TECTIVAI

Security & privacy

We watch jobsites. Not workers.

Tectiv is built on the assumption that the person on camera deserves the same protections as the data they generate. Here is exactly how we handle both.

Encryption
In transit + at rest
HTTPS/TLS in transit · Supabase encryption at rest · RTSP credentials encrypted (Fernet)
Inference
Dedicated GPU
Runs on a hosted GPU server (RunPod) — no customer hardware
Hosting
US-based
Supabase (data) · Vercel (frontend) · AWS S3 (footage)
Footage
You control it
Raw video deleted after processing unless you opt in · structured data is always yours

Five things we will not do

The lines we do not cross.

Rule 01

No facial recognition.

Our models detect people, equipment, and activity. They do not — and will not — match faces against any identity database.

Rule 02

No worker scorecards.

Workers are tracked only as anonymous IDs for counting and activity. We do not link a track to a named person or build per-employee scorecards — the dashboard answers 'how was the slab pour,' not 'how was Marc.'

Rule 03

No selling your data.

Your jobsite data is yours. We never sell it, license your footage, or share it with insurers. We may use footage to improve our own detection models — and only if you allow it.

Rule 04

No forced retention.

Raw video is deleted after processing unless you opt in to retention. Keep it to improve accuracy, or do not. Structured data (counts, durations, zones) is always yours to export or delete.

Rule 05

No surprise access.

Tectiv staff access your data only to operate the service or when you ask us for help — never to browse. Per-access audit logging is on our roadmap.

Compliance

Audits, certifications, paperwork.

Roadmap

SOC 2 Type II

Planned · not yet started

Roadmap

GDPR + CCPA

Deletion on request today · full workflow planned

Roadmap

ISO 27001

Planned · roadmap

Roadmap

OSHA 29 CFR 1926

PPE detection on the roadmap

Roadmap

Penetration test

Planned · pre-launch

Roadmap

Bug bounty

Planned · future

Data flow

Where the bytes go.

Step 01

Camera

RTSP stream

Your hardware. Tectiv never owns the camera.

Step 02

Secure ingest

Tectiv backend

The stream reaches our backend over the network; RTSP credentials are encrypted at rest.

Step 03

GPU inference

Dedicated GPU

Frames are analyzed on a GPU. Detections — counts, zones, activity — are extracted; annotated, timestamped frames are retained per your settings.

Step 04

Your dashboard

Vercel + Supabase

Counts, durations, and zones. Footage is retained per your settings and deletable on request.

Documents

Read the fine print.

Sub-processor list

Supabase · Vercel · AWS S3 · Resend

Request →

Data Processing Addendum

Available on request

Request →

Vulnerability disclosure

Report it via our contact form

Report →

Privacy policy

Published — plain language, no legalese

Read →

Terms of service

Published — pre-launch terms

Read →

Privacy by design

Questions about your data?

Ask us anything about security, retention, or deployment. We answer in plain language.

We use cookies for analytics and to understand how visitors use this site. You can accept or decline. See our privacy policy.