Principle one
Purpose limitation & data boundaries
Physical security data should remain focused on its intended safety purpose. We design technical controls directly into our platform architecture — such as enabling organizations to restrict facial processing strictly to designated Person of Interest (POI) profiles — to keep features targeted. Additionally, our global infrastructure features localized cloud shards that support data residency requirements by keeping data stored, and in some regions processed, locally. This infrastructure is backed by robust data processing terms in our Customer Data Processing Addendum, Standard Contractual Clauses (SCCs) designed to meet high global standards, and certification to the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework ("Data Privacy Frameworks" or "DPF") as a legal basis for transfers of personal information from the EU, the UK, and Switzerland to the U.S.
Strict data siloing
Your video and data are logically separated in dedicated, tenant-isolated cloud environments. Your organization's data is never pooled with other customers or placed into a shared, searchable network.
Local data residency
You choose exactly where your cloud data is stored (US, Canada, Australia, Germany, Japan, Singapore and South Korea) to meet local compliance requirements.
Enterprise Controlled Encryption (ECE)
ECE is an opt-in, dual-key system where decryption requires authorization from your own OIDC identity manager (like Okta or Entra ID). Without your key, it is not possible for Verkada or non-authorized users to access your video.