A camera network produces intelligence only as trustworthy as its evidence chain, and only as safe as the infrastructure beneath it. Vaidome delivers the analytics and the sovereign, cyber-hardened platform they run on — engineered as one system.
All data resident in-country. Fully offline and air-gap capable. No external cloud dependency.
Cyber-hardened
Security engineered into every layer, not added afterwards. This is our core discipline.
Rust-native runtime
No interpreted languages in production. A smaller, auditable attack surface end to end.
Post-quantum ready
Encryption built to withstand the quantum era, today — through our Nizam post-quantum cryptography work.
The problem
Cameras everywhere, nobody watching
Adding cameras does not add visibility. Organisations keep hitting the same four limits.
Operator fatigue
Dozens of live streams, one pair of eyes. Attention drops within minutes — and that is exactly when the critical moment goes by.
Hours after the incident
Proving an incident means hours of scrubbing through recordings. The footage is found, but not in time.
Data cannot leave
Regulation and operational security do not allow footage to reach an external cloud. Most analytics products ask for exactly that.
Vendor lock-in
Every new requirement becomes a new project, a new wait and a new invoice. The organisation cannot retrain or change its own detection models.
Technical architecture
One pipeline: capture, reason, prove, act
Six stages, engineered as one system. Each stage hands the next an auditable record.
01
Capture
ONVIF / RTSP
Multi-camera ingest from the cameras you already have. No camera replacement required.
02
Rust agent
Zero-copy ingest
Frame scheduling and back-pressure control. No interpreted languages, and predictable resource use.
03
AI inference
H200 GPU · MIG
Mission-trained models running on partitioned GPUs.
04
Analytics store
ClickHouse
Events and metadata held queryable at scale.
05
Correlate and alert
Batin engine
Rules, data-loss prevention and real-time alarm generation.
06
Operations UI
RBAC dashboard · APIs
Role-based operator screens and APIs into external systems.
Evidence path
Every clip and every detection is written to Hafiz with a SHA-256 hash chain — tamper-evident and court-defensible.
Security envelope
End-to-end encrypted
Post-quantum cryptography
Hash-chained audit
In-country residency
Three differentiators
Three decisions that set us apart
These are not marketing headlines. They are design decisions taken at the very start of the architecture, and they cannot be undone.
01
Your data never leaves
No cloud, no external APIs, no phoning home for a licence. Installation runs without internet, and the system works at full function on an air-gapped network. Data stays in-country.
Fully offline / air-gap operation
No external cloud dependency
IPsec IKEv2 tunnels, segmented VLANs
In-country data residency
Monitoring wall
02
A provable evidence chain
Every alarm frame is written to disk and sealed with SHA-256. All operations are recorded in a hash-chained, immutable audit log, and the chain is verified with a single action.
Frames and clips sealed with SHA-256
Hash-chained immutable audit log
Signed evidence package and offline verifier
Legal hold and retention policy
Alarm detail
03
Your own model, trained on site
Models are developed in-house and trained on data from your own site, then re-trained on site as conditions change. The whole cycle, from labelling to promotion, runs on your server without a line of code.
No-code labelling, training and promotion
Shadow mode: run on live traffic without raising alarms
Quality scorecard measured on a frozen test set
On an air-gapped network, with no internet
Studio — training
Layered view
A layered stack of production-ready components
Data flows upward. Security and sovereignty span every layer.
Data flow
Presentation
Operator UI · RBAC dashboards and secure APIs
VaidomeReady
Correlation and alerting
Rules, data-loss prevention and real-time alarms
BATINReady
Storage
ClickHouse analytics · Hafiz immutable evidence store
HAFIZProduction
AI inference
H200 · MIG · mission-trained models
VaidomeReady
Ingestion
Rust agent · decode, scheduling, back-pressure
VaidomeReady
Sources
IP cameras · ONVIF / RTSP · existing VMS
Input
PRODUCT = proprietary Vaidome product · Vaidome = built in-house · Green = production-ready
Security and sovereignty
spans every layer
Nizam — post-quantumPRODUCT
CortexDNS — monitoringPRODUCT
End-to-end encryption
Hash-chain audit
RBAC · MFA
Air-gap · residency
AI functions
Detection built for your mission
All models are developed in-house and trained on site- and mission-specific data, then re-trained on site as conditions change. Inference runs on our Rust runtime — auditable, with no interpreted-language dependencies.
Number Plate (ANPR)
Multi-lane plate capture and watch-listing.
Face Recognition
Identity matching with lawful-use controls.
Crowd & Density
Occupancy, flow and gathering analytics.
Intrusion & Perimeter
Line-cross, zone breach and motion anomaly.
Object & Vehicle
Classify, count and track objects and vehicles.
Behaviour & Loitering
Abnormal movement and dwell detection.
Abandoned Object
Left-luggage and unattended-item alerts.
Uniform & Attire
Detect specified clothing or markings.
Rule engine — without writing code
Detection on its own is not enough. Rules decide which detection becomes an alarm, and your operator team builds the rules.
Zones and lines
Zone breach, line crossing, entry and exit, and headcount.
Camera tampering
Blackout, blur, scene change and frozen image — derived from the frame already being processed, at no extra compute cost.
Event chains
Multi-step scenarios such as "if the subject passes this door and stops in this zone within 30 seconds".
Arming schedule
Rules run only during the hours you set, and maintenance windows can be defined.
Model lifecycle
Your own data, no code
Off-the-shelf models are general purpose. High accuracy on site comes from training on the organisation's own footage — which is exactly what Studio is for.
1
Label
Collect examples by drawing boxes on your own recordings.
2
Freeze the dataset
Create a versioned, reproducible training set.
3
Train
Start training on GPU and follow progress and metrics.
4
Promote
Run it in shadow mode, read the quality scorecard, then promote it through an audited gate.
Quality scorecard
We do not claim accuracy; we measure it. It is computed with a standard COCO evaluation on a frozen test set and reported class by class.
0.801
mAP@0.5
0.951
Precision
A real measurement example. Your own result depends on your data and your class definitions.
Quality scorecard
Closed learning loop
Sub-threshold detections and operator false-alarm flags feed the labelling queue for the next version of the model. The system adapts to your site as it is used.
Evidence and compliance
A court-defensible record
A security system that cannot defend the record it produces is only a monitoring system. The evidence chain was built for this requirement from the start.
How the hash chain works
Every record carries the digest of the one before it. Changing a single line breaks the entire chain, and verification shows it immediately.
Record n-1sha256 a3f9…7c21
Record nsha256 7c21…be04
Record n+1sha256 be04…1d8a
Chain verifiedTampering detected
Audit chain verification
2,550,994records·32s
Audit log
SHA-256 seal
The alarm frame and the event clip are written to disk and hashed with SHA-256. Any later change is detectable.
Signed evidence package
Report, frame, clip and manifest leave the organisation as a single package. The recipient checks it with an offline verifier.
Legal hold
While the retention policy runs, records under investigation are locked against deletion.
Row-level isolation
PostgreSQL row-level security isolates data fail-closed: a role without permission cannot query the data at all.
Immutable audit log
Who changed what, and when — all written to the chain and verified with a single action.
Backup and restore
Restore from backup is proven by regular restore drills, and synchronisation is supported on air-gapped networks.
Cybersecurity — our core discipline
Where most vendors stop, we begin
Security is not a layer dressed over video analytics afterwards; it is the platform itself.
Post-quantum cryptography
CRYSTALS-Dilithium and SPHINCS+ through our Nizam work — resistant to harvest-now-decrypt-later attacks.
Immutable audit and evidence
The Hafiz SHA-256 hash-chain makes every log and every clip tamper-evident and court-defensible.
RBAC + MFA
Fine-grained roles, least-privilege enforcement and multi-factor access across the platform.
End-to-end encryption
Data is encrypted in transit and at rest across every layer of the platform.
Secure communication
IPsec IKEv2 tunnels, segmented VLANs, air-gap and closed-network operation.
Hardened supply chain
Pure-Rust production runtime — no interpreted languages, and a minimal attack surface.
Runtime hardening
Services do not run as root
Read-only root filesystem
Untrusted models load in an isolated sandbox
EdDSA-signed JWT and login attempt throttling
Envelope encryption and master key rotation
Clock-jump watchdog (time trust on air-gapped networks)
The platform beneath the analytics
Four proprietary products, one hardened stack
Video analytics is only the visible part. Beneath it sit four proprietary products, each hardened and engineered in its own right — Hafiz already in production, the others production-ready.
HAFIZ
Production
Secure storage and fast data
S3-compatible object store, 90+ endpoints
Next-generation secure retention of every frame
SHA-256 hash-chain, air-gap sync, PQC-ready
CORTEXDNS
Ready
Network and environment monitoring
DNS-layer visibility and threat blocking
Detects anomalies in the operating network
Post-quantum protected DNS
BATIN
Ready
Monitoring and data-loss prevention
eBPF kernel-level traffic inspection
Data-loss prevention and exfiltration control
Correlation and real-time alerting engine
NIZAM
Ready
Post-quantum cryptography
Quantum-resilient cryptographic layer
CRYSTALS-Dilithium and SPHINCS+
Hardens the whole platform for the PQC era
Screen tour
What the operator actually sees
The product interface is available in Turkish and English. Every screen is designed so the operator can take the next step in a single click.
Layouts from 1×1 to 4×4, camera-to-tile assignment, named walls and tour mode.
Screen 1 / 15
Performance and scalability
Concrete performance, confirmed at acceptance
Representative operating figures on the specified hardware, confirmed against the agreed SLA at acceptance.
ANPR plate-read accuracy
95%
ANPR plate-read accuracy
Face verification (1:1)
99%
Face verification (1:1)
End-to-end alarm latency
<1s
End-to-end alarm latency
Real-time, per stream
30 fps
Real-time, per stream
Event ingest rate
100k+/s
Event ingest rate
System availability
99.9%
System availability
Concurrent streams scale with GPU nodes
Approximately 300 concurrent 1080p streams per GPU node, scaling near-linearly. The chart projects that figure linearly. Evidence retention extends to petabyte scale.
Alarm noise suppression
44.1 events/min1 alarm/min
Events are grouped into episodes, so operators see one alarm instead of a stream of near-duplicates.
30-day report time
2.94s26 ms
A summary layer makes reports open instantly.
GPU telemetry cost
10s~30 ms
About 0.3% of a single CPU core — measuring the system does not slow it down.
Measured efficiency
Integration
Open standards, no vendor lock-in
Interoperability is delivered through published, open standards. We integrate with the platforms shown via those standards — rather than as a certified reseller.
Vaidome Platform
Video / VMS
ONVIF · RTSP — integrates with Milestone, Genetec and other VMS platforms.
Storage
S3-compatible API (90+ endpoints) — Hafiz or any S3 target.
Enterprise systems
REST and gRPC APIs — export models and events to third-party applications.
SIEM / PSIM
syslog and CEF feeds — alerts flow into your existing security operations.
GIS / Geospatial
GeoJSON and map-service APIs — plot cameras and detections on maps.
Prometheus metrics, a ready-made Grafana dashboard and GPU telemetry.
No notification is lost
Failed notifications are queued and retried with exponential backoff. Critical external actions can be gated on operator approval.
Deployment and implementation method
From discovery to long-term support
Engagement begins only on acceptance of our proposal; implementation follows the phased path below.
1
Discover
Site survey, camera and network assessment, requirement mapping.
2
PoC
Limited-camera pilot proving detection and performance on your own data.
3
Train and tune
Model training and on-site calibration to your environment.
4
Rollout
Phased, secured deployment across the network.
5
Commission
Integration, acceptance testing and go-live.
6
Train teams
Operator and administrator enablement.
7
Support
SLA-backed maintenance, updates and model re-training.
Air-gap installation
The installation package is carried on USB and its SHA-256 verification runs fail-closed. Nothing beyond Docker is installed on the customer server, and no step requires internet.
Named references are shared under NDA at the short-list stage, with each client's written consent — and we can arrange direct reference calls. For sensitive, security-critical deployments, deployment counts and locations are treated as confidential.
What we can share now
Public release of Hafiz (v0.3.0) — inspectable engineering
Independent recognition: NATO seminar acceptance (PQC)
Live technical demonstration on your own scenarios
Architecture and security deep-dive with our engineers
NDA-based reference introductions at short-list stage
Technical summary
Technical specifications
A ready reference for specification documents and tender files.
Technical specifications
Specification
Value
Deployment
On-premises, fully offline / air-gap capable
Data residency
All data in-country; no external cloud dependency
Hardware
NVIDIA GPU (H200 · MIG partitioning) or CPU-only profile
Camera protocol
ONVIF · RTSP; works alongside an existing VMS
Runtime
Pure-Rust production runtime; no interpreted languages
Data layer
ClickHouse analytics · PostgreSQL (RLS) · Hafiz S3-compatible object store
SHA-256 hash-chain · signed evidence package · offline verifier · legal hold
Interface language
Turkish and English operator interface; PWA for mobile
Installation
Single box, docker compose, air-gap package on USB; SHA-256 fail-closed verification
Licensing
Per module · per camera count · per classes per camera
Extended capabilities
The wider capability set
These capabilities are part of the platform and are enabled according to deployment scope.
Available
Natural-language search
Event description and free-text recording search via a local vision-language model.
Available
Cross-camera journeys
Person re-identification across cameras and a unified journey timeline.
Available
High availability
Active-passive redundancy with automatic failover.
Available
IoT sensor triggers
Doors, turnstiles and field sensors feed directly into event chains.
Available
PTZ control
Moving cameras are driven from the operator console.
Frequently asked questions
Questions asked when writing specifications
Direct answers. If we are not certain about something, we say so.
Does it really work without internet?
Yes. The installation package is carried on USB, verification is local, and the system runs at full function on an air-gapped network. It does not call out for licence checks, download models or send telemetry.
Does it work with our existing cameras?
Yes. It works with IP cameras that provide ONVIF and RTSP, and it sits alongside existing VMS installations such as Milestone and Genetec. No camera replacement is required.
Does it replace our VMS?
It does not have to. It works with your existing VMS through open standards and adds the layer that the VMS cannot see — analysis, rules, alarms and evidence. If you prefer, recording and monitoring can also be consolidated with us.
Is a GPU mandatory?
No. It also runs on a CPU-only profile, with camera density and model complexity planned accordingly. The GPU profile reaches approximately 300 concurrent 1080p streams per node.
How many cameras does it support?
Scale grows near-linearly with the number of GPU nodes. Approximately 300 concurrent 1080p streams per node is a representative figure; the exact number is set by frame rate, resolution and the number of active models, and we calculate it together during discovery.
Where is the data stored?
On your own server. Analytics data sits in ClickHouse, configuration and permissions in PostgreSQL, and evidence in the Hafiz S3-compatible object store. None of it leaves the boundary of your organisation.
How do you prove model accuracy?
We do not claim accuracy; we measure it. mAP, precision and recall are computed with a standard COCO evaluation on a frozen test set and reported as a per-class scorecard. That scorecard becomes part of the acceptance file.
Why is an off-the-shelf model not enough on our site?
Off-the-shelf models are general purpose: lighting, camera angle, clothing and scene layout are specific to your site. High accuracy comes from training on the organisation's own footage; Studio exists for exactly this, and it is a design decision rather than a weakness.
How do you reduce false alarms?
In three layers: events are grouped into episodes (in one measured case, 44.1 events per minute reduced to a single alarm), rules and chains add context, and operator false-alarm flags feed the labelling queue for the next version of the model.
Is the evidence legally defensible?
Frames and clips are sealed with SHA-256, all operations are written to a hash-chained immutable audit log, and the chain can be verified. An incident is exported as a signed package that the recipient checks with an offline verifier. Final admissibility of the evidence rests with the relevant court.
Are face and plate recognition used lawfully?
These functions come with lawful-use controls: role-based access, multi-factor authentication, a retention policy, and every query written to the immutable audit log. Which functions are enabled, and to what scope, depends on the organisation's legal assessment and local regulation.
How long does deployment take?
We work through seven stages: discovery, proof of concept, training, rollout, commissioning, team enablement and support. The duration becomes clear during discovery, based on camera count, site conditions and the scope of model training.
Next step
Let us prove it on your scenarios — under NDA.
We propose a scoped, scenario-based demonstration of the computer-vision and closed-network capabilities most relevant to your priorities, followed by a security and architecture deep-dive.