Security

How KardoVision protects your sites, your video and your account — as built today.

The shape of it

The cloud manages the organisation; the KardoHub runs and understands the site; every Kardo device can run itself. Nothing critical depends on the tier above it: recording, door access and local AI carry on through an internet outage, a hub failure or a screen crash. Video is recorded on the KardoHub’s own disk at your site and leaves it only as far as each camera’s privacy mode allows.

Devices dial out; nothing dials in

Signed firmware, apps and models

Encrypted transport and storage

Your account

Tenant isolation, tested

Every table carries the account it belongs to and every query is scoped to it. One automated test walks every API route the running code exposes (438 at the last count) and, as another account’s owner, hub and integration key, asks for your things by id. It checks that no answer carries your data, that your rows are unchanged after every write, that nothing of theirs points at yours, that the platform console refuses a customer credential, and that nothing answers with a server error. It runs against a throwaway database before a release.

Privacy modes and least data

An audit log that cannot be rewritten

Every account has an audit log of who did what: sign-ins, role, site and device-limit changes, grants and end dates, privacy and retention changes with before and after, exports, support sessions and the video they opened, and changes made on a KardoHub’s own screen (marked as such). Entries are append-only: the application cannot change or delete one, and a database trigger refuses it too. Only the nightly retention job removes entries, after 730 days or the owner’s choice of at least a year.

Support only when you grant it

Kardo support cannot open your account. An owner or manager grants a read-only session for one, four or twenty-four hours, limited to devices unless they also allow video or figures, and can end it at any moment; each session lasts at most an hour and is written to your audit log with what it opened. The platform console shows every open grant and ends it with one button.

Keeping the platform honest

What is not done yet

Said plainly, so nobody reads more into the above than is there:

Last updated 29 September 2026. KardoVision is a product of Kardo.