Data security
Your data stays yours.
Every deployment is designed around customer-controlled data, documented access, and a clear operating boundary.
Company-wide commitments
Standards for every product and system we deploy.
Customer-controlled architecture
The customer approves where operational data is stored and which systems may receive it. For data-sensitive deployments, we select only products and architectures that can satisfy the agreed customer-controlled or on-premises boundary.
Documented data flows
Before deployment, we document what data is collected, where it goes, who can access it, and which external services or subcontractors are involved.
Controlled access
Every proposed system must document how named users, roles, permissions, and administrator ownership work. Customer administrators retain control of accounts and permissions wherever the selected product supports that model.
Customer-set retention
Retention, export, and deletion requirements are agreed before product selection. A vendor default is not accepted when it conflicts with the customer’s documented boundary.
No secondary use
We document whether the product vendor, cloud provider, or support system has any right to use customer data. Products that permit sale or unapproved model training are not selected for the deployment. Diagnostic or support access is limited to the agreed purpose.
Permissioned support
Remote support connections and vendor dependencies are documented before deployment. Support access is customer-approved and time-bound where the selected architecture supports it.
Product selection
Security is a product-selection requirement.
If a product cannot satisfy the deployment's required data boundary, access model, retention controls, or support process, it is not offered for that use case. Every proposed system receives a product-specific data sheet before purchase.
| Data sheet item | What it covers |
|---|---|
| Data collected | What the system gathers in normal operation |
| Video and audio | What is captured, at what resolution, and where it is processed |
| Analytics and metadata | Event records, alert data, and operational analytics created by the system |
| Storage location | Local, edge, customer cloud, or vendor cloud |
| External connections | Drone telemetry, flight-control links, dock or cloud dependencies, license checks, and update traffic |
| Administrator ownership | Who controls accounts, roles, and permissions |
| User roles | How access is segmented between operators, admins, and support |
| Retention and deletion | How long data is kept and how it is removed |
| Remote support | Vendor firmware, update, diagnostic, and support connections |
| Incident escalation | How security events are reported and handled |
| Updates and backups | How the system is maintained and how data is protected during updates |
How data stays within the boundary.
A locally stored video stream may still create cloud alerts, telemetry, license checks, update traffic, or support connections. We document the full boundary, not just the storage location.
Customer-controlled data boundaryDiagram showing where operational data lives: local storage, edge compute, customer cloud, and which connections leave the boundary
Documented support accessDiagram showing how remote support connects to the system: customer-approved, time-bound, logged, and limited to the agreed purpose
Standards and certification
Requirements first. Equipment second.
We define the job's safety, data, training, aviation, accessibility, and equipment requirements first, then select and configure systems with the documentation to match.
SOC 2, ISO 27001, CJIS, PREA, UL, and similar certifications apply to specific companies, products, services, and scopes. We only reference a standard when the exact product and deployment scope support the statement.
Regulatory scope
We map each deployment to the applicable product, operator, site and mission requirements.
FCC
Applicable models are checked for the required FCC equipment authorization or supplier declaration.
FAA
UAS deployments are planned around applicable pilot, registration, Remote ID and airspace requirements.
OSHA
Site-specific safety planning is coordinated with applicable workplace requirements.
Regulatory requirements are product-, configuration-, operator-, location- and mission-specific. References do not imply agency endorsement or company-wide certification.
Define the data boundary before deployment.
Tell us about the system and the operating environment. We will document the data boundary and select products that fit it.
Find the robot that fits your site.
Free site assessment. We tell you what actually works before you spend a dollar.