Security & Trust

Security and privacy, by design

QORA watches the places that matter most — so how we handle your video and data is the product, not an afterthought. Here’s exactly how we protect it, in plain terms, including what we’ve built and what’s still on the roadmap. We won’t claim a certification we don’t hold.

Data protection

Access is scoped, encrypted in transit, and every action is on the record.

Encryption in transit

All API and console traffic runs over TLS/HTTPS. Camera streams to the cloud ride an encrypted transport (RTSPS).

Strict tenant isolation

Every request is authenticated and scoped to your organization at the gateway; one customer can never see or reach another’s cameras, incidents, or data.

Role-based access

Admins, managers, and operators get only what their role needs. Passwordless magic-link sign-in, a step-up PIN for sensitive actions, and per-integration scoped API keys.

Tamper-evident audit trail

Every meaningful action is written to an append-only audit log and exported to immutable storage — who did what, when.

Privacy by design

The most sensitive capabilities are off until you deliberately turn them on — and you can see, limit, and delete what’s collected.

Privacy Center

A read-only view (and PDF export) of what QORA collects for your sites and how it’s used — no digging required.

Facial recognition is off by default

It ships disabled, is gated behind explicit terms, and is enabled per-site only when you choose. Most sites never turn it on.

You control retention

Set a keep-N-days window per site; older snapshots are automatically deleted or archived. Keep only what you need.

Bring your own archive

Send retained evidence to your own S3 or R2 bucket — your data can live in storage you own and control.

Your cameras, your data, your call

No rip-and-replace, and no lock-in on where your video lives.

Cloud, on-prem edge, or hybrid

Run analysis in the cloud, on a local edge appliance that keeps video on your network, or a mix — your deployment, your choice.

Works with your existing cameras

Any ONVIF/RTSP camera. You don’t hand your footage to a new hardware vendor to use QORA.

Data minimization

We keep what’s needed to detect and review incidents — not a permanent copy of everything, unless you ask for it.

Human-in-the-loop by default

AI flags; people decide. QORA is built so it can’t take a high-stakes action on its own.

No auto-action on critical detections

A weapon detection never fires a response on its own — an operator must review the frame and confirm first. AI is an assistant, not the trigger.

Confirm-gated responses

Automated responses (a speaker warning, a relay, a webhook) can be floored to require a human confirmation before anything happens.

Verified-alarm evidence

A human video-verify produces a tamper-evident packet (frames + hashes + the AI & human verdict) for priority dispatch or a monitoring centre.

Compliance & disclosure

Where we are today — stated honestly. We’ll update this page as each item lands.

SOC 2 Type II In progress

We’re building toward a SOC 2 Type II examination. We do not claim certification yet — this line updates when the report is issued.

GDPR / CCPA-aligned Practiced

Data-minimization, retention limits, per-tenant deletion, and the Privacy Center support GDPR/CCPA-style data-subject workflows today.

Responsible disclosure Open

Found a vulnerability? Tell us and we’ll work it in good faith. See the security contact below.

Data Processing Agreement On request

Need a DPA or your security questionnaire completed for procurement? Reach out — we’ll turn it around.

We list capabilities we’ve actually shipped and roadmap items we’re actively working — never a badge we haven’t earned. If you need a specific control or attestation for procurement, ask and we’ll tell you exactly where it stands.

Security contact & responsible disclosure

Report a suspected vulnerability or a security concern to security@qoraguard.com. Please give us a reasonable window to investigate and remediate before public disclosure; we won’t pursue good-faith researchers.

For a DPA, a completed security questionnaire, or architecture detail for procurement, contact us.

Talk to us about security Start a 30-day pilot