Security & Data Privacy
Security Operations Software & Data Privacy
Protect the data behind every DeepX deployment, across DXHub, computer vision, AI agents, and CAMBOX PRO® devices. You decide where data is processed, how long it lives, and who can reach it.

Privacy by design
Privacy controls are built into every product, from capture through to deletion.
Data minimization
Work from derived events across video, documents, sensors, holding less data.
Your control
You decide where data is processed, how long it lives, and who sees it.
One way we minimize data
Edge Processing Reduces Exposure
Keep raw data close to its source and there is less to lose. Where you deploy CAMBOX PRO® devices, detection runs on the device and only event metadata and flagged segments travel onward over encrypted channels.
The same minimization holds across cloud and on-premise deployments of DXHub, so every product captures and keeps less by default. It also works in remote, low-connectivity sites, recording locally and syncing results when a link returns.


Security built into every layer
Privacy By Design
Build privacy into the architecture, and most rollout objections disappear. Many use cases never need identity at all, including occupancy counting, vehicle counting, and PPE detection.
Designing these to detect events rather than recognise individuals keeps monitoring proportionate. DeepX also separates raw footage from derived data, which makes least-privilege access easier to enforce and prove.
Process less, protect more
Non-Identifiable Processing
Favour processing that does not single out individuals. The platform turns video into counts, events, and short clips tied to a detection.
For model development, DeepX uses synthetic data generation, training detection on artificial scenes instead of real footage of real people. Masking and redaction limit identifiable detail in stored and shared outputs.

Data Security and Access
Govern every feed and record so the right people get in and everyone else stays out.
Tenant segregation
DeepX isolates identity, policy, and data boundaries across separate tenants.
Access roles
Encrypt stored and transmitted data, with customer-managed keys available to you.
Tenant segregation
Restrict every feed through role-based access control and two-factor authentication.
Audit trails
Log every access and search event in immutable, reviewable audit records.
Threat detection
Monitor suspicious access patterns and security events in real-time.
Deployment resilience
Run on-premise, in your VPC, at the edge, or fully air-gapped.
Security operations software
Anomaly Detection For Security
Detection matters only when it surfaces the clip that counts. DXHub runs real-time anomaly detection across monitored environments, applying machine learning to motion, objects, and behaviour.
Anomaly detection algorithms tuned to each site mean fewer false alerts. When an anomaly is detected, DXHub creates a time-stamped event with an evidence clip and routes it into your VMS or SIEM through APIs, with human review kept in the loop.
Restricted-area entry
Flag access to zones that should stay clear.
Wrong-way vehicles
Catch movement against the expected flow.
Unattended objects
Surface items left where they should not be.
How We Process Data
Handle customer data against a clear set of principles that a procurement reviewer can map directly to GDPR.
Lawful basis
Process data on a clear lawful basis such as site safety.
Purpose limit
Keep monitoring tied to defined goals like intrusion and PPE alerts.
Data minimization
Capture only what each use case needs, favouring events over footage.
Model accuracy
Tune models to each site and let teams validate and correct detections.
Storage limit
Hold data for configurable windows and delete it once no longer needed.
Data confidentiality
Protect data with encryption, access roles, and audit trails throughout.
Accountability
Non-Identifiable Processing
DeepX helps organizations meet major data protection and security requirements, including GDPR, SOC 2, and HIPAA. Our platform supports compliance through access control, encryption, audit logging, and configurable data retention. Your footage is never used to train models without your agreement, and consent and access events are logged for review.
GDPR
SOC 2
HIPAA
Talk to us before your security review
Tell us about your site, your data rules, and your security review, and we will show you exactly where data is processed, what leaves the site, and who can reach it.
Frequently Asked Questions
Where is my data processed, and what leaves the site?
Processing happens where you choose, including on the device at the edge with CAMBOX PRO®, inside your own cloud or VPC, or fully on-premise. Where edge processing runs, detection happens on the device and only event metadata and flagged segments travel onward, so far less raw footage ever leaves your environment. This data minimization sits at the core of how our artificial intelligence security system is built, which keeps exposure low by default.
How does the anomaly detection work?
DXHub runs real-time anomaly detection across your monitored environments, applying machine learning to motion, objects, and behaviour. The anomaly detection algorithms are tuned to each site so that detecting anomalies produces fewer false alerts and less noise for your operators. When an anomaly is detected, the anomaly detection software creates a time-stamped event with an evidence clip and routes it into your VMS or SIEM through APIs. Human review stays in the loop, so the anomaly detection system informs decisions rather than acting on its own.
Can individuals be identified in the footage?
Many use cases never need identity at all, including occupancy counting, vehicle counting, and PPE detection, and we design these to detect events rather than recognise people. Where a deployment allows it, the platform works from counts, events, and short clips tied to a detection, and policy-based masking limits identifiable detail in stored and shared outputs. For model development we rely on synthetic data generation, training detection on artificial scenes instead of real footage of real people.
Where is our data stored and processed?
Processing happens where you choose, including on-premise, inside your VPC, or in a regional cloud, so data stays within the boundary you set. Running detection at the edge keeps most footage on site, which means far less data moves anywhere at all.
How is our data encrypted?
Encryption protects data both in transit and at rest, and customer-managed keys keep authority over that data with you. Tenant segregation keeps one customer environment fully separate from another across the platform.
Who can access our footage and records?
Access runs through cloud security access control, so every feed and record is governed by role-based access control and two-factor authentication. Immutable audit trails log each access and search event, which lets you show who opened a feed, when, and why. People reach only what their role allows, down to the individual user.
How long do you keep our data?
Hold data only for as long as each use case requires, then delete it on a defined schedule once it is no longer needed. Retention windows are configurable per deployment, so you can match your own data rules and obligations.
