Data & retention

Your data belongs to you.

Everything your cameras and your people create in Vallaris belongs to your organization. Here is where it lives, how long it is kept, how your evidence is proven original, and how you take it all with you.

Effective October 4, 2026.

Your data is yours

  • Video, pictures, alarms, incidents, evidence, notes, reports and the audit trail all belong to your organization.
  • Vallaris stores and processes your data only to provide the service to you.
  • Vallaris never sells your data, and never shares it except with the service providers that run the platform (below).
  • Vallaris does not use your data to train AI models.
  • You can export everything at any time, and you decide how long it is kept.

Where your data lives

DataWhere
Video recordingsOn the SmartHub at your site
Live videoSent from your SmartHub to the operator watching it; not recorded in the cloud
Alarm and incident clips, snapshots, evidence files, case exportsCloud storage, copied there the moment they exist, so a stolen or damaged SmartHub never takes them with it
Alarms, incidents, events, notes, settings, usersCloud database
Audit trail and chain of custodyCloud database
  • The SmartHub connects outward only: no inbound firewall rules are opened at your site.
  • Video is never recorded continuously. Clips are recorded when your analytics detect an event, or when an operator asks for one.

How long it is kept

Your administrators set your organization's retention in the console (Settings → Data retention). The defaults:

DataDefaultYou can set
Video on the SmartHub30 days1 to 365 days
Alarm and incident files in the cloud30 days7 to 3,650 days
Records (alarms, incidents, events, notes)1 year30 to 3,650 days, never shorter than files
Audit trail1 year365 to 3,650 days
Anything you Keep, and any incident not yet closedUntil you stop keeping it—
  • Keep (a legal hold): mark an incident Keep and it is kept, with its alarms, clips, evidence and exports, whatever the schedule says, until your administrator stops keeping it. A single file or export can be kept on its own. An incident that is still open is always kept.
  • What is past your schedule and not kept is removed automatically, and each removal is recorded in your audit trail. A removed evidence file keeps its record: its name, its fingerprint, its chain of custody, and when it was removed.
  • On the SmartHub, the oldest video goes first if its disk runs low before the end of the schedule. Alarm and incident clips are already in the cloud by then.
  • Operating data that is not your content (device health and status) is kept for up to 30 days.

Evidence you can take to court

  • Every evidence file is fingerprinted (SHA-256) when it is stored, and the fingerprint is checked against the stored file. A clip also carries the fingerprint the SmartHub took when it recorded it.
  • Every view, download, export and removal of evidence is recorded in its chain of custody: who, and when.
  • Every evidence file and case export comes with a certificate signed by Vallaris. The signing key is held in a hardware security module: nobody, Vallaris included, can read or copy it. Old certificates keep verifying even if the key is ever replaced.
  • Video is never altered, not even with a visible stamp: changing it would change the very fingerprint that proves it is the original.
  • A case export holds a plain-language incident report, the original videos and pictures, and a page that plays them in any browser. The technical detail is in a separate integrity report for experts.
  • Anyone, including a court or the other side, can check a file at vallaris.ai/verify. The file is checked on their own computer and never uploaded.
  • Your administrator, or Vallaris on your behalf, can give a court's or the other side's technical expert a read-only link to one incident's full integrity detail. The link lasts 30 days, can be revoked at any time, and every use is recorded.

When your contract ends

  • For 30 days after your contract ends, your administrators can sign in and export everything: every record, and every stored file with its fingerprint. You can also export at any time before then.
  • After those 30 days, sign-in closes, and all of your data in the cloud is deleted within 90 days of the end of your contract. Vallaris keeps a record of what was deleted and when, and confirms the deletion in writing on request.
  • Video on a SmartHub is wiped when the SmartHub is returned or decommissioned.
  • You can ask for your data to be deleted at any time before your contract ends.

Service providers

Vallaris runs on a small number of infrastructure providers: hosting, database, storage, email and text-message delivery, and AI analysis of camera frames for alarm review and search. Each processes your data only to deliver its part of the service. The current list of providers, what each does and where it processes data is available on request; it changes as the platform's infrastructure changes.

Security

  • Encrypted connections (TLS) between your site, the cloud and every browser.
  • Passwords are stored only as salted hashes; stored keys and camera credentials are encrypted.
  • Every organization's data is kept apart, and that separation is tested on every change to the platform.
  • Access by role and by site, down to single cameras.
  • Two-factor sign-in.
  • An audit trail of every operator action.

Changes and questions

We will tell customers about material changes to this policy before they take effect. Questions, export or deletion requests, and requests for the list of service providers go to sales@vallaris.ai.