Security & Compliance

Licensed, real-world. Not synthetic. Not scraped.

Compliance and data integrity aren’t features we added later — they are how the pipeline was designed from day one.

GDPR-alignedMulti-jurisdictionRights-clearedAudit trailPII anonymizationEncrypted at rest
01

Data sourcing legitimacy

Real-world captureNot scrapedNot synthetic

Every clip in our pipeline is captured through explicit, informed consent. We do not use synthetic generation, web scraping, or unlicensed footage. All data is original, real-world, and captured under a controlled protocol — so the provenance chain starts clean.

02

Global compliance framework

GDPR-alignedMulti-jurisdictionRights-cleared

Our data operations are designed for global use. Rights clearance is multi-jurisdiction — not tied to a single country's framework. GDPR principles are applied as a baseline: purpose limitation, data minimisation, subject rights. Customers deploying in regulated markets can request documentation.

03

Collector consent & data rights

Informed consentWithdrawal rightsData subject access

Collectors consent explicitly before any capture session. Consent covers the specific task type, use of the footage for AI training, and rights transfer. Collectors can withdraw consent and request deletion of their data. Personal data is separated from training data and handled under strict access controls.

04

Audit trail & provenance

Per-dataset provenanceChain of custodyInspection-ready

Every dataset includes a provenance record: capture date, environment category, collector consent reference, annotation pipeline version, and QA score. This record travels with the dataset and is inspection-ready. Customers can trace any clip back to its capture context without exposing collector identity.

05

Data storage & security

Encrypted at restEncrypted in transitCustomer isolation

Data is stored encrypted at rest and in transit. Access to raw capture data is role-restricted; customer datasets are isolated and not shared between customers. Infrastructure runs on AWS (eu-west-1) with CloudTrail audit logging and KMS key management.

06

PII & anonymization

Face maskingPlate redactionPII detection

Egocentric captures may incidentally capture bystander faces, licence plates, or other personal identifiers. Our pipeline applies automated detection and masking for faces and plates before any data leaves the annotation stage. Additional anonymization passes can be applied on request for sensitive deployment contexts.

Questions about compliance or data governance? We’re happy to share documentation and answer technical questions.