Skip to content
BLUEURAL

Trust &
privacy.

We are asking you to put a monitoring device on your network. That deserves a straight account of what the product does with your data, and what we have not built yet.

How your data is handled

On-premise processing

Traffic and logs are analysed on the appliance inside your network. Raw packet data and video are not sent off-site, which keeps the sensitive material where it already lives.

Encrypted in transit and at rest

Data sent to the management platform travels over TLS with per-device certificates. Logs held on the appliance are encrypted on disk.

Minimal collection

We collect network metadata and alert context — not user documents, message contents or credentials. If it is not needed to explain an alert, we do not want it.

Product and platform security

Signed firmware and secure boot

Appliances verify signed images before boot, and OS and dependency patches are shipped as part of the subscription.

Vulnerability handling

We track advisories affecting our stack, including NVIDIA Jetson platform bulletins, and notify affected customers when a fix matters to them.

Compliance direction

ISO 27001 certification is on our roadmap rather than in hand today. We build on vetted open-source components so our stack can be inspected.

What Blueural does not claim

Security marketing tends to imply completeness. Being clear about the boundaries is more useful to you than another guarantee.

  • No system prevents every breach. Blueural narrows the window between compromise and discovery — it does not eliminate it.
  • Monitoring is not compliance. Our logs and reports support an audit, but they do not by themselves satisfy any standard.
  • Deep packet inspection of personal traffic is not the design. Sessions are treated as metadata, and you remain responsible for informing staff as local law requires.
  • We are not a managed service. Alerts arrive with context and next steps, but somebody at your end still decides what to act on.

Policies and governance

Privacy policy

What personal data we hold, why we hold it, and how to have it removed.

Read it →

Terms of use

Licence scope, customer responsibilities and limits of liability.

Read it →

Incident response

Containment first, then root cause, then notification to anyone affected.

Read it →

Responsible disclosure

If you find a vulnerability in anything we build, we want to hear about it before anyone else does. We aim to acknowledge reports within two business days, keep you updated while we work on a fix, and credit you publicly if you would like that.

  • Give us reasonable time to ship a fix before disclosing publicly
  • Do not access, modify or delete data belonging to others while testing
  • Include enough detail for us to reproduce the issue
Report a vulnerability