Getting Started Cameras & Video Detection & Recording Automation & Events Actions Integration & Connectivity Network & Discovery AI & Remote Control MQTT Modbus Pi4J & Raspberry Pi GPIO ZeroMQ System & Administration Comparisons Use Cases Troubleshooting About & Legal
Home / Documentation / Security at Banalytics
Company Security

Security at Banalytics

A local-first architecture for systems that interact with the physical world.

Banalytics is designed so that recordings, telemetry, device credentials, and operational decisions can remain under the control of the person or organisation that owns the equipment. This page describes the security boundaries of the product and how to report a concern.


Local infrastructure remains the source of truth

Banalytics is an edge platform. Its Agent runs on a host selected and controlled by the owner of the physical infrastructure. Cameras, sensors, industrial devices, local files, recordings, telemetry and device-side integrations are configured and operated at that edge location. Banalytics does not require those operational data sets to be copied into a central Banalytics cloud in order to work.

This design does not eliminate the need for local security. The owner remains responsible for the security of the Agent host, the local network, connected equipment, administrator accounts, stored recordings, device credentials, operating-system updates and any third-party services connected to the deployment.

Portal coordination is separate from operational traffic

The Banalytics Portal keeps the limited account, environment-registration and connection-signalling information required to link an authorised user with an Agent. When a user connects to an Agent through the portal, the browser and Agent establish an isolated WebRTC communication channel. The payload exchanged through that channel is not routed through Banalytics infrastructure.

In practical terms, Banalytics infrastructure is not the default repository for a customer’s video, sensor telemetry or device-control traffic. The owner chooses which users may access an environment and which components, dashboards or integrations are exposed. See Portal integration and Access sharing and peer-to-peer communication for the technical model.

Account and application access

  • Restricted portal areas require an authenticated user session.
  • Portal accounts can use password-based sign-in or supported identity-provider sign-in. Password credentials are stored using BCrypt password hashing.
  • Role-based restrictions are used for privileged portal functions.
  • Environment owners control sharing and should remove access that is no longer required.

The Portal stores account, registration, licensing and availability metadata for an Agent, but does not configure customer equipment or receive device credentials, per-component settings, locally produced video or telemetry. The connection service cannot obtain those data by itself. To use an Agent, a user must authenticate directly with the Agent by entering its access code; the service that coordinates the connection does not know that code. An Agent therefore remains under the access rules set by its owner, even when a browser-to-Agent connection is established through the Portal.

Access to a Banalytics environment can be powerful: it may expose live information or trigger actions configured by the owner. Use unique passwords, keep access groups small, revoke obsolete shares, and protect the devices and networks on which Agents run.

On-premise deployment and data location

For municipalities, industrial operators and other organisations that require exclusive control, Banalytics can be deployed on premises. In this model the organisation controls the servers, network boundaries, storage, identities, backups and integrations. It can selectively connect parts of its infrastructure to another organisation or city only when it chooses to do so.

The hosted Portal is not presented as a fixed data-residency service or a central store for operational data. We do not publish a permanent list of hosting providers or a blanket region guarantee on this page. For a specific planned deployment, contact us before production use to discuss the applicable architecture, hosting and data-processing details.

Current security programme

Banalytics is an early-stage company. We do not currently claim ISO 27001, SOC 2, a bug-bounty programme, a fixed incident-response SLA, or recurring independent penetration tests. We prefer to state the controls and boundaries that exist rather than imply a certification or process that is not in place.

Security improvements are made through normal product and infrastructure work. We will update this page when a material change affects the security model or the commitments described here.

Report a security issue

Please report suspected vulnerabilities to info@banalytics.live with the subject Security report. Include a clear description, affected URL or component, steps to reproduce, potential impact and any safe proof of concept. Do not include credentials, personal data, recordings or other sensitive payloads unless we specifically request them through an agreed secure channel.

Please do not disrupt services, bypass access controls, access another person’s data, or run destructive or high-volume testing. We do not currently operate a public bug-bounty programme. We will review good-faith reports and may ask follow-up questions to validate and remediate the issue.

Security and privacy questions

For deployment-specific questions, contact info@banalytics.live. Please also read our Privacy Policy and Terms of Service.

Last updated: 20 July 2026.