Security.
A comprehensive overview of the security, privacy, and data-protection practices that safeguard customer footage and data on the Darkfield platform.
// version 1.04 · june 2026 · prepared for prospective and existing customers
1 · Introduction
Linox Ltd builds Darkfield, an AI vision platform that runs perception on the cameras an organisation already operates. By its nature, Darkfield handles some of the most sensitive data a business holds: live video of its sites, its people, and its operations. Security and privacy are therefore not features added after the fact — they are the starting point of the architecture.
This whitepaper describes the controls Linox operates across infrastructure, data handling, access management, model oversight, and incident response. It is written for the security, IT, and data-protection teams evaluating Darkfield.
Darkfield is in UK private beta during 2026. This document reflects our current practices and is updated as the platform matures. Availability of some features depends on the chosen plan and deployment model.
2 · Security & Privacy at a Glance
Darkfield turns video into events, and we keep only the smallest amount of data needed to deliver the service. For customers who require it, frames can be anonymised in memory before anything is written to disk.
Darkfield offers three deployment models so the data-egress profile matches your risk appetite and budget.
| Deployment model | Plan | Where inference runs | Raw video leaves firewall? |
|---|---|---|---|
| Edge | Enterprise | On-site AI vision-box, behind your firewall | No. Raw video stays on your network. Only events, detections, and short evidence clips reach Linox. |
| Managed cloud | SME | A dedicated, network-isolated instance in the UK, managed by Linox | Yes — streamed over an encrypted channel to your own isolated instance. Not a shared, multi-tenant pool. |
| Air-gapped | Defence / critical infrastructure | Fully on partner hardware, with no outbound connection to Linox | No. Signed model-weight updates are delivered on disk on a quarterly cadence. |
Across every model, data is encrypted in transit and at rest and UK data residency is maintained. In-memory anonymisation, which removes identifying detail from each frame before any clip is persisted, is available for customers who require it.
3 · Infrastructure Security
Darkfield is engineered to expose the smallest possible surface to your network and to ours.
- Edge-first architecture: The Darkfield network gateway and AI vision-box install in minutes and run perception on-site. The gateway reaches only the cameras you nominate — the rest of your network remains unreachable to Darkfield.
- Network segmentation and isolation: Production environments are segmented to contain and protect different parts of the infrastructure. For SME managed-cloud customers, inference runs in a dedicated, network-isolated instance rather than a shared multi-tenant pool.
- UK-hosted cloud: Cloud ingest and the management plane run on UK-based infrastructure, keeping customer data within the United Kingdom.
- Zero-trust corporate access: Corporate endpoints operate under a zero-trust model in which every access request is verified before it is granted.
- Endpoint and email security: Endpoint detection and response (EDR) tooling and email threat protection are deployed across the corporate fleet to block malicious content before it reaches our teams.
- Authentication to production: Access to production systems, datastores, and networks requires unique credentials or authorised SSH keys, a valid multi-factor authentication (MFA) method, and an approved encrypted connection.
- Monitoring and audit logging: Infrastructure and access events are logged centrally and continuously monitored so that suspicious activity can be reviewed and acted upon.
4 · Data Encryption
Data is protected at every stage of its lifecycle.
- Encryption in transit: All data moving between your site, your devices, and Linox is encrypted using TLS 1.2 or higher. This includes RTSP streams from managed-cloud customers.
- Encryption at rest: Stored data — including events, detections, short evidence clips, and configuration — is encrypted using AES-256.
- Air-gapped integrity: Model-weight updates delivered to air-gapped deployments are cryptographically signed and validated before they are activated.
5 · Data Privacy & Minimisation
This is the heart of operating AI vision responsibly.
- Perception close to the source: In edge (Enterprise) deployments, raw frames never leave your firewall. In managed cloud (SME) deployments, raw video is streamed only to your dedicated, network-isolated instance in the UK — never to a shared pool — and is processed under Linox's management.
- In-memory anonymisation (on request): For customers who require it, anonymisation can be applied to each frame in RAM before any clip is persisted. In all deployments, Darkfield retains events and short evidence clips, not continuous footage.
- UK GDPR by default: Darkfield is built to be UK GDPR-compliant out of the box. In most deployments you act as the data controller and Linox acts as your processor, governed by a Data Processing Agreement (DPA).
- Data residency: Processing and storage for UK customers remain within the United Kingdom.
- Retention and disposal: Retention windows are configurable. Data is securely disposed of at the end of its retention period and when a customer leaves the service.
- Zero-retention option: For sensitive deployments, a zero-retention mode processes events without persisting evidence clips.
- Identifiable individuals: Where a deployment may involve identifiable individuals — for example faces, or number plates checked against DVLA — in-memory anonymisation is available on request, and Linox supports customers in completing Data Protection Impact Assessments (DPIAs) and minimising what is captured.
6 · Access Control
Access to customer data and to the platform is granted on a least-privilege basis.
- Single sign-on and MFA: Support for SSO, with MFA enforced for administrative access.
- Role-based access control: Granular roles (administrator, user, and service accounts) ensure people and systems can only reach the data and functions their role requires.
- Customer-managed access: Customers manage their own users, the cameras each user can see, and how alerts are routed.
- Provisioning and de-provisioning: Access requires a documented request and approval before it is granted, and is promptly revoked on role change or departure.
- Audit logging and export: A comprehensive audit trail of user access and administrative actions is maintained and can be exported for integration into your own SIEM.
7 · Model Safety, Accuracy & Oversight
Because Darkfield decides what is worth a person's attention, the model itself is held to account.
- Self-QA: The system samples its own output on a rolling window and scores it against the data table agreed with you at onboarding.
- Automatic retraining: When precision drops below the agreed tolerance, a retrain is triggered automatically — per camera, on the actual scene — and the new weights are validated before they go live.
- Human oversight: Every change is recorded in an audit log. You can pause or override the system at any time.
- Scoped detection: Open-vocabulary detection is limited to what you define, and the Vision AI layer only flags events that match the agreed description. This reduces false positives and avoids unnecessary surveillance.
8 · Secure Development & Change Management
Changes to the platform are controlled, reviewed, and traceable.
- Development lifecycle: A formal software development lifecycle (SDLC) governs the development, acquisition, implementation, change, and maintenance of the platform.
- Change management: Changes to software and infrastructure are authorised, documented, tested, peer-reviewed, and approved before they reach production. Relevant changes are communicated to affected internal and external users.
- Vulnerability management: Defined procedures cover the identification, triage, and remediation of vulnerabilities within agreed service levels.
- Dependency security: Third-party dependencies are monitored for known vulnerabilities.
9 · Security Validation
Linox validates its controls through regular internal testing and review.
- Penetration testing: Penetration tests are conducted at least annually. Findings are addressed through a prioritised remediation plan.
- Control self-assessments: Linox performs control self-assessments at least annually to confirm that controls are in place and operating effectively, with corrective actions tracked to closure.
- Vulnerability and system monitoring: Continuous monitoring and a defined vulnerability-management process keep the platform under ongoing review.
- UK regulatory compliance: Linox operates under the UK GDPR and the Data Protection Act 2018 and designs deployments to support customers' obligations under the Surveillance Camera Code of Practice.
10 · Incident Response
Linox maintains a documented Incident Response Plan designed for rapid detection, containment, investigation, and resolution.
- Plan and ownership: A formal Incident Response Plan assigns clear ownership and defines escalation paths to leadership.
- Detection and alerting: Centralised log ingestion, analysis, and monitoring (SIEM) with automated alerting.
- Scope: The plan covers both traditional security events (such as unauthorised access or system disruption) and AI/product-safety events (model behaviour or output outside expected guardrails).
- Prioritisation and SLAs: Incidents are assigned a severity based on their impact to confidentiality, integrity, and availability, with critical incidents requiring rapid acknowledgement.
- Breach notification: Where personal data is affected, Linox supports notification to the ICO and to affected customers in line with the UK GDPR 72-hour requirement.
- Testing: The plan is tested through tabletop and technical exercises to ensure operational effectiveness.
11 · Reliability, Disaster Recovery & Business Continuity
Darkfield is designed to keep working through disruption.
- Disaster recovery: A Disaster Recovery Plan outlines a phased approach — assessment, recovery of temporary operations, and reconstitution to normal service.
- Business continuity: A Business Continuity Plan is maintained and tested at least annually.
- Redundancy: Cloud storage, databases, and load balancers are replicated to support high availability.
- Backups: Encrypted daily backups are retained for a defined period, integrity-checked, and tested.
- Edge resilience: Edge deployments continue to run perception locally if the connection to Linox is interrupted; events are buffered and synchronised when connectivity returns.
12 · Organisational & Personnel Security
Security depends on people as much as systems.
- Background checks: Performed on new employees where lawful.
- Code of conduct: Acknowledged by employees at hire; violations are subject to a disciplinary policy.
- Security training: Staff receive security awareness training.
- Device management: Endpoint and mobile devices are centrally managed through a mobile device management (MDM) system.
- Password policy: Enforced across in-scope systems.
- Roles and accountability: Roles and responsibilities are documented, and performance is reviewed.
13 · Security Controls Reference
The following controls are implemented and operated across the Darkfield platform and Linox's operations as of June 2026.
Infrastructure security
| Control | Description | Status |
|---|---|---|
| Unique production database authentication | Authentication to production datastores uses authorised secure mechanisms, such as unique SSH keys. | Implemented |
| Unique account authentication | Authentication to systems and applications uses a unique username and password or authorised SSH keys. | Implemented |
| Access control procedures | The access control policy documents the requirements for adding, modifying, and removing user access. | Implemented |
| Unique network system authentication | Authentication to the production network uses unique usernames and passwords or authorised SSH keys. | Implemented |
| Remote access MFA | Production systems can only be remotely accessed by authorised employees holding a valid MFA method. | Implemented |
| Remote access encryption | Production systems can only be remotely accessed via an approved encrypted connection. | Implemented |
Organisational security
| Control | Description | Status |
|---|---|---|
| Employee background checks | Background checks are performed on new employees where lawful. | Implemented |
| Code of conduct | Employees acknowledge a code of conduct at hire; violations are subject to a disciplinary policy. | Implemented |
| Performance evaluations | Managers complete performance evaluations for direct reports at least annually. | Implemented |
| Password policy | Passwords for in-scope system components are configured according to policy. | Implemented |
| MDM system | A mobile device management system centrally manages devices supporting the service. | Implemented |
Product security
| Control | Description | Status |
|---|---|---|
| Control self-assessments | Control self-assessments are performed at least annually, with corrective actions taken on findings. | Implemented |
| Data transmission encrypted | Secure protocols encrypt confidential and sensitive data transmitted over public networks. | Implemented |
| Vulnerability and system monitoring | Formal policies define requirements for vulnerability management and system monitoring. | Implemented |
| Data encryption utilised | Datastores housing sensitive customer data are encrypted at rest. | Implemented |
| Penetration testing | Penetration testing is performed at least annually, with remediation tracked to agreed service levels. | Implemented |
Internal security procedures
| Control | Description | Status |
|---|---|---|
| Continuity and disaster recovery plans | Business Continuity and Disaster Recovery Plans maintain information-security continuity if key personnel are unavailable. | Implemented |
| Change management | Changes are authorised, documented, tested, reviewed, and approved before production deployment. | Implemented |
| Development lifecycle | A formal SDLC governs development, implementation, change, and maintenance of systems. | Implemented |
| Management roles defined | Management has defined roles to oversee the design and implementation of information-security controls. | Implemented |
| Security policies | Information-security policies and procedures are documented and reviewed at least annually. | Implemented |
| Access requests required | User access is based on job role, or requires a documented access request and manager approval before provisioning. | Implemented |
| Incident response policies | Security and privacy incident response policies are documented and communicated to authorised users. | Implemented |
| Incident management | Incidents are logged, tracked, resolved, and communicated to relevant parties per the incident response policy. | Implemented |
| Risk assessments | Risk assessments are performed at least annually, considering threats, change, and the potential for fraud. | Implemented |
| System changes communicated | Customers are notified of critical system changes that may affect their processing. | Implemented |
Data and privacy
| Control | Description | Status |
|---|---|---|
| Data retention procedures | Formal retention and disposal procedures guide the secure retention and disposal of company and customer data. | Implemented |
| Data classification policy | A data classification policy helps ensure confidential data is secured and restricted to authorised personnel. | Implemented |
| Customer data deleted upon leaving | Customer data containing confidential information is purged from the application environment when customers leave the service. | Implemented |
14 · Contact
Linox is committed to providing a secure and privacy-respecting platform for every customer. We continuously monitor and improve our security practices as the platform grows.
For questions about this document, to request a Data Processing Agreement, or to discuss specific requirements such as DPIAs or air-gapped deployment, please contact our security team:
// © 2026 linox ltd · united kingdom