Skip to content
Vaidome

Sovereign · Cyber-hardened · Rust-native

We do not sell cameras. We secure what they see.

A camera network produces intelligence only as trustworthy as its evidence chain, and only as safe as the infrastructure beneath it. Vaidome delivers the analytics and the sovereign, cyber-hardened platform they run on — engineered as one system.

  • Air-gap capable
  • On-premises
  • Hash-chained evidence
  • Models re-trainable on site
  • No cloud dependency
Operator monitoring wall
Multi-camera live monitoring wall with simultaneous camera streams in a grid layout

Sovereign by design

All data resident in-country. Fully offline and air-gap capable. No external cloud dependency.

Cyber-hardened

Security engineered into every layer, not added afterwards. This is our core discipline.

Rust-native runtime

No interpreted languages in production. A smaller, auditable attack surface end to end.

Post-quantum ready

Encryption built to withstand the quantum era, today — through our Nizam post-quantum cryptography work.

The problem

Cameras everywhere, nobody watching

Adding cameras does not add visibility. Organisations keep hitting the same four limits.

Operator fatigue

Dozens of live streams, one pair of eyes. Attention drops within minutes — and that is exactly when the critical moment goes by.

Hours after the incident

Proving an incident means hours of scrubbing through recordings. The footage is found, but not in time.

Data cannot leave

Regulation and operational security do not allow footage to reach an external cloud. Most analytics products ask for exactly that.

Vendor lock-in

Every new requirement becomes a new project, a new wait and a new invoice. The organisation cannot retrain or change its own detection models.

Technical architecture

One pipeline: capture, reason, prove, act

Six stages, engineered as one system. Each stage hands the next an auditable record.

  1. 01

    Capture

    ONVIF / RTSP

    Multi-camera ingest from the cameras you already have. No camera replacement required.

  2. 02

    Rust agent

    Zero-copy ingest

    Frame scheduling and back-pressure control. No interpreted languages, and predictable resource use.

  3. 03

    AI inference

    H200 GPU · MIG

    Mission-trained models running on partitioned GPUs.

  4. 04

    Analytics store

    ClickHouse

    Events and metadata held queryable at scale.

  5. 05

    Correlate and alert

    Batin engine

    Rules, data-loss prevention and real-time alarm generation.

  6. 06

    Operations UI

    RBAC dashboard · APIs

    Role-based operator screens and APIs into external systems.

Evidence path

Every clip and every detection is written to Hafiz with a SHA-256 hash chain — tamper-evident and court-defensible.

Security envelope
  • End-to-end encrypted
  • Post-quantum cryptography
  • Hash-chained audit
  • In-country residency

Three differentiators

Three decisions that set us apart

These are not marketing headlines. They are design decisions taken at the very start of the architecture, and they cannot be undone.

01

Your data never leaves

No cloud, no external APIs, no phoning home for a licence. Installation runs without internet, and the system works at full function on an air-gapped network. Data stays in-country.

  • Fully offline / air-gap operation
  • No external cloud dependency
  • IPsec IKEv2 tunnels, segmented VLANs
  • In-country data residency
Monitoring wall
Multi-camera live monitoring wall with simultaneous camera streams in a grid layout
02

A provable evidence chain

Every alarm frame is written to disk and sealed with SHA-256. All operations are recorded in a hash-chained, immutable audit log, and the chain is verified with a single action.

  • Frames and clips sealed with SHA-256
  • Hash-chained immutable audit log
  • Signed evidence package and offline verifier
  • Legal hold and retention policy
Alarm detail
Alarm detail screen showing the evidence frame, event clip and rule information together
03

Your own model, trained on site

Models are developed in-house and trained on data from your own site, then re-trained on site as conditions change. The whole cycle, from labelling to promotion, runs on your server without a line of code.

  • No-code labelling, training and promotion
  • Shadow mode: run on live traffic without raising alarms
  • Quality scorecard measured on a frozen test set
  • On an air-gapped network, with no internet
Studio — training
Model training screen with hyperparameters, a progress bar and GPU utilisation

Layered view

A layered stack of production-ready components

Data flows upward. Security and sovereignty span every layer.

  1. Presentation

    Operator UI · RBAC dashboards and secure APIs

    VaidomeReady
  2. Correlation and alerting

    Rules, data-loss prevention and real-time alarms

    BATINReady
  3. Storage

    ClickHouse analytics · Hafiz immutable evidence store

    HAFIZProduction
  4. AI inference

    H200 · MIG · mission-trained models

    VaidomeReady
  5. Ingestion

    Rust agent · decode, scheduling, back-pressure

    VaidomeReady
  6. Sources

    IP cameras · ONVIF / RTSP · existing VMS

    Input

PRODUCT = proprietary Vaidome product · Vaidome = built in-house · Green = production-ready

Security and sovereignty

spans every layer

  • Nizam — post-quantumPRODUCT
  • CortexDNS — monitoringPRODUCT
  • End-to-end encryption
  • Hash-chain audit
  • RBAC · MFA
  • Air-gap · residency

AI functions

Detection built for your mission

All models are developed in-house and trained on site- and mission-specific data, then re-trained on site as conditions change. Inference runs on our Rust runtime — auditable, with no interpreted-language dependencies.

Number Plate (ANPR)

Multi-lane plate capture and watch-listing.

Face Recognition

Identity matching with lawful-use controls.

Crowd & Density

Occupancy, flow and gathering analytics.

Intrusion & Perimeter

Line-cross, zone breach and motion anomaly.

Object & Vehicle

Classify, count and track objects and vehicles.

Behaviour & Loitering

Abnormal movement and dwell detection.

Abandoned Object

Left-luggage and unattended-item alerts.

Uniform & Attire

Detect specified clothing or markings.

Rule engine — without writing code

Detection on its own is not enough. Rules decide which detection becomes an alarm, and your operator team builds the rules.

  • Zones and lines

    Zone breach, line crossing, entry and exit, and headcount.

  • Camera tampering

    Blackout, blur, scene change and frozen image — derived from the frame already being processed, at no extra compute cost.

  • Event chains

    Multi-step scenarios such as "if the subject passes this door and stops in this zone within 30 seconds".

  • Arming schedule

    Rules run only during the hours you set, and maintenance windows can be defined.

Model lifecycle

Your own data, no code

Off-the-shelf models are general purpose. High accuracy on site comes from training on the organisation's own footage — which is exactly what Studio is for.

  1. 1

    Label

    Collect examples by drawing boxes on your own recordings.

  2. 2

    Freeze the dataset

    Create a versioned, reproducible training set.

  3. 3

    Train

    Start training on GPU and follow progress and metrics.

  4. 4

    Promote

    Run it in shadow mode, read the quality scorecard, then promote it through an audited gate.

Quality scorecard

We do not claim accuracy; we measure it. It is computed with a standard COCO evaluation on a frozen test set and reported class by class.

0.801
mAP@0.5
0.951
Precision

A real measurement example. Your own result depends on your data and your class definitions.

Quality scorecard
Model quality scorecard with mAP, precision and recall metrics and a per-class table

Closed learning loop

Sub-threshold detections and operator false-alarm flags feed the labelling queue for the next version of the model. The system adapts to your site as it is used.

Evidence and compliance

A court-defensible record

A security system that cannot defend the record it produces is only a monitoring system. The evidence chain was built for this requirement from the start.

How the hash chain works

Every record carries the digest of the one before it. Changing a single line breaks the entire chain, and verification shows it immediately.

  • Record n-1
  • Record n
  • Record n+1
Chain verifiedTampering detected

Audit chain verification

2,550,994records32s

Audit log
Audit log screen with operation rows and the hash-chain verification result

SHA-256 seal

The alarm frame and the event clip are written to disk and hashed with SHA-256. Any later change is detectable.

Signed evidence package

Report, frame, clip and manifest leave the organisation as a single package. The recipient checks it with an offline verifier.

Legal hold

While the retention policy runs, records under investigation are locked against deletion.

Row-level isolation

PostgreSQL row-level security isolates data fail-closed: a role without permission cannot query the data at all.

Immutable audit log

Who changed what, and when — all written to the chain and verified with a single action.

Backup and restore

Restore from backup is proven by regular restore drills, and synchronisation is supported on air-gapped networks.

Cybersecurity — our core discipline

Where most vendors stop, we begin

Security is not a layer dressed over video analytics afterwards; it is the platform itself.

Post-quantum cryptography

CRYSTALS-Dilithium and SPHINCS+ through our Nizam work — resistant to harvest-now-decrypt-later attacks.

Immutable audit and evidence

The Hafiz SHA-256 hash-chain makes every log and every clip tamper-evident and court-defensible.

RBAC + MFA

Fine-grained roles, least-privilege enforcement and multi-factor access across the platform.

End-to-end encryption

Data is encrypted in transit and at rest across every layer of the platform.

Secure communication

IPsec IKEv2 tunnels, segmented VLANs, air-gap and closed-network operation.

Hardened supply chain

Pure-Rust production runtime — no interpreted languages, and a minimal attack surface.

Runtime hardening

  • Services do not run as root
  • Read-only root filesystem
  • Untrusted models load in an isolated sandbox
  • EdDSA-signed JWT and login attempt throttling
  • Envelope encryption and master key rotation
  • Clock-jump watchdog (time trust on air-gapped networks)

The platform beneath the analytics

Four proprietary products, one hardened stack

Video analytics is only the visible part. Beneath it sit four proprietary products, each hardened and engineered in its own right — Hafiz already in production, the others production-ready.

HAFIZ

Production

Secure storage and fast data

  • S3-compatible object store, 90+ endpoints
  • Next-generation secure retention of every frame
  • SHA-256 hash-chain, air-gap sync, PQC-ready

CORTEXDNS

Ready

Network and environment monitoring

  • DNS-layer visibility and threat blocking
  • Detects anomalies in the operating network
  • Post-quantum protected DNS

BATIN

Ready

Monitoring and data-loss prevention

  • eBPF kernel-level traffic inspection
  • Data-loss prevention and exfiltration control
  • Correlation and real-time alerting engine

NIZAM

Ready

Post-quantum cryptography

  • Quantum-resilient cryptographic layer
  • CRYSTALS-Dilithium and SPHINCS+
  • Hardens the whole platform for the PQC era

Screen tour

What the operator actually sees

The product interface is available in Turkish and English. Every screen is designed so the operator can take the next step in a single click.

Layouts from 1×1 to 4×4, camera-to-tile assignment, named walls and tour mode.

Screen 1 / 15

Performance and scalability

Concrete performance, confirmed at acceptance

Representative operating figures on the specified hardware, confirmed against the agreed SLA at acceptance.

ANPR plate-read accuracy
95%
ANPR plate-read accuracy
Face verification (1:1)
99%
Face verification (1:1)
End-to-end alarm latency
<1s
End-to-end alarm latency
Real-time, per stream
30 fps
Real-time, per stream
Event ingest rate
100k+/s
Event ingest rate
System availability
99.9%
System availability

Concurrent streams scale with GPU nodes

Approximately 300 concurrent 1080p streams per GPU node, scaling near-linearly. The chart projects that figure linearly. Evidence retention extends to petabyte scale.

30016002900312004GPU node

Alarm noise suppression

44.1 events/min1 alarm/min

Events are grouped into episodes, so operators see one alarm instead of a stream of near-duplicates.

30-day report time

2.94s26 ms

A summary layer makes reports open instantly.

GPU telemetry cost

10s~30 ms

About 0.3% of a single CPU core — measuring the system does not slow it down.

Measured efficiency

Integration

Open standards, no vendor lock-in

Interoperability is delivered through published, open standards. We integrate with the platforms shown via those standards — rather than as a certified reseller.

Vaidome Platform

Video / VMS

ONVIF · RTSP — integrates with Milestone, Genetec and other VMS platforms.

Storage

S3-compatible API (90+ endpoints) — Hafiz or any S3 target.

Enterprise systems

REST and gRPC APIs — export models and events to third-party applications.

SIEM / PSIM

syslog and CEF feeds — alerts flow into your existing security operations.

GIS / Geospatial

GeoJSON and map-service APIs — plot cameras and detections on maps.

Notification and messaging

Webhook + HMAC, SMTP email, MQTT (QoS 1), SNMP (TRAP/INFORM).

Observability

Prometheus metrics, a ready-made Grafana dashboard and GPU telemetry.

No notification is lost

Failed notifications are queued and retried with exponential backoff. Critical external actions can be gated on operator approval.

Deployment and implementation method

From discovery to long-term support

Engagement begins only on acceptance of our proposal; implementation follows the phased path below.

  1. 1

    Discover

    Site survey, camera and network assessment, requirement mapping.

  2. 2

    PoC

    Limited-camera pilot proving detection and performance on your own data.

  3. 3

    Train and tune

    Model training and on-site calibration to your environment.

  4. 4

    Rollout

    Phased, secured deployment across the network.

  5. 5

    Commission

    Integration, acceptance testing and go-live.

  6. 6

    Train teams

    Operator and administrator enablement.

  7. 7

    Support

    SLA-backed maintenance, updates and model re-training.

Air-gap installation

The installation package is carried on USB and its SHA-256 verification runs fail-closed. Nothing beyond Docker is installed on the customer server, and no step requires internet.

  • NVIDIA GPU profileHigh-density, multi-stream deployment
  • CPU-only profileRuns on sites without GPUs

Air-gap boundary

  • IP cameras

    ONVIF / RTSP

  • Organisation server

    Analysis · recording · dashboard

  • Operator workstations

    Organisation network

No internet connection

Use cases

Same core, different mission

What changes between sectors is not custom code but a model trained on the organisation's own data. The events below are typical examples.

Correctional facilities

  • Entry into a restricted zone
  • Gathering and crowding
  • Fights and falls

Incidents are seen as they occur and defended afterwards with sealed evidence.

Credibility and innovation

Proven where proof is hardest

Where named references cannot be shared, our credibility rests on published work and independent recognition.

NATO seminar acceptance

Our post-quantum cryptography work was accepted for presentation at a NATO seminar — external validation of the science behind Nizam.

Hafiz v0.3.0 — public release

A public release of 40,000+ lines of Rust: 90+ S3 endpoints, blockchain-style hash-chain audit, PQC capabilities and air-gap sync.

Nizam PQC engineering

A dedicated post-quantum cryptography effort hardening the platform against harvest-now-decrypt-later threats.

Engineering backbone

H200 GPU clusters (MIG-partitioned) · Kubernetes / KubeFlow ML pipelines · high-throughput columnar analytics and secure object storage · encrypted site-to-site networking.

References, handled with discretion

Named references are shared under NDA at the short-list stage, with each client's written consent — and we can arrange direct reference calls. For sensitive, security-critical deployments, deployment counts and locations are treated as confidential.

What we can share now

  • Public release of Hafiz (v0.3.0) — inspectable engineering
  • Independent recognition: NATO seminar acceptance (PQC)
  • Live technical demonstration on your own scenarios
  • Architecture and security deep-dive with our engineers
  • NDA-based reference introductions at short-list stage

Technical summary

Technical specifications

A ready reference for specification documents and tender files.

Technical specifications
SpecificationValue
DeploymentOn-premises, fully offline / air-gap capable
Data residencyAll data in-country; no external cloud dependency
HardwareNVIDIA GPU (H200 · MIG partitioning) or CPU-only profile
Camera protocolONVIF · RTSP; works alongside an existing VMS
RuntimePure-Rust production runtime; no interpreted languages
Data layerClickHouse analytics · PostgreSQL (RLS) · Hafiz S3-compatible object store
IntegrationREST · gRPC · S3 (90+ endpoints) · Webhook + HMAC · SMTP · syslog RFC 5424 / CEF · MQTT (QoS 1) · SNMP · GeoJSON
ObservabilityPrometheus metrics · ready-made Grafana dashboard · GPU telemetry
CryptographyEnd-to-end encryption in transit and at rest · CRYSTALS-Dilithium · SPHINCS+ · EdDSA-signed JWT
Access controlRole-based access control (RBAC) · multi-factor authentication (MFA) · row-level isolation
EvidenceSHA-256 hash-chain · signed evidence package · offline verifier · legal hold
Interface languageTurkish and English operator interface; PWA for mobile
InstallationSingle box, docker compose, air-gap package on USB; SHA-256 fail-closed verification
LicensingPer module · per camera count · per classes per camera

Extended capabilities

The wider capability set

These capabilities are part of the platform and are enabled according to deployment scope.

  • Available

    Natural-language search

    Event description and free-text recording search via a local vision-language model.

  • Available

    Cross-camera journeys

    Person re-identification across cameras and a unified journey timeline.

  • Available

    High availability

    Active-passive redundancy with automatic failover.

  • Available

    IoT sensor triggers

    Doors, turnstiles and field sensors feed directly into event chains.

  • Available

    PTZ control

    Moving cameras are driven from the operator console.

Frequently asked questions

Questions asked when writing specifications

Direct answers. If we are not certain about something, we say so.

Does it really work without internet?

Yes. The installation package is carried on USB, verification is local, and the system runs at full function on an air-gapped network. It does not call out for licence checks, download models or send telemetry.

Does it work with our existing cameras?

Yes. It works with IP cameras that provide ONVIF and RTSP, and it sits alongside existing VMS installations such as Milestone and Genetec. No camera replacement is required.

Does it replace our VMS?

It does not have to. It works with your existing VMS through open standards and adds the layer that the VMS cannot see — analysis, rules, alarms and evidence. If you prefer, recording and monitoring can also be consolidated with us.

Is a GPU mandatory?

No. It also runs on a CPU-only profile, with camera density and model complexity planned accordingly. The GPU profile reaches approximately 300 concurrent 1080p streams per node.

How many cameras does it support?

Scale grows near-linearly with the number of GPU nodes. Approximately 300 concurrent 1080p streams per node is a representative figure; the exact number is set by frame rate, resolution and the number of active models, and we calculate it together during discovery.

Where is the data stored?

On your own server. Analytics data sits in ClickHouse, configuration and permissions in PostgreSQL, and evidence in the Hafiz S3-compatible object store. None of it leaves the boundary of your organisation.

How do you prove model accuracy?

We do not claim accuracy; we measure it. mAP, precision and recall are computed with a standard COCO evaluation on a frozen test set and reported as a per-class scorecard. That scorecard becomes part of the acceptance file.

Why is an off-the-shelf model not enough on our site?

Off-the-shelf models are general purpose: lighting, camera angle, clothing and scene layout are specific to your site. High accuracy comes from training on the organisation's own footage; Studio exists for exactly this, and it is a design decision rather than a weakness.

How do you reduce false alarms?

In three layers: events are grouped into episodes (in one measured case, 44.1 events per minute reduced to a single alarm), rules and chains add context, and operator false-alarm flags feed the labelling queue for the next version of the model.

Is the evidence legally defensible?

Frames and clips are sealed with SHA-256, all operations are written to a hash-chained immutable audit log, and the chain can be verified. An incident is exported as a signed package that the recipient checks with an offline verifier. Final admissibility of the evidence rests with the relevant court.

Are face and plate recognition used lawfully?

These functions come with lawful-use controls: role-based access, multi-factor authentication, a retention policy, and every query written to the immutable audit log. Which functions are enabled, and to what scope, depends on the organisation's legal assessment and local regulation.

How long does deployment take?

We work through seven stages: discovery, proof of concept, training, rollout, commissioning, team enablement and support. The duration becomes clear during discovery, based on camera count, site conditions and the scope of model training.

Next step

Let us prove it on your scenarios — under NDA.

We propose a scoped, scenario-based demonstration of the computer-vision and closed-network capabilities most relevant to your priorities, followed by a security and architecture deep-dive.

Direct contact

info@vaidome.com

Webvaidome.com

You can send NDA requests to this address as well.

If form submission is not configured, your email application will open.