Trust &
privacy.
We are asking you to put a monitoring device on your network. That deserves a straight account of what the product does with your data, and what we have not built yet.
How your data is handled
On-premise processing
Traffic and logs are analysed on the appliance inside your network. Raw packet data and video are not sent off-site, which keeps the sensitive material where it already lives.
Encrypted in transit and at rest
Data sent to the management platform travels over TLS with per-device certificates. Logs held on the appliance are encrypted on disk.
Minimal collection
We collect network metadata and alert context — not user documents, message contents or credentials. If it is not needed to explain an alert, we do not want it.
Product and platform security
Signed firmware and secure boot
Appliances verify signed images before boot, and OS and dependency patches are shipped as part of the subscription.
Vulnerability handling
We track advisories affecting our stack, including NVIDIA Jetson platform bulletins, and notify affected customers when a fix matters to them.
Compliance direction
ISO 27001 certification is on our roadmap rather than in hand today. We build on vetted open-source components so our stack can be inspected.
What Blueural does not claim
Security marketing tends to imply completeness. Being clear about the boundaries is more useful to you than another guarantee.
- No system prevents every breach. Blueural narrows the window between compromise and discovery — it does not eliminate it.
- Monitoring is not compliance. Our logs and reports support an audit, but they do not by themselves satisfy any standard.
- Deep packet inspection of personal traffic is not the design. Sessions are treated as metadata, and you remain responsible for informing staff as local law requires.
- We are not a managed service. Alerts arrive with context and next steps, but somebody at your end still decides what to act on.
Policies and governance
Responsible disclosure
If you find a vulnerability in anything we build, we want to hear about it before anyone else does. We aim to acknowledge reports within two business days, keep you updated while we work on a fix, and credit you publicly if you would like that.
- Give us reasonable time to ship a fix before disclosing publicly
- Do not access, modify or delete data belonging to others while testing
- Include enough detail for us to reproduce the issue