Built to pass your toughest review
Safety data is sensitive by definition: incidents, health signals, video. Here is how ECSafety protects it, and the answers your IT and legal reviewers will ask for.
SOC 2 Type II
Independently audited controls for security, availability, and confidentiality. Report available under NDA.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest. Secrets managed in cloud KMS; no credentials in code or config.
Role-based access
Row-level security in the database itself. Users, and Aura answering them, see only what their role allows.
Edge-first video
Camera Hub and the AI Hub process footage on your network. Raw video never has to leave your site.
Responsible AI
Aura is grounded in your data, cites its sources, never trains external or public models on Customer Data, and keeps humans in charge of safety decisions.
Your data, portable
You own your Customer Data. Export any time via CSV and API. Retention follows your settings, deletion on request.
Where is our data hosted?+
In AWS (us-west-2 primary), isolated per customer with row-level security. Camera detections can run entirely on-premise via the AI Hub, in which case raw footage never leaves your network.
Does Aura train on our data?+
No. We do not use your Customer Data to train external or public AI models. Aura's answers are grounded in your own documents and records at question time, with citations, and are covered by your organization's retention controls.
Which third-party AI providers are involved?+
Some Aura features run on foundation models from third-party providers under contracts that prohibit training on your data. The current subprocessor list is available on request at privacy@ecsiteapp.com.
How does authentication work?+
SSO/SAML is supported for enterprise plans, alongside per-user accounts with MFA. Sessions are short-lived and refreshable; API access uses scoped tokens.
What happens to our data if we leave?+
You can export everything (forms, incidents, media, audit trails) via CSV and API. On termination we delete Customer Data on your instruction, per the retention schedule in your agreement.
How is worker privacy handled for wearables?+
Wearable data is session-scoped by design: vitals and motion are read only during active Lone Worker sessions the worker starts, are visible only to roles your organization allows, and are used only for safety escalation.
Can you support strict data-residency or no-cloud-video policies?+
Yes. That is what the AI Hub is for: detection happens on-premise, only configured event metadata reaches the cloud, and your DPA covers exactly what leaves the site.
Deeper questions? Security review packets, the subprocessor list, and our DPA are available at privacy@ecsiteapp.com.
Bring your security team to the demo.
We'd rather answer the hard questions on day one.
No credit card required · Deploys in days · SOC 2 Type II
