Skip to content
IRIS NEURALContact
Back to capabilities

Can you prove who watched that video, and when?

Who sees what, who did what, and how you prove it afterwards

A video system gathers the most sensitive material an organisation holds: people, number plates, comings and goings, working hours. Buying it is not enough. Months later you have to be able to explain who saw what, and why. IRIS starts there. Everyone signs in with their own account and sees only their part, and everything they do is written into a log that cannot be altered. Not even by an administrator.

At a glance

What it can do

  • Who sees which camera

    315 permissions across 66 modules, granted and withdrawn one at a time. Access can cover a whole site, a single camera or one investigation, with an expiry date.

  • And when they can log in

    Each person gets a window of days, hours and months. Outside it they cannot get in, and the screen says why. Signing in takes a second factor, and open sessions are visible and can be closed.

  • A log that cannot be edited

    Every action is written down and tied to the one before it by a fingerprint. Alter one entry and the chain breaks, and the screen names the entry and the date.

  • What you hand over is signed

    The log exports to a spreadsheet, an interchange file or a formal report, always with its fingerprint inside. Whoever receives it can check nothing was touched. The export itself is logged too.

  • Unmasking takes two people

    Private areas are blacked out for everyone. Revealing them needs a written reason, a second person to approve it and a time limit. Who, when and why is all on the record.

  • Every record with its own clock

    Video, logs and personal data do not last the same. Each type carries its own term with the legal basis written beside it, runs on its own overnight and leaves a record of what it deleted.

  • Knowing before you need it

    The screen tells you which camera has had no image for two days and which one nobody is watching. And when something has not been measured, it says so instead of painting it green.

  • Everything through one port

    The whole system is administered from the browser: no configuration files, no logging into the server. Everything travels over port 443, and the models and maps are our own, so it works with no internet.

  • Eight profiles, ready made

    Administrator, operator, auditor, supervisor, technician, validator, compliance officer and data protection officer all come ready made. Nobody builds the permission model from scratch: you take one, duplicate it and trim it.

  • Exactly what gets written down

    27 details for every action: who, what, on what, from which address and with which program, how it looked before and after, whether it worked or was denied, and a plain sentence for someone who does not know the system.

  • The seven rights, answered

    Access, rectification, erasure, restriction, portability, objection and automated decisions each have their screen, their clock and their warning before the deadline. And anyone files their own and downloads their data from their own profile.

  • No command line

    1,524 configuration values across 44 services, all from the browser and all logged with who and when. There are no files to edit and no server to log into: running this does not take a specialist.

The part that answers a tender

What you need to be able to show when somebody asks

A permission is not one big switch. IRIS splits 315 permissions across 66 modules, granted or withdrawn one at a time: you decide who sees which camera, who exports video and who can do nothing but watch. Eight profiles come ready made — administrator, operator, auditor, supervisor, technician and a few more — and anyone who needs a different one duplicates it and trims it, without limit. Above the permission sits the scope: which site, which camera, which case, with an expiry date and a warning a week before it runs out. And one rule is printed on the screen itself: if a group denies something, that denial always wins, even when the profile grants it. That is what lets you hand out a broad profile and trim it for one team without inventing a new one.

The audit log only accepts additions: once written, it is not touched. That is not a promise made by the software, it is a rule of the data store itself, which refuses any attempt to change or delete an entry by hand, no matter who tries. Each entry keeps 27 details — who, what, on what, from which address, how it looked before and how it looked after — and is tied to the previous one by a fingerprint. In a working installation that adds up to 489 distinct actions on record: sign-ins and sign-outs, permission changes, a recording opened, a camera moved, exports, configuration changes. One button walks the whole chain and answers whether it is intact, or at which entry and on which date it broke. The log is also sealed period by period, so that two years from now today's state can still be checked.

Personal data is handled by type, not in one lump. Each table carries its own term with the legal basis written beside it, and a nightly pass applies them on its own and leaves a trace of what it deleted; before arming it you can run a dry run, which deletes nothing and shows what would go. The seven requests a person can file — access, rectification, erasure and the rest — each have their screen, their deadline and their warning as that deadline nears, and any user files their own from their profile. A data breach opens with its 72-hour clock in plain view, and the dashboard flags the ones that have run past it. Private areas of a camera are black for everyone, and revealing them takes a written reason, a second person to approve it and a limited window. Biometric data has its own term, separate from video, and the screen states in writing that extending it increases legal exposure, instead of letting it stretch with nobody saying a word.

Compliance is kept as a list, not as a speech. There are the 79 controls of the Spanish national security framework at its high level and the 93 controls of annex A of ISO 27001, each with its status, its evidence, the date of the last review and who carried it out; the two frameworks are cross-referenced, so a single statement of applicability answers both audits. There is also a register of the artificial intelligence systems in use and a queue where a person reviews the machine's decisions and confirms, overrides or escalates them. And it is worth saying what this is not: IRIS is designed to help you meet those frameworks, but it is not certified or approved under any of them. It is the organisation running the system that gets certified, with its own processes and premises; what the product supplies is the evidence to get there. The one third-party approval we do hold is for people counting, granted by the Spanish Centre for Metrology.

The breakdown that costs money is the one you discover on the day you need the video. So there is a panel that sorts every camera — connecting, no image, switched off on purpose, not measured, not being watched — and says how long it has been like that, how many outages it has had in the last 24 hours and the last seven days, and how long the worst one lasted. Services and servers work the same way: when something fails you do not get a red icon, you get the reason written out, and that reason tells apart it is not running, it has gone hours without refreshing, it answers but produces nothing, and it was switched off on purpose. There is also a diagnostic that hunts the silent faults, the ones that never raise an error: two services fighting over the same port, a database change never applied, a watchdog that has stopped. And one decision says a lot about the product: when something has not been measured, the screen does not paint it green. No faults found is not the same as could not be checked, and here the two are told apart.

All the configuration lives inside the system and is handled from the browser: 1,524 values across 44 services — cameras, storage, network, retention, languages and time zones — with not one file to edit and no server to log into. Every change records who made it and when, and every setting is documented inside the platform itself: what it governs, in which unit, what its default is and what happens if you set it to zero, which does not always mean unlimited. The certificate inventory is cut from the same cloth: it lists them all, warns about the ones about to expire and raises two warnings on its own that almost nobody prints in a brochure: that the system is being served with the factory certificate, the same one in every installation, and that some of the machine's addresses appear in no certificate at all. Renewing one asks for the administrator's password again, because having a session open is not enough to replace a certificate, and a copy of what was there is kept before anything is touched. Small details, and exactly the ones you miss six months in.

The figures

Counted, not estimated

  • 315permissions across 66 modules, granted and withdrawn one by one
  • 489distinct actions written into the audit log
  • 79controls of the Spanish national security framework, with their evidence
  • 443the only port you have to open in the firewall
  • 27details the log keeps every time somebody does something
  • 1,524configuration values across 44 services, all from the browser

Questions

Is IRIS certified under the national security framework or ISO 27001?

No, and no piece of software can be certified on your behalf: it is the organisation running the system that gets certified, with its own processes, staff and premises. What IRIS does is arrive designed to help you meet those frameworks with the groundwork already done: the 79 controls of the Spanish national security framework at its high level and the 93 of annex A of ISO 27001, each with its status, its evidence and its review date, cross-referenced so the same task is not done twice. We say it that way instead of showing you a badge: the difference shows up in the first audit. The one third-party approval we do hold is for people counting, granted by the Spanish Centre for Metrology.

Can an administrator erase the trace of what they did?

No. The audit log only accepts additions, and that rule is not enforced by the program but by the data store itself: any attempt to change or delete an entry by hand is refused, whatever permissions the person holds. The only thing that deletes is the retention policy the organisation has declared, and that purge is logged too, with the policy applied, how many entries went and who triggered it. On top of that, each entry carries the fingerprint of the previous one: if somebody reached underneath and touched the data, the chain would break, and the verification screen would name the entry and the date it happened.

Can I give an outside contractor access to a few cameras for a few days only?

Yes, and that is the normal case. Access is granted per camera, per site — with everything below it or without — or per investigation, always with an expiry date; the screen warns on its own about grants running out in the next seven days. On top of that you can add a time window: outside it the person gets a plain message and does not get in. Revoking requires a reason, and the grant keeps who gave it, when, why, who took it away and for what reason. That is how a temporary access closes instead of staying open forever because nobody remembered.

What happens when someone leaves the organisation?

The account is deactivated, and that is reversible in case they come back. Their open sessions are revoked at once: credentials already in circulation stop working without waiting to expire, so nobody stays inside until some record runs out. The grants they held over sites or cameras are revoked with a mandatory reason, and the access keys their programs used are cut off, keeping who removed them. What does not leave with the person is their trail: the log still shows what they did while they were there. And if they also exercise their right to erasure, the deletion is handled as a request, with a grace period before it becomes final, and anonymisation replaces the personal data inside the entries, leaving the chain intact and counting how many were anonymised: the log goes on proving what happened without keeping who it was.

How do you prove to a third party that the log has not been touched?

With three things you can hand over. The first is the integrity check: it walks the whole chain and answers intact, or points at the exact entry and date where it breaks. The second is the signed export — spreadsheet, interchange file or report — which carries the signature inside the file itself, so whoever receives it checks for themselves that nothing was touched, without trusting us or you. The third are the anchors and the period seals, which fix the state of the log on a given date so it can be checked against years later. And it comes with a warning we put in writing on the screen itself: entries written before chaining was switched on are declared as such, with how many there are and why they cannot be verified. We would rather say it ourselves than have the expert witness find it.

The real interface, step by step

You set the rule once. IRIS applies it every time.

You will see a summary of the interface, played step by step and hands-free. Each round starts with another case. The complete tool does not fit in a demo.

  1. Checks the whole system
  2. Flags what is failing
  3. Puts it on one screen
IRIS NEURAL
30ES
IRISDirectoGrabacionesGISIncidencias3996SituaciónCasosLPRAutomatizacionesIRIS DATA
Ask a question or make a request…Send
IRIS · Infinity Neural

And the best part

We would rather promise less.Let the first week be the surprise, not the brochure.

What it cannot do gets said on day one, not on the last day. A short list that holds beats a long one that falls apart the moment it is switched on.

Tell us your problem and we will say whether IRIS understands it, or not yet.

We reply the same working day.