Security
Your content never leaves.
On-premises and air-gapped operation with a no-egress architecture keeps content and traffic protected. Designed for environments where security and control are non-negotiable.
Security at a glance
No data egress
An architecture where content never crosses your network boundary.
Role-based access control
Operator, administrator, and auditor roles are separated and LDAP-linked.
Audit logs
Who changed what and when, recorded in immutable logs.
Encryption in transit and at rest
Standard encryption applied on both sides.
How it works
Controls at three layers: network, access, and data.
Network isolation
Air-gapped or DMZ placement. No outbound session is ever established.
Least privilege
Least-privilege roles with scoped API keys.
Data lifecycle
Retention periods are defined for intermediate artifacts, then they expire automatically.
Key specifications
Technical specifications
Security control items, adjustable to your organization's policy.
- Deployment mode
- Air-gapped · DMZ · VPC
- External communication
- Not required (on-premises)
- Inbound
- Port whitelist
- Transport encryption
- TLS 1.3
- Permission model
- RBAC
- Directory integration
- LDAP · Active Directory
- API authentication
- API key · OAuth 2.0
- Sessions
- Expiry and forced termination
- At-rest encryption
- AES-256
- Data residency
- Customer-designated location
- Audit logs
- Immutable, forwardable to external SIEM
- Log retention
- Policy-based (default 1 year)
Frequently asked questions
Anything not covered here, we answer in a technical meeting.
Do you hold security certifications such as ISO 27001?
We share current certification status during consultation. The product itself is designed around air-gapped operation and no data egress, and we provide the technical documentation and control checklists your certification audit requires.
Can we receive security review material?
Yes. We provide a review package including architecture diagrams, data flow diagrams, a control checklist, and our vulnerability response procedure. Request it when you contact us.
Can audit logs be forwarded to our existing SIEM?
Yes. Structured logs are sent over syslog or an HTTP endpoint, integrating with Splunk, ELK, and similar systems.
How do you respond when a vulnerability is found?
Response windows are tiered by severity, and patches are distributed accordingly. For air-gapped environments we deliver offline patch packages with an application procedure.
Your video infrastructure,
one level up.
Start with a single card and scale as needed. We design the demo, the rollout, and the technical review with you.