Built to be inspected

Designed for critical-infrastructure and public-sector environments: conservative data handling by default, and alignment work you can verify, stated as readiness, not certification.

ClaimWhat it means
NDAA §889 / TAA hardware postureEXCOM ships software only, designed to run on compliant camera and compute hardware procured by the customer, for example Axis, Hanwha Vision, Bosch, Pelco cameras and NVIDIA Jetson edge compute.
Non-biometric by defaultNo facial recognition. Multi-camera continuity uses pseudonymous, appearance-based identity that is ephemeral by design.
Metadata-only edge egressRaw video stays on site. Only event metadata (detections, tracks, incidents) leaves the edge node.
Customer owns the deploymentOn-premises, air-gapped, or in the customer’s own Azure Government / AWS GovCloud subscription. EXCOM operates no cloud that holds your data and has no standing access to it; any support access is customer-authorized and audited.
Access control & auditRole-based access control and a tamper-evident audit trail over incidents, evidence, and operator actions.
NIST alignmentNIST Cybersecurity Framework mapping and an NIST SP 800-171 readiness crosswalk are maintained as living engineering artifacts, available under a briefing.

Data handling, in one paragraph

EXCOM preserves operational control at the site level. Deployments run within customer-controlled infrastructure, keeping video inside the operational environment while sharing only authorized security metadata. The platform is non-biometric by default and provides role-based access control with an auditable record of every incident and operator action.

Want the detail?

The compliance briefing pack covers the control set, the readiness crosswalks, and the shared-responsibility model.