Zero raw-footage upload — data sovereignty protected by a zero-trust architecture
Purpose-built for agencies with strict security requirements. Kaster runs an on-prem-first architecture: master files never touch the cloud and stay in your own facility at all times. AI-powered search works without opening a single inbound firewall port, so security review clears on the first pass.
Zero upload, zero exposure — security review clears on the first pass
Data sovereignty stays entirely in your hands
Raw audio/video files stay in your own facility at all times — never uploaded to the cloud, never leaving your control. Physical custody and ownership of the data remain yours throughout.
Zero attack surface — security review clears on the first pass
The Edge Agent used for analysis can only initiate outbound connections; no inbound port needs to be opened, meeting agency requirements for a "zero-trust, minimal exposure" security posture.
Auto-purged after use, every step auditable
Temporary analysis data in the cloud compute environment is automatically purged within 30 days — no copy of the original content is retained, and every access is traceable for audit.
Model isolation — never used for third-party training
Audio summaries, keyframes, and semantic embeddings uploaded to the cloud are used solely to build a dedicated search index for your agency. They are never retained, and never used to train models for other customers or third parties unrelated to your organization.
A spec sheet your security lead can verify at a glance and defend under audit
| Time | Action | Actor | Status |
|---|---|---|---|
| 2026-06-11 15:32:24 | Semantic search query | Archive retrieval staff | Authorized |
| 2026-06-11 15:13:37 | AI derivative upload for analysis (not raw footage) | Edge Agent | Authorized |
| 2026-06-11 15:13:35 | Temporary data lifecycle purge | System (automatic) | Completed |
- Connection direction
- Outbound only: the Edge Agent only initiates outbound HTTPS (443) connections. Your firewall never needs to open an inbound port — there's no entry point for an external scan to find, so there's nothing for an attacker to break into.
- Derivative transfer authorization
- Presigned URLs, each valid for a single one-hour window and expiring automatically — one key, one single use. This dynamic, time-boxed authorization model closes off the risk of a leaked static link or misuse at the physical time-limit level.
- Data retention
- Non-sensitive derivatives (audio summaries, keyframes, and semantic embeddings only) are automatically deleted from the cloud under a lifecycle policy — purged as soon as analysis completes, with no permanent retention. You never end up with an unaccounted-for copy of your data sitting somewhere.
- Raw files
- Stored exclusively on the customer's own storage infrastructure (NAS / on-prem servers) — no copy is retained or uploaded on the system side. Ownership and control of the data remain yours throughout.
- Trust boundary
- Raw video never crosses the on-prem transmission path at all, eliminating leak risk at the physical architecture level — this boundary doesn't rely on trust to hold, because there's no path across it to begin with.
* The review takes just 15 minutes and is a purely technical discussion; during POC validation we commit to not requiring any changes to your on-prem firewall or network configuration.
What you might still want to know about security compliance
Q1Has Kaster passed third-party security certifications like SOC 2 or ISO 27001?
Kaster's core product runs an on-prem-first architecture: raw sensitive files never leave your facility and are never backed up to the cloud, eliminating cloud-storage exposure at the source. We have not yet obtained third-party audit certification; whether to pursue one is evaluated based on customer needs and project planning.
Q2Does our internal firewall need to open any outbound connection channel to deploy Kaster?
No. The Edge Agent uses an outbound-only connection model, initiating only outbound HTTPS (443) connections. No inbound port needs to be opened — there's no entry point for an external scan to find, so there's nothing to break into.
Q3Are the derivatives uploaded to the cloud ever used to train models for other customers or third parties?
No. Derivatives are used solely to build a dedicated search index for your agency's archive. Temporary cloud data is automatically deleted under a 30-day lifecycle policy and is never retained or used to train models unrelated to your organization.
Q4Is there a data leak risk if a Presigned URL is exposed?
We use a dynamic, time-boxed authorization model. Each Presigned URL is valid for a single one-hour window and expires automatically, and each key maps to a single use — closing off the risk of a leaked static link or misuse at the physical time-limit level.
Q5How can our security team verify access records and the audit trail?
Every semantic search query, derivative upload, and temporary data purge is logged in the access log, which your security team can review and cross-check at any time to confirm that every step is accounted for.