Most platforms upload your footage. Sauron inverts that.
The same software runs in two places. At your site it does the actual work: person detection, dwell-time tracking, face matching against a locally enrolled gallery, and optical tamper and glare detection. In a central instance it receives only finished events, meaning what happened, where, when and with what confidence, and correlates those events into incidents across sites.
Raw camera frames, face embeddings, movement traces and evidence files are structurally incapable of crossing that boundary. This is not a policy setting or a configuration option. The central instance refuses raw camera intake outright and never loads a recognition model at all. A misconfigured device, a copied credential or a well-meaning engineer cannot open that door, because the door does not exist on that half of the system. You can adopt AI security analytics without your footage becoming someone else’s asset.
There are two deployment models. Local plus central is the recommended one: cameras feed a Sauron server on your premises, on-site staff work from a local dashboard, and a one-way uplink carries derived events to a central instance for oversight across sites. Fully local is the same deployment with the uplink switched off, so nothing leaves the building at all. That suits sites which cannot be networked outward. The software is identical in both cases. There is no cut-down edition and no feature held back for a higher tier.
Sauron suits any organisation accountable for what its cameras saw. That includes industrial plants and utilities, commercial property and retail estates, logistics depots and transport hubs, healthcare and education campuses, and government facilities. It is a particularly close fit wherever a regulatory or contractual obligation prevents footage being handed to a third party’s cloud.