AtomVision Security & Compliance

    Video can stay on the edge box. Optional cloud storage uses encryption, access controls, and regional residency choices. Compliance documents are available for review.

    Encryption

    • AES-256-GCM encryption at rest
    • TLS 1.3 encryption in transit
    • End-to-end encrypted video streams
    • Automatic key rotation

    Compliance & Certifications

    • SOC 2 Type II reports on request
    • GDPR-ready with EU data residency
    • HIPAA-ready architecture (technical controls provided, BAA process required)
    • Hardware documentation on request
    • Data residency options: US, EU, Asia-Pacific

    Access Controls

    • Role-based access control (RBAC)
    • SAML 2.0 SSO (Okta, Azure AD, OneLogin)
    • Multi-factor authentication
    • IP allowlisting and per-site permissions
    • Complete audit logs of all access

    Infrastructure

    • AWS-powered with multi-region redundancy
    • Automated backups, DDoS protection
    • Regular third-party penetration testing

    Contact AtomVision for a security review or compliance documentation.

    Enterprise Security

    How video is protected,
    on the box and in the cloud

    AES-256-GCM at rest, TLS 1.3 in transit, role-based access, and residency options when you use the optional cloud. SOC 2 Type II reports are available for review.

    atomvision.app · Settings · Security
    AES-256-GCM · TLS 1.3
    Audit log
    Last 90 days · 12,418 events
    SOC 2 Type II · Tamper-evident · Streamed to your SIEM
    Identity
    Ok
    Okta · acme.okta.com
    Connected
    Protocol
    SAML 2.0
    JIT provisioning
    SCIM v2
    Group → Role mapping
    • atomvision-adminsAdmin
    • security-opsOperator
    • store-managersViewer
    MFA enforced — all roles
    154 / 154 users

    Encryption at Every Layer

    From camera to cloud to viewer — your footage is encrypted at every step

    atomvision.app · Security · Encryption pipeline
    End-to-end · TLS 1.3 · AES-256-GCM
    Camera
    RTSP / ONVIF
    Adaptor
    TLS 1.3
    Cloud
    AES-256-GCM at rest
    Viewer
    Browser · Mobile
    Encrypted
    verified
    AES-256 Storage
    All video and metadata is encrypted with AES-256-GCM before it's written to disk. Keys are scoped per-organization and never shared across tenants.
    Modern TLS 1.3
    All connections use TLS 1.3 with perfect forward secrecy. Older protocol versions are disabled at the network layer.
    End-to-End Delivery
    Video streams are encrypted from the camera through the AI Edge Analytic Box to our servers, then re-encrypted for delivery to your browser. Your footage is never decrypted in transit.
    Managed Key Rotation
    Encryption keys are automatically rotated on a regular schedule. If a key is ever compromised, rotation limits exposure to a bounded window of time.

    Compliance & Certifications

    We do the hard work so your compliance team doesn't have to start from scratch

    atomvision.app · Security · Compliance
    Reports available on request
    On request
    SOC 2 Type II
    Type II reports covering security, availability, and confidentiality controls can be shared with your auditors on request
    DocPDF · Available on request
    Compliant
    GDPR-Ready
    Data processing agreements, right-to-erasure support, and EU data residency options
    DocPDF · Available on request
    Architecture Ready
    HIPAA-Ready
    HIPAA-ready architecture — we provide the technical controls, you provide the BAA process
    DocPDF · Available on request
    On request
    Hardware documentation
    We can share component documentation for procurement. We do not publish an NDAA badge on this page.
    DocPDF · Available on request
    US · EU · AP
    Data Residency Options
    Choose where your data lives: US, EU, or Asia-Pacific regions. Data never leaves your selected region
    DocPDF · Available on request

    Access Controls

    Control who sees what, from where, and track every action

    atomvision.app · Settings · Roles & Access
    SAML 2.0 · MFA enforced · IP allowlist
    Role permission matrix
    RoleLivePlaybackExportManageAudit
    Admin
    Operator
    Viewer
    Auditor
    Custom roles · per-site scoping · synced via SCIM 2.0
    Access controls in use
    • Role-Based Access Control
      Predefined roles (Admin, Operator, Viewer) plus custom roles with granular permissions. You decide who can view live feeds, export footage, or manage users.
    • SAML 2.0 SSO
      Integrate with Okta, Azure AD, OneLogin, or any SAML 2.0 provider. Users log in with their existing corporate credentials—no separate AtomVision password needed.
    • Multi-Factor Authentication
      Enforce MFA organization-wide via TOTP, authenticator push, or hardware security keys. MFA can be required for specific roles or all users.
    • IP Allowlisting
      Lock platform access to approved IP ranges—your office networks, VPN exit nodes, or specific locations. Any attempt from outside those ranges is rejected.
    • Per-Site Permissions
      Grant users access to specific sites or camera groups. A regional manager in one city doesn't need to see—or accidentally access—another region's footage.
    • Audit Logs
      Every login, live view, export, configuration change, and permission update is logged with timestamp and user identity. Exportable for compliance reviews.

    Infrastructure Security

    Enterprise-grade cloud infrastructure designed for reliability and resilience

    atomvision.app · Status · Infrastructure
    All systems operational
    AWS regions · multi-AZ
    • us-east-1
      Virginia
      38 msok
    • us-west-2
      Oregon
      64 msok
    • eu-west-1
      Ireland
      91 msok
    • eu-central-1
      Frankfurt
      88 msok
    • ap-southeast-1
      Singapore
      142 msok
    • ap-northeast-1
      Tokyo
      156 msok
    Defenses in depth
    • AWS Multi-Region
      Built on AWS with workloads distributed across multiple availability zones. Regional failover keeps the platform available even during localized outages.
    • Automated Backups
      Footage and configuration data are continuously backed up with point-in-time recovery. Retention policies are configurable per your compliance requirements.
    • DDoS Protection
      Always-on volumetric and application-layer DDoS mitigation. Traffic scrubbing happens before it reaches our application servers.
    • Penetration Testing
      We conduct annual third-party penetration tests and remediate findings on an accelerated timeline. Test summaries are available to enterprise customers on request.

    Audit & Transparency

    Full visibility into platform activity — because trust requires proof

    atomvision.app · Audit · Compliance export
    Tamper-evident · CSV / JSON
    audit-2026-05.csv · preview
    12,418 events · last 90 days · streaming to your SIEM
    • Detailed Activity Logs
      Every action is logged—who accessed what camera, when they viewed it, what they exported, and any configuration changes. Searchable and filterable for incident review.
    • Chain-of-Custody Exports
      Footage exports include tamper-evident metadata: hash verification, download timestamp, and exporting user identity. Suitable for evidence submission and legal proceedings.
    • Scheduled Compliance Reports
      Automated reports on access patterns, failed login attempts, and compliance posture—delivered on your schedule. Useful for quarterly security reviews and audits.

    Security FAQ

    Common questions about our security and compliance posture

    Where is my data stored?

    All footage is stored on AWS infrastructure with data residency options in the US, EU, and Asia-Pacific regions. You choose where your data lives, and it stays there. We never move your data across regions without explicit consent.

    How is footage encrypted?

    Footage is encrypted with AES-256-GCM at rest and TLS 1.3 in transit. Streams are end-to-end encrypted from your cameras through the AI Edge Analytic Box to our servers. Encryption keys are rotated automatically on a regular schedule.

    Do you support HIPAA?

    We provide HIPAA-ready architecture with all required technical controls — encryption, access controls, audit logging, and data segmentation. You bring the BAA process and your compliance team; we provide the infrastructure that passes the audit.

    Can I get compliance documentation?

    Yes. We provide SOC 2 Type II reports, penetration testing summaries, and data processing agreements upon request. Enterprise customers receive scheduled compliance reports and can request custom documentation for their audit cycles.

    Need a security review?

    Our security team is available to walk through our controls, share compliance documentation, and answer your team's questions.