Security

Last updated 30 July 2026

Encryption. TLS 1.3 in transit. AES-256 at rest. Per-project key separation.

Face blurring. Runs at ingestion in an isolated pre-processing stage, before any inference. Irreversible. Cannot be disabled at any tier.

Access control. Role-based and least-privilege. Engineer access to customer media requires a named ticket, is time-boxed, and is logged. Logs retained 12 months.

Infrastructure. Hosted in Indian cloud regions. Network isolation between the ingestion, inference, and application tiers. Secrets in a managed vault, not in code or environment files.

Development. Mandatory peer review, automated dependency scanning, secret scanning in CI, and static analysis on every pull request.

Backups. Encrypted, daily, restore tested quarterly.

Model governance. Every model version is recorded with its training data provenance, evaluation results, and known failure modes. Outputs carry a confidence indicator. Customer media is excluded from shared-model training unless separately opted in.

Incident response. Documented runbook. Confirmed personal data breaches are notified to the Data Protection Board and affected principals within 72 hours.

Vulnerability disclosure. Report to security@oneeye.in. We acknowledge within 2 business days. We will not pursue legal action for good-faith research that respects user privacy and avoids service disruption.

Current certification status. We are not yet ISO 27001 or SOC 2 certified. We publish this plainly rather than implying otherwise. [Update this line when that changes.]

← Back to oneeye.in