Privacy & Governance
TirionAI is built for environments where data governance is a requirement, not a preference. Video is processed at the edge, only verified events move across the network, and the system is designed to support our customers' obligations under EU law.
GDPR
Video is processed locally at the edge, so personal data barely moves. Only verified event metadata is centralised, supporting data minimisation (Art. 5) and helping deployers meet the DPIA (Art. 35) obligations that systematic monitoring of public areas triggers.
EU AI Act
TirionAI operates as a verification aid under human oversight. It performs none of the practices prohibited under Article 5, and is built to support the technical-documentation, logging and transparency expectations placed on high-risk deployers. We work with each deployer on the risk classification of their specific use.
NIS2
For operators classed as essential or important entities, TirionAI is built around strong encryption (AES-256, TLS 1.3), tamper-evident logging and an architecture that keeps working when connectivity is degraded, supporting risk-management and incident-reporting duties.
What TirionAI does not do
No real-time remote biometric identification or facial recognition. No emotion recognition. No biometric categorisation to infer protected characteristics. No social scoring or predictive profiling. No scraping of footage to build facial-recognition databases.
Human oversight
TirionAI detects, verifies and prioritises events, but a person makes every decision and takes every action (AI Act Art. 14). Every event and operator action is logged in tamper-evident, timestamped records (Art. 12).
Your operation outlives our contract
TirionAI runs on infrastructure you control, footage you already own, and cameras and a VMS you already operate. If our relationship ends, your cameras, your VMS, and your event history keep working. Nothing about your operation is hostage to us staying in business.