The physical-world data, in depth.
This is the part of Performance Hub that handles the most sensitive data an organisation can hold: video of its people, analytics about their movement, and, where enabled, facial recognition. It deserves the most detailed treatment on this Trust Centre. The guiding principle is the same as the rest of the platform: video is processed at your facility; the cloud stores, serves and manages. Identification is a separate, opt-in activity with its own controls, and lawful operation is in your hands.
Roles.
Video surveillance (VSaaS): how footage is handled.
Capture and processing on site. An Edge Processor appliance at your facility ingests your existing IP cameras over the local network, records around the clock, and runs on-device AI. Cameras talk only to the Edge Processor; they never need internet access and never expose ports to the world.
- Standard camera video is recorded as-is, at full native resolution and frame rate, with no generational quality loss.
- Recording happens on the appliance first; clips are written locally as they happen, then uploaded, so a cloud interruption never causes a gap in recording.
- Recording modes are per camera: motion-triggered (default) or continuous, and can be disabled per camera while live view keeps working.
Storage in your chosen region. Finished recordings are uploaded, encrypted, to cloud object storage in the region you choose for that facility, after a transient local buffer. If the appliance is stolen or destroyed, you lose at most the recent footage still queued for upload.
Live view does not round-trip through the cloud. Your browser negotiates a direct, encrypted peer-to-peer stream with the appliance, with an encrypted fallback. Live video is not stored in or served from cloud storage.
Search and analysis happen on-device wherever possible. Capabilities such as natural-language video search and object detection run on the Edge Processor itself. Only the resulting vectors (compact mathematical representations, not video) are stored in the cloud region you choose, so you can search your footage without the footage leaving your control.
Who can access footage.
Access is layered and audited:
- The module must be enabled for the facility; the user must be assigned to that facility; and footage is available to management-level roles (facility managers and administrators), not standard end-user accounts.
- Per-facility isolation. Cameras and footage never blend across facilities. A user assigned to three of an organisation's ten facilities sees exactly those three.
- Guest sharing is via time-limited, unguessable-URL links scoped to Timeline, Live View or Recordings, with a mandatory expiry (default six hours). Guest sessions end everywhere when the link expires. Guests structurally cannot see any people or AI data, retain footage, change settings, or reach other parts of Performance Hub.
- Audit. The module keeps Access Logs of all viewing sessions, staff and guest alike, plus a Share History of every guest link created. You always have an answer to "who has seen this footage?". Door unlocks from Live View require a stated reason and are logged.
- Programmatic access (API/MCP) can never see more than its owner could in the UI, and video streams themselves are not exposed over MCP.
AI Vision / people analytics.
AI Vision adds an intelligence layer on top of your cameras: people counting, dwell time, zone activity, heatmaps and visit patterns.
- Person detection runs on the Edge Processor at your site, and is opt-in per camera via a People Tracking setting. You choose deliberately where people intelligence adds value and skip it where it does not.
- Facial recognition also runs on the Edge Processor. Face detection, tracking and identification are performed on-device; the same architecture can overflow to the cloud for heavier analysis, but recognition does not depend on sending your video to a third-party recognition service.
- Unidentified people are pseudonymous by default. They are tracked as "shadow profiles" shown as an anonymous identifier, with no name unless linked to an identified profile.
- AI-estimated attributes (age range, gender, ethnicity, eyewear, emotion) are statistical estimates from imagery, not facts. They are used for aggregate analytics and are never used to grant or deny anything. Access-zone rules match access rights, types and tags, not estimated attributes.
- Graceful degradation. Without reference photos, people appear as unidentified visitors and the aggregate analytics (zone activity, sentiment, demographics) still function.
- Additional detection classes are in development. Alongside people, detection of other object classes - for example vehicles, number plates (ALPR) and animals - is on the roadmap. These extend the same on-device detection model and will carry the same access controls and residency.
- Audio, where enabled. Audio from cameras or networked microphones can be made available to your agent for analysis and reporting (for example building summaries and reports). It is opt-in and governed by the same access controls and storage-region choices as the rest of your footage data.
- Data minimisation. Optional contact fields are only stored when you enable them, and turning a field off removes its stored values.
Facial recognition controls.
Facial recognition is an opt-in capability within people analytics, with its own controls separate from recording.
Recognition runs on your Edge Processor. Face detection, tracking and identification are performed on the appliance at your facility, not by sending your video to a third-party recognition service. Heavier analysis may overflow to the cloud where supported; biometric matching is done on-device wherever possible.
What is stored. Recognition uses mathematical face templates, held in isolated collections for identified people, unidentified visitors (shadow profiles), and a blacklist. Face imagery (detection crops, profile photos, shadow photos) is stored under your facility's own storage prefix, in the same region as your footage.
Per-facility isolation by default. Facial collections are isolated per facility by default. Organisations may enable cross-facility access to facial collections for multi-site deployments under their policy.
Matching and review. Matching uses operator-tunable thresholds, quality gates, and optional visit-assisted signals. Suggested links from unidentified to identified profiles go to a human review queue; rejections require a recorded reason.
Blacklist means suppression, not alerting. Blacklisting a face stops it being seen at all; it does not notify anyone when the face is seen. This is the documented mechanism for honouring an opt-out, and it also manages device load - a persistent lifelike but non-person detection (for example a mannequin) can be blacklisted so it is never sent to recognition or churned as a repeat profile.
What it is used for. People identification on a timeline, visit patterns, tailgating and credential-sharing flags, access-zone violations (which flag and report but do not lock doors), and aggregate reports. Estimated attributes are never used to grant or deny access.
What is not exposed. Biometric references and face imagery are not exposed over the API or MCP; tools return metadata and profile data, not the face collections. Write operations on people (identify, merge, blacklist, delete) are human-confirmed UI workflows, by design.
Retention and deletion of video, vision and face data.
Video and AI metadata have separate, organisation-configurable retention policies:
| Category | Options | Default |
|---|---|---|
| Recordings | 1 week / 1 / 3 / 6 / 12 / 24 months | 1 month |
| Timelapse | 6 months / 1 / 2 years / Forever | 6 months |
| AI metadata (detections, timeline, imagery) | 1-5 years / Forever | 24 months |
- Retention deletion is automatic and permanent; it does not rely on anyone remembering.
- Individual clips can be retained indefinitely (exempt from auto-deletion), and each retained clip carries a name, written notes and an actor, which is exactly the paper trail a privacy inquiry asks for.
- Three deletion levels for people data: delete an unidentified person (removes the shadow profile, face references, detection records and imagery); permanently remove an identified person and all associated data; and time-based retention cleanup. Deletion is permanent and cannot be undone.
- Right-to-be-forgotten caveat. If a person still exists in your source system of record, a future sync can recreate their profile. A genuine deletion request must be actioned in the source system too, then here.
Lawful operation is in your hands.
Performance Hub gives you the controls; lawful operation is your responsibility as the operator. In practice that means:
- Signage disclosing camera surveillance and facial-recognition/analytics use.
- A privacy policy and a lawful basis (typically consent gathered when access rights are issued for identified people), with consideration for visitors and other non-registered individuals.
- Data minimisation, honouring deletion requests, restricting access, and periodic review of the blacklist and review queue.
Regimes such as GDPR, US state privacy and biometric laws (for example Illinois' BIPA) and the Australian Privacy Act are directly relevant to these features. We provide the controls to operate within them; the obligations are yours.