Built to be inspected
Designed for critical-infrastructure and public-sector environments: conservative data handling by default, and alignment work you can verify, stated as readiness, not certification.
| Claim | What it means |
|---|---|
| NDAA §889 / TAA hardware posture | EXCOM ships software only, designed to run on compliant camera and compute hardware procured by the customer, for example Axis, Hanwha Vision, Bosch, Pelco cameras and NVIDIA Jetson edge compute. |
| Non-biometric by default | No facial recognition. Multi-camera continuity uses pseudonymous, appearance-based identity that is ephemeral by design. |
| Metadata-only edge egress | Raw video stays on site. Only event metadata (detections, tracks, incidents) leaves the edge node. |
| Customer owns the deployment | On-premises, air-gapped, or in the customer’s own Azure Government / AWS GovCloud subscription. EXCOM operates no cloud that holds your data and has no standing access to it; any support access is customer-authorized and audited. |
| Access control & audit | Role-based access control and a tamper-evident audit trail over incidents, evidence, and operator actions. |
| NIST alignment | NIST Cybersecurity Framework mapping and an NIST SP 800-171 readiness crosswalk are maintained as living engineering artifacts, available under a briefing. |
Data handling, in one paragraph
EXCOM preserves operational control at the site level. Deployments run within customer-controlled infrastructure, keeping video inside the operational environment while sharing only authorized security metadata. The platform is non-biometric by default and provides role-based access control with an auditable record of every incident and operator action.
Want the detail?
The compliance briefing pack covers the control set, the readiness crosswalks, and the shared-responsibility model.