Skip to content
Vestigit
Technology · Security & Privacy

Data boundary, identifier handling and responsibility.

How Vestigit treats identifiers, samples and detection records, and where the boundary sits between the customer's stack and the Vestigit service.

Data boundary at a glance

How Vestigit handles video, identifiers and detection artefacts.

Video and identifier processing occurs in agreed environments. Customer identity systems remain the source of truth. Only the customer maps identifiers to a person, account, subscriber or device. Detection records are designed to support investigations; they are not represented as admissible legal evidence and do not commit Vestigit to specific certifications, subprocessor lists, retention or residency guarantees on this page.

Data boundary at a glance

Video and identifier processing occurs in agreed environments. Customer identity, authentication and entitlement systems remain the source of truth; Vestigit may receive pseudonymous session context required for internal technical correlation.

Identifier ownership

The embedded identifier is opaque. Only the customer maps a result to a person, account, subscriber or device — that mapping stays inside the customer entitlement layer.

Detection record

The recovered identifier is the core output. Workflow context, timestamp and sample reference depend on the validated deployment and sample path.

Customer-controlled policy

Revocation, blocking and takedown decisions remain owned and executed by the customer.

Shared responsibility

Where Vestigit ends and your stack begins.

Shared responsibility across security-relevant areas
AreaCustomerVestigit
Content ingest & encodingOwnedIntegrates into supported stages
Session identity & mappingOwnedProvides mapping surface
Watermark embeddingProvides workflow accessOwned
Sample captureOwned or provider-fedAssists in defined workflows
Detection & attributionConsumes resultsOwned
Policy & enforcementOwnedProvides evidence inputs
Data residency & retentionOwnedAgrees during discovery
Security discovery inputs

Questions we scope together.

  • Data residency requirements for sample and detection artefacts.
  • Retention policy for samples, detections and audit logs.
  • Encryption in transit and at rest for the sample path.
  • Access control model, role assignment and audit-log expectations.
  • Logging integrations with the customer SIEM / observability stack.
  • Restricted-network access model for on-prem or hybrid deployments.
Procurement & vendor review

What to request during discovery.

  • Solution scope and data boundary description.
  • List of independent assessments available to review under NDA.
  • Shared responsibility matrix agreed for the target deployment.
  • Discovery inputs required for security, legal and procurement review.

Discuss security and data requirements.

Data boundary, retention, logging integrations and shared responsibility — aligned during discovery.