Security
There is no person in the record.
The design is the evidence. It is published and you do not have to trust us to read it.
We do not read plates and we do not read faces. The product has no recognition system. So there is no gallery, no watch list, no reverse lookup to steal. Imagery is a layer you can buy. Imagery of a public street has people in it. So we control it with access, logs and contracts. We do not call it anonymous.
Fig 01
Where the data sits and who can reach it
The pylon
Tracking runs here
The platform
Filed by place and time
The buyer
A limited export
- Out of the pylonCommitmentThe record the pylon made, and where that record came from. No data can be sent into a pylon.
- In storageTodayNever filed under an object. So there is no index from an object back to its records.
- Out to a buyerTodayA shape on a map, a time window, a stated reason. No one can ask it about a person.
- Internal accessCommitmentNo one here has access all the time. Emergency access expires. It shows in the customer's own log.
| Document | State |
|---|---|
| Control register | +Published |
| Compliance posture | +Published |
| Sub-processor list | +Published |
| Transparency log | +Published |
| Accessibility statement | +Published |
| Vulnerability policy | +Published |
| Data access policy | +On request, under NDA |
| Architecture description | +On request, under NDA |
| Control mapping | –Not written |
| Incident response plan | –Not written |
| Security questionnaire | –Not written |
| SOC 2 report | –None, no auditor engaged |
| Penetration test | –None, not commissioned |
03 / Scope
Three things get called security here
Abuse of the platform
A stolen account, a fake request, a bad export, someone on the inside. All tagged on the register.
A customer checking a claim
A product, not a control. It is on verification.
Police buying data
Normal terms. Two people sign off. Every request is published. On requests.