Trust & Compliance

Controls that make
video operations governable.

Conquer handles video-derived operational data. Its security and privacy controls are designed into tenant scope, site access, AI dispatch, retention, evidence and audit paths — and we document the boundaries rather than making blanket compliance claims.

🇪🇺 Regional AI-routing controls

EU data mode is enforced at the AI dispatch point. When the configured compliant route is unavailable, Conquer refuses the analysis rather than silently falling back to another provider or route.

🔒 Explicit AI boundaries

Provider and model eligibility are policy-controlled. The active provider configuration, including any provider retention commitments, remains a deployment and contractual fact to verify during onboarding — it is not hidden behind a generic “AI compliant” badge.

🗄️ Retention as a control

Retention windows are scoped per tenant and applied by a scheduled sweep to stored assets and operational records. Teams can manage retention and use targeted deletion paths for the data in their scope.

🧾 Tamper-evident audit trail

Security-relevant actions are recorded in an append-only, hash-chained audit log. The application can verify the chain’s integrity; the fixed audit retention policy is 365 days.

🏢 Tenant, role and site scope

Tenant-scoped records use PostgreSQL Row-Level Security. Within a tenant, direct and group site grants, active-organisation scope and server-enforced capabilities constrain which operational objects a user can act on.

🔐 Deliberate two-factor governance

Authenticator-based account two-factor controls are available. The tenant-administrator requirement is a beta governance control that is disabled by default and must be explicitly armed by the tenant; trusting a Google sign-in is that tenant's policy choice because Conquer cannot verify whether Google MFA was used.

🧹 Reviews and evidence minimisation

Operational evidence is referenced, scoped and subject to retention. Review workflows can pin the evidence they need, while immutable run manifests expose opaque proof references rather than provider URLs or storage paths.

⌁ Aggregate-only optimisation

Model Optimizer suggestions use aggregate verdict counts and site scope, not predictions, reviewer notes, evidence, prompts or run inputs and outputs. Suggestions are manual-only: accepting one never edits a Flow or Intel.

↗ Durable webhook delivery

Outbound workflow webhooks use a transactional outbox with retry, dead-letter and replay paths, delivery history and encrypted signing-secret snapshots. Delivery is at least once, so receivers must deduplicate delivery identifiers.

◇ VMS integration boundary

The active product experience is Verkada. The connector architecture is provider-neutral, but Eagle Eye, Rhombus and Nx Witness / DW Spectrum adapters are dormant foundations without configured customer credentials, IDs or live integrations.

⌘ Developer-surface boundary

The versioned REST API contract and read-only MCP adapter are dormant internal foundations. They are not enabled customer integrations, a public developer programme or a plan entitlement.

Your role, our role

Your organisation remains responsible for its lawful basis, signage and information obligations. Conquer provides controls and implementation evidence to support your governance process; roles and contractual terms are confirmed for each engagement.

Documents

Ask us for the current materials at [email protected]. We will share the applicable documentation and deployment evidence for your review.

Data-processing termsApplicable roles, instructions and data-handling terms for the engagement
Technical controls overviewTenant scope, retention, audit and deployment-control evidence
Provider and subprocessor informationCurrent provider configuration and the boundaries relevant to the deployment
Retention & deletion controlsProduct-level retention paths and operational deletion capabilities
DPIA support materialTechnical input your privacy team can use in its own assessment
Incident communication processEngagement-specific escalation and evidence expectations

Review the controls for your deployment.

Tell us about your region, provider requirements and operating model. We’ll share the evidence and constraints relevant to that scope.

Request security materials