Annual third-party audit of security, availability, and confidentiality controls.
CertifiedFull compliance with EU General Data Protection Regulation. Data processing agreements available.
CompliantCalifornia Consumer Privacy Act compliance. Consumer data rights fully supported.
CompliantHealthcare data handling capabilities with BAA available for healthcare deployments.
AvailableInformation security management aligned with ISO 27001 framework.
In progressPayment card data never stored. Billing handled by PCI-compliant payment processors.
CompliantAll customer data is encrypted at rest using AES-256 encryption, ensuring that stored information remains protected even in the event of unauthorized physical access to storage media.
Data in transit is secured using TLS 1.3, the latest transport layer security protocol, for all communications between clients, our API, and internal services.
AgenticEye offers data residency options across US, EU, and APAC regions. Customers can choose where their data is stored and processed to meet local regulatory requirements.
Automated data retention policies allow customers to configure how long event data, alerts, and video clips are stored. Data is automatically purged according to these policies.
We fully support the right to deletion. Customers can request complete removal of their data at any time, and we will process deletion requests within 30 days in accordance with applicable regulations.
AgenticEye is hosted on SOC 2 certified cloud infrastructure with multi-region redundancy and 99.99% uptime SLA. Our infrastructure providers maintain the highest levels of physical and logical security.
Network segmentation ensures that customer environments are fully isolated. Each tenant's data is logically separated with strict access controls preventing cross-tenant access.
All public-facing endpoints are protected by a Web Application Firewall (WAF) that filters and monitors HTTP traffic, blocking common attack vectors including SQL injection, XSS, and CSRF attacks.
Enterprise-grade DDoS mitigation is in place to absorb and deflect volumetric attacks, ensuring platform availability even under sustained attack conditions.
We conduct quarterly penetration testing through independent third-party security firms. Findings are remediated on a priority basis, and results are available to enterprise customers upon request.
AgenticEye is committed to building AI that is fair, transparent, and accountable. Our AI models undergo regular bias testing to ensure equitable performance across diverse populations, lighting conditions, and environments.
We do not perform facial recognition without explicit customer consent and configuration. Customers have full control over whether facial recognition features are enabled within their deployments.
Our platform includes built-in privacy masking capabilities that can automatically blur faces, license plates, and other personally identifiable information in video feeds before processing or storage.
Human-in-the-loop review options are available for all AI-generated alerts and decisions. Customers can configure confidence thresholds that require human verification before actions are taken.
We believe in transparent AI decision-making. Our platform provides explainability features that show why an alert was triggered, what the AI detected, and the confidence level of each determination.
For security questionnaires, SOC 2 reports, or DPA requests, contact [email protected].