Camera Engine
Back to home
Draft — pending legal review. Everything below reflects what's actually implemented today, kept deliberately current rather than aspirational. It has not yet been reviewed by counsel as a formal representation.

Security

Last updated September 2026 · Draft

We'd rather tell you exactly what's true today than make broad claims. This page lists what's actually implemented, and is equally explicit about what isn't yet.

In place today

  • Encrypted camera credentials. RTSP usernames and passwords are encrypted at the field level (AES-256-GCM) before storage and are never returned by any API response.
  • Hashed API keys. API keys are shown once at creation and stored only as a SHA-256 hash — we cannot retrieve a lost key, only reissue one.
  • Hashed passwords. Admin, vendor-portal, and customer passwords are hashed with bcrypt; plaintext passwords are never stored.
  • Tenant isolation. Every vendor-scoped request is checked against that vendor's own data. Cross-tenant access attempts return a not-found response rather than a permission error, so a compromised key can't even confirm another vendor's data exists.
  • Rate limiting. Login and signup endpoints are throttled to reduce brute-force and abuse risk.
  • Nightly encrypted-at-rest backups, retained on a 14-day rolling basis, with periodic restore verification.
  • Per-request session checks. A suspended account loses access on its very next request, not just when its session token naturally expires.
  • Security headers applied to all responses (via Helmet).

Not in place yet — stated plainly

  • HTTPS/TLS. This deployment currently runs on HTTP while a domain name and TLS certificate are being finalized. Until that's live, traffic to this specific deployment is not encrypted in transit. We treat this as a priority, not an afterthought.
  • No formal third-party security audit or penetration test has been conducted yet.
  • No high-availability / failover infrastructure — the Service currently runs on a single server.
  • No automated external alerting is active yet. The capability exists (an uptime webhook that can notify Slack/Discord/etc. on status changes) but is not yet configured for this deployment.

Reporting a security issue

If you believe you've found a security issue, please email info@zennialhub.in with details. We'll acknowledge reports and work to address confirmed issues promptly.

Terms of Service Privacy Policy Security Data Compliance API Docs