Can I export my data?

Yes. Clips and analysis results can be exported from the dashboard; contact us for a bulk export.

Do you train AI models on my footage?

No. Your footage is analyzed to produce your results. We do not use customer video to train models.

Where is my data stored?

Data residency options are available on Enterprise plans. Tell us the region your policy requires and we will confirm in writing before you sign.

Reporting a vulnerability

If you believe you have found a security issue, email us with the details and steps to reproduce. We will acknowledge within two business days and keep you updated until it is resolved. We will not pursue legal action against researchers who report in good faith and do not access other customers' data.

[email protected]