Last updated September 2026 · Draft
To be direct: Camera Engine has not obtained any formal third-party compliance certification (e.g. SOC 2, ISO 27001) at this time. If your organization requires a certified compliance posture as a condition of purchase, please tell us — it's useful signal for what to prioritize, and we'd rather say so now than imply otherwise.
Every vendor's customers, cameras, API keys, and usage data are scoped to that vendor alone at the application level. Cross-tenant access is checked on every request, not assumed from context.
We collect what's needed to operate the Service — see the Privacy Policy for the specific fields. Camera RTSP credentials are encrypted at rest. By default the Service is live-view only and stores no footage; a vendor may opt a camera into short motion-triggered clips or opt-in face-count detection, both off unless explicitly enabled and both auto-deleted after 7 days.
Data is currently hosted on infrastructure located at hosting region — to be specified. If a specific data residency requirement applies to your organization, let us know before onboarding.
Backups are retained 14 days on a rolling basis. Deleted records are soft-deleted before permanent removal, to guard against accidental loss. Vendors can request full deletion of their data — contact us to initiate that process.
The Service runs on standard hosting/infrastructure providers necessary to operate it. A full sub-processor list is available on request while this page is still in draft.
Compliance questions can be sent to info@zennialhub.in.