SentrixShield
Home Platform Solutions Pricing Trust Company Contact Book a scan
Home/Trust & privacy
Trust & privacy

A surveillance analytics company that refuses to identify anyone.

This page is the longest one on our site, and deliberately so. We are asking you to point cameras at your customers, your staff and — in some deployments — children. You are entitled to know precisely what happens to what those cameras see, in language you can hold us to.

No facial recognition

Not a setting. Not on request. Not for law enforcement. The capability does not exist in the product.

Video stays on site

Inference runs on an appliance inside your building. Frames do not traverse the internet by default.

Indian data residency

Event data is stored and processed in Indian data-centre regions. It does not leave the country.

Retention you control

30 days by default, 14 on education sites, configurable down to 24 hours. Deletion is real deletion.

The line, drawn precisely

What the system does and does not do

Vague privacy language is how companies keep options open. Here is the specific version.

It does

  • Detect that a person is present in a region, and count them
  • Track that person's path within a single visit to compute dwell and flow
  • Estimate a coarse age bracket and gender as an anonymous statistical aggregate, where the customer enables it
  • Recognise objects, postures and events — a queue, a fall, an obstruction, an empty shelf
  • Retain a short clip only for alerts you have explicitly armed with clips enabled

It does not

  • Compute, store or compare face embeddings or biometric templates of any kind
  • Maintain any identity database, watchlist, blocklist or loyalty linkage
  • Re-identify the same person across separate visits, across sites, or across customers
  • Infer religion, caste, health status, disability or any other sensitive characteristic
  • Score, rank or profile named individual employees — staff watches are about coverage of a position, not surveillance of a person
  • Sell, share or license your event data to advertisers, data brokers or third parties

On requests we decline

We are asked, reasonably often, to add face matching — usually for a repeat-shoplifter list. We say no, and we will keep saying no. Once a system can identify a named individual from a camera, every other guarantee on this page becomes a promise about how we intend to behave rather than a fact about what the software can do. We would rather lose the deal than lose the distinction. If face matching is a requirement for you, we are the wrong vendor and we will say so on the first call.

Data flow

What leaves your building, exactly

DataWhere it livesLeaves premises?Default retention
Raw camera videoYour existing NVRNo — neverYour NVR's own setting
Decoded framesEdge appliance RAMNoDiscarded within seconds
Detection vectorsEdge applianceNoDiscarded after aggregation
Structured events
counts, durations, breaches
SentrixShield, Indian regionYes30 days (14 on education)
Aggregate demographics
bracket counts, no individuals
SentrixShield, Indian regionYes, if enabled30 days
Alert clips (20s)Edge, then cloud if attachedOnly for armed alerts with clips on30 days, or as configured
The digital twinSentrixShield, Indian regionYes — it is built thereLife of the account
Console audit logSentrixShield, Indian regionYes12 months

The scan footage itself is a special case: it is uploaded once for reconstruction and deleted within seven days of the twin going live. People captured incidentally during a walkthrough are not detected, indexed or retained — the reconstruction cares about walls, not customers.

Regulatory

The DPDP Act, 2023, in practice

India's Digital Personal Data Protection Act sets the frame we build inside. Here is how each obligation shows up as something concrete in the product.

In most deployments you are the Data Fiduciary and SentrixShield is your Data Processor. We sign a processing agreement that says so, and we will not process your data for any purpose you have not instructed.

Nothing on this page is legal advice. Your own obligations depend on your premises, your sector and your notices — take advice, and we will supply whatever documentation your adviser asks for.

Every deployment ships with printed signage in English and Tamil stating that the premises use automated video analytics, that no facial recognition is performed, what is measured, and how to contact you about it. Education sites additionally receive a parent-notice letter template.
Each watch declares its purpose in plain English — that sentence is the purpose record. Events emitted by a watch are tagged with it, so an audit can show exactly why any given data point exists. We do not repurpose your events for model training, benchmarking or anything else.
The architecture is the minimisation. Frames are discarded at the edge within seconds; only the aggregate that answers your question is retained. A footfall watch stores a number per interval, not a record per person.
30-day default, 14 days on education sites, configurable down to 24 hours per watch. Expiry is enforced by a scheduled hard delete, not by a flag — expired rows are removed from primary storage and from backups within a further 30 days.
Because we hold no identifiers, an individual generally cannot be located in our data — which is the strongest possible answer to an erasure request. Where a clip has been retained for an alert, you can delete it from the console immediately, and we will action a written request within 72 hours.
TLS 1.3 in transit, AES-256 at rest, per-tenant key separation, role-based access with per-region scoping, mandatory MFA for administrative roles, SSO and SCIM on Command, and a full console audit log retained for twelve months.
We notify you without undue delay and in any case within 72 hours of becoming aware, with what we know, what we do not yet know, and what we are doing. We will not wait for a complete picture before telling you.
Education deployments disable demographic estimation entirely, default to 14-day retention, and default clip attachment to off. We will not enable demographic estimation on a site we know to be a school, even if asked.

Security posture

Data in transitTLS 1.3
Data at restAES-256, per-tenant keys
Hosting regionMumbai & Chennai (India)
Cross-border transferNone
Access controlRBAC, per-site and per-region
Admin authenticationMFA mandatory
SSO / SCIMCommand plan
Audit log retention12 months
Edge applianceSigned firmware, no inbound ports
BackupsEncrypted, in-region, 30-day cycle
Penetration testingAnnual, third party
Vulnerability disclosuresecurity@sentrixshield.shop

Certification status — stated honestly

We are a young company and we are not going to imply otherwise. Below is exactly where we stand. If a badge is not on this page, we do not hold it.

DPDP Act 2023 alignmentImplemented
Signed processing agreementAvailable on request
Third-party penetration testAnnual
ISO/IEC 27001In progress
SOC 2 Type IINot yet started

Ask us anything specific

Security questionnaires, architecture review calls, DPA redlines, or a walkthrough of the edge appliance for your IT vendor — all fine, all normal, none of them chargeable.

Contact the team

Bring your hardest privacy question to the first call.

We would rather have the difficult conversation before you buy than after.