Visylix is engineered with enterprise-grade security, data privacy, and responsible AI governance at its core. On-premise deployment, dynamic privacy masking, SHA-256 evidence locks, and full audit trails for the workflows compliance teams actually sign off on.
Request Compliance DocumentationEvery regulated workflow Visylix supports, mapped to the standards and frameworks your auditors care about.
Visylix is designed with privacy by design principles that support compliance with GDPR, India DPDPA, and other data protection regulations.
Visylix implements enterprise-grade security controls to protect your video infrastructure and sensitive data.
Aptibit is committed to responsible AI development and deployment with transparency, fairness, and accountability across all 22 Visylix AI models.
Visylix flexible deployment architecture ensures your data stays where your regulations require.
Visylix supports compliance requirements across regulated industries.
Visylix aligns with international standards and frameworks for AI and data management.
Talk to our team about specific compliance requirements for your industry, jurisdiction, and procurement process.
No. Visylix holds no formal security certification today, and we will not imply otherwise. What it provides are the technical controls those frameworks assess: on-premise or air-gapped deployment, encryption in transit, role-based access control with 30+ permissions, configurable retention, evidence lock with SHA-256 hashing, and full audit logging of every operator action. Formal certification is on the roadmap.
Yes, and the deployment model is the reason. Because Visylix runs as a Docker image on infrastructure you control, including fully air-gapped, personal data never has to leave your premises for processing. That removes the cross-border transfer question rather than mitigating it. Your obligations around lawful basis, access control, retention and breach notification remain yours regardless of where the software runs.
Not on an on-premise deployment. All 22 AI analytics and the Radha copilot execute locally on your hardware. Many platforms describe themselves as on-premise while still calling out to a hosted service for inference or for the assistant; Visylix does not, which is what makes air-gapped operation possible.
Face recognition is available but should be treated as a policy decision rather than a default. Several jurisdictions, including Illinois under BIPA and the EU under GDPR Article 9, treat biometric data as a special category with consent and retention requirements. In deployments where biometrics are not required, intrusion, loitering, line crossing and crowd analytics answer most operational questions without processing biometric data at all.
Every view, export and configuration change is written to an audit log against the operator who performed it. Recordings can be hashed with SHA-256 and locked so retention rules cannot delete them while an investigation is open, which supports a chain-of-custody record. Logs can be streamed to a SIEM such as Splunk, Elastic or Datadog via webhook or syslog.
Visylix is software and is camera-agnostic, so NDAA Section 889 questions attach to the cameras and recorders you deploy, not to the VMS. Visylix does not require or bundle any specific camera hardware, which means it can be run entirely on NDAA-conformant equipment of your choosing.
Wherever you put it. Visylix does not host your video. It runs on your servers, your virtual machines or your own cloud account, and recordings are written to storage you control, with retention configurable per camera and per site. There is no Visylix-operated cloud holding customer footage.