Sauron
[00 / SAURON]

The analysis runs where
your systems already are.

Sauron is a security intelligence service. We connect to the security systems you already run, analyse what they see on your own premises, and bring the events that need a decision to an operator. Anything held centrally is encrypted, separated and accountable.

[01 / CAPABILITIES]

Ingest. Analyse. Correlate. Escalate.

01

Works with the systems you already run

There is no requirement to replace hardware. Sauron models sites, devices and events rather than a single camera type, so your systems are described once and analysed consistently regardless of the mix of vendors. Gateways handle ingest on site and register each device with its own credential. Integration with access-control platforms is in development.

02

Detection and analysis

Detection and dwell-time tracking across device views, with matching against an enrolled gallery of staff and authorised visitors. Optical fault detection identifies tampering, obstruction and glare, and separates gradual drift from sudden change.

03

Correlation and investigation

An incident engine groups related events instead of presenting a flat alert feed. An investigation workspace follows one question across multiple events and sites. Structured search covers events, incidents, investigations and device faults.

04

Approval and accountability

Nothing consequential happens on its own. An action that carries weight waits until someone with the authority to release it does so. Access is granted by role, so an operator, a duty manager and an auditor each see what their work requires and no more. Every event carries a review step, and access to evidence is written to the audit log.

05

Continuity through outages

Gateways buffer detections locally through a network outage and deliver them in order once the link returns, writing to local disk before any network attempt is made. A retry after a lost response is treated as a replay rather than a second detection, so nothing is lost and nothing is counted twice.

06

Reporting that reaches your team

An analysed detection becomes an event, and an event that matches what you have asked us to watch for is raised as an incident in the dashboard your operators already work from, with the footage and the sequence that produced it attached. We agree with you which event types warrant escalation and which are recorded without raising an alert, and who receives them. Reporting covers event and incident volume, response times, device availability, the most common event types, and which sites generate the most recurring problems.

[02 / RESPONSIBILITY]

Biometric data is handled the way it should be.

Recognising a face is a serious thing to do on someone else’s behalf. We designed the handling of that data before the features that use it, and we hold ourselves to it in every deployment.

Encrypted at rest

Biometric records and evidence are encrypted at rest with AES-256-GCM, and TLS protects data in transit. This applies to every deployment as standard.

Keys that rotate

Every encrypted record is tagged with the key that sealed it, so keys can be retired and data re-encrypted without downtime or a maintenance window.

Separated by tenant

Your records are held apart from those of every other organisation at the structural level, rather than by a query condition that could be misapplied.

Access is recorded

A biometric record can be opened only by a role permitted to do so, and each access is written to the audit log with the user and the time it occurred.

[03 / HOW IT WORKS]

Analysis at the edge. Oversight at the centre.

The same software runs in two places. On your premises it does the heavy work: detection, dwell-time tracking, matching against an enrolled gallery, and optical fault detection. Data is processed where it is captured, so the volume of raw material moving across your network stays low and analysis does not depend on a link to anywhere else.

A central instance receives the results, meaning what happened, where, when and with what confidence, and correlates them into incidents across sites. Where records are held centrally, they are held under the controls described above, and the same is true of the evidence attached to them.

You choose how much leaves the building. Local plus central is the usual arrangement: your devices feed a Sauron server on site, your staff work from a local dashboard, and derived events travel to a central instance so someone can see across every site at once. Fully local is the same deployment with the uplink switched off, for sites that cannot be networked outward. The software is identical either way, and the choice stays yours after go-live.

We work with organisations accountable for what their systems recorded. That includes industrial plants and utilities, commercial property and retail, logistics and transport, healthcare and education campuses, and government facilities. The requirements differ in detail, but each needs the same thing: a defensible account of what was observed and what was done about it.

[04 / CONTACT]

Business enquiries

We are happy to walk through how Sauron would apply to your systems, what it would see, and how we would deploy it.