TRUST — SECURITY

Security

VisionGuard runs on a computer inside your own building — not in a cloud account of ours. This page says, plainly, where what it sees is kept, who can use it, and the small number of things that ever leave the site.

Where it's kept

Camera footage, face data and attendance are stored in local files on the machine at your site. Search history — every track-a-person search and every question asked through Ask — is written down too, but today that record lives only in the server's memory, not in a file; more on that below. Nothing about your site is copied anywhere else by default — only the two exceptions later on this page ever leave.

Signing in

Every account signs in with an email and a password of at least 12 characters. Passwords are never stored as typed — they go through a slow, one-way hash built for exactly this, so a stolen database is not a stolen password list. A wrong password and an account that doesn't exist come back the same way, in the same time, so there's nothing for a stranger to learn by guessing.

Signing in issues a temporary pass rather than a permanent one: it can be cancelled immediately if a laptop is lost or someone leaves, and it expires automatically 12 hours after you sign in, whether or not it was used the whole time.

Two roles, decided by the server

Every account is either an administrator or IT — there is no third tier. Administrators can enrol people, add or edit cameras, manage accounts, remove a person and change settings. IT accounts can do the everyday work — watch cameras, run searches, clear an alert — but not that. Which one you are is decided by VisionGuard's own server, on every request, from your account; it is never taken from what a screen happens to show, so editing a browser changes nothing about what it lets you do. Anyone who can reach the console can sign up for their own account with no invitation needed, but it is always an IT account, never an administrator one — the first administrator, and any after it, is created by a command run on the machine itself, which nobody can reach over the network.

Every search is written down

A track-a-person search is logged before its result is shown, not after — so a search that finds nothing is still on the record. Knife-alert decisions, camera changes, alert-recipient changes and removing a person are all logged the same way: who did it, what they did, and when.

The plain limit today: that log lives in the server's memory, so restarting it clears the history. A fix that saves every entry for good, and lets an administrator remove a mistaken one only by typing a reason — leaving a permanent note that it happened — has been specified and is being prepared.

How long footage is kept

Recorded clips are deleted automatically after a set number of days — 30, by default. The video goes; the record that something happened — when, on which camera, who reviewed it — is kept. A restricted-area camera works a little differently: it keeps only its three most recent clips, for the same reason — proof, without keeping video forever.

Removing a person

Only an administrator can remove someone, and it's logged before it happens. Their face data and their entry in the directory are deleted at once — VisionGuard stops recognising them from the next camera frame, with no restart needed. Their past sightings stay in the system but are unreachable from any page. A way to erase those too has been decided on but is not yet built.

What leaves the site

Two things about what happens on your site leave it, and only two. Ask sends your typed question to Google's Gemini, after masking names and number plates on your own machine first — a name becomes a placeholder before anything is sent. Gemini's free tier is what's configured today, and its terms let Google use what's submitted and let a human reviewer read it; a paid plan would turn that off with no change to the product. A word VisionGuard doesn't recognise is sent exactly as typed, which can include a name if that's what was typed into the question.

Email alerts go out through Gmail, so Google's mail servers see the text — but the text carries facts only: what happened, where, when, how sure, and who decided. It never carries a name, a face or a picture.

The console's own connection

Today the console is reached over a plain connection on your site's own network — HTTPS for it has been planned but is not switched on yet. Until it is, treat that network the way you would any system holding this kind of data.

Reporting a problem

Found a security problem, or think you have one? Tell us directly: support@vision-guard.org, or call or WhatsApp +20 100 253 5081, Sunday to Thursday, 9:00–18:00.

Last updated 27 September 2026