Security & data handling

Customer video does not leave the box. By default and by design.

CHEQIT is built for environments where video can't be sent to a vendor cloud. The trust story is architectural: where the product runs, what crosses the perimeter, and what stays inside.

Data flows

What stays inside, and what crosses the perimeter.

Stays on-prem Camera streams, snapshot frames, baseline images, recording metadata, alert evidence (before/after/diff), and audit decision context — all stored inside the customer environment.
RTSP · Snapshots · Baselines · Evidence · Audit
Crosses perimeter (only when allowed) Online licence validation, signed update manifests, and minimal aggregated health telemetry — never customer footage. Air-gapped sites turn this off entirely.
Licence validate · Update manifests · Health pings
Never sent Camera frames, recordings, evidence images, customer data, identifiable scene content. CHEQIT's connected services are not video pipelines.
No video · No frames · No evidence egress

Deployment posture

Runs where you decide. Activates how you decide.

Hosting model

On-premisesSingle signed Linux bundle, deployed by systemd next to the recorder. No cloud processing of customer video.
Air-gappedOffline activation via signed key files. Updates delivered as signed bundles you transfer with normal media controls.
Hybrid restrictedOnline licence/update path can be tunnelled or proxied through your egress controls — CHEQIT accepts a configurable manager origin.

Authentication & access

Local accountsUsername + password with bcrypt hashing and minimum length policy enforced server-side.
Optional MFATOTP/email-based MFA challenge on sign-in for accounts that opt in.
Scoped RBACRead/write scopes by site, group, camera, tag, alert type, and action. Decisions emit auditable context.
Enterprise IdP (post-MVP)OIDC, AD/LDAP, SAML are scaffolded; full enterprise verification is deliberately deferred to post-MVP and not claimed complete.

Release integrity

Signed bundlesLinux releases ship with SHA-256 checksums, detached signatures, and a published release public key.
Verifiable manifestsThe download manifest exposes version, channel, release date, build commit, restart flags, and migration notes.
Rollback disciplineUpdate workflows include dry-run and rollback paths. Customers control when each site updates.

Audit & governance

Audit eventsConfiguration, alert policy, scope, activation, and operator decisions are recorded with structured payloads.
Tamper-evident chainOptional HMAC-anchored audit chain — set once, validated continuously, exposed for compliance review.
Evidence retentionPer-camera retention defaults with per-site overrides; export bundles require explicit operator action.

Where we are honest

Compliance trajectory — what we have, what's coming.

We don't claim compliance certifications we don't hold. The current foundation is architectural; formal certifications follow as the product enters general availability.

Today (limited release)

Architectural postureOn-prem deployment, no video egress, signed releases, offline activation, scoped RBAC, optional tamper-evident audit.
Operational disciplineRegression-gated delivery with proof-gate artifacts on every release.
Honest scope notesXProtect / AD / LDAP / SAML full enterprise integrations are explicitly deferred to post-MVP.

On the roadmap

SOC 2 Type IITargeted post-GA. Architecture and controls are aligned; formal audit will follow.
ISO 27001Process and policy framework being built alongside the product.
Regional residency & compliance regimesDriven by customer demand — UK GDPR, EU GDPR, sector-specific frameworks.