Security at AgenticEye
Your data security is not just a feature — it's our foundation.
AgenticEye processes sensitive camera feeds and operational data across critical industries. We understand the responsibility this carries. Our security infrastructure is designed to exceed industry standards, ensuring your data remains protected at every layer.
🔒
AES-256 encryption
All data encrypted at rest using AES-256 standard
🛡️
TLS 1.3
All data in transit secured with latest TLS protocol
✅
SOC 2 Type II
Audited compliance with SOC 2 security framework
🔐
Zero trust
Role-based access with multi-factor authentication
Infrastructure security
Cloud architecture
AgenticEye is hosted on enterprise-grade cloud infrastructure with:
- Multi-region deployment for redundancy and disaster recovery
- Auto-scaling infrastructure that adapts to demand without performance degradation
- Network segmentation with strict firewall rules and private subnets
- DDoS protection with automatic mitigation at the network edge
- 99.9% uptime SLA for enterprise deployments
Data isolation
Each customer's data is logically isolated within our platform. Camera feeds, event data, alerts, and reports are siloed per account with strict access controls. No customer can access another customer's data under any circumstances.
Application security
Secure development
- Secure SDLC: Security is integrated into every stage of our development lifecycle
- Code reviews: All code changes undergo mandatory peer review with security focus
- Static analysis: Automated SAST tools scan for vulnerabilities before deployment
- Dependency scanning: Continuous monitoring of third-party libraries for known CVEs
- Penetration testing: Regular third-party penetration tests conducted quarterly
Authentication & access control
- Multi-factor authentication (MFA) available for all accounts, required for admin roles
- Single Sign-On (SSO) via SAML 2.0 and OpenID Connect for enterprise customers
- Role-based access control (RBAC) with granular permission levels
- Session management with automatic timeout and concurrent session controls
- API key rotation and scoped access tokens for integrations
Camera feed security
We treat camera feed data with the highest level of sensitivity:
- Encrypted streams: All camera feeds are encrypted during transmission to our platform
- No permanent raw storage: Raw video feeds are processed in real-time and not stored unless explicitly configured by the customer
- Event-only retention: Only flagged events and alerts are retained, according to your subscription tier
- Customer-controlled deletion: You can delete any event data at any time through the platform
- On-premise option: Enterprise customers can deploy AgenticEye on their own infrastructure for maximum data control
Compliance
- SOC 2 Type II: Annual audit demonstrating security, availability, and confidentiality controls
- GDPR: Full compliance with EU General Data Protection Regulation, including data processing agreements and privacy impact assessments
- CCPA: Compliance with California Consumer Privacy Act requirements
- HIPAA: Available for healthcare-adjacent deployments under Business Associate Agreements
- ISO 27001: Information security management system aligned with ISO 27001 standards
Incident response
Our incident response program includes:
- 24/7 monitoring: Security operations center continuously monitors for threats and anomalies
- Incident classification: Structured severity levels with defined response times (P1: 15 min, P2: 1 hour, P3: 4 hours)
- Customer notification: Affected customers are notified within 72 hours of confirmed data incidents, in compliance with GDPR and applicable regulations
- Post-incident review: Root cause analysis and remediation plans published for all significant incidents
Vulnerability disclosure
We welcome responsible security research. If you discover a vulnerability in AgenticEye, please report it to [email protected]. We commit to:
- Acknowledging receipt within 24 hours
- Providing an initial assessment within 5 business days
- Working with you to understand and resolve the issue
- Not pursuing legal action against good-faith security researchers
Employee security
- Background checks for all employees with access to production systems
- Mandatory security awareness training (onboarding + annual refresher)
- Principle of least privilege for all internal access
- Endpoint security with device management and encryption on all company devices
Questions?
For security inquiries, audits, or to request our SOC 2 report, contact our security team: