Security & Data Processing Overview

Last updated: October 1, 2025

1. Security Architecture

Nesher operates on a single-tenant logical architecture. Each Customer receives a dedicated, isolated instance. Video ingest is secured via RTMPS and WebRTC streams are encrypted end-to-end via DTLS/SRTP. Data at rest is encrypted using AES-256.

2. Audit Logging

The platform generates tamper-evident audit logs for all flight operations, remote control commands, configuration changes, and video access events. Logs cannot be modified by standard users and are retained indefinitely unless deleted by a super-admin.

3. Data Processing Agreement (DPA)

This section constitutes our Data Processing Agreement for the purposes of GDPR and similar privacy frameworks.

3.1 Role of Parties

The Customer is the Data Controller. Nesher is the Data Processor. Nesher will process Customer Data solely on documented instructions from the Customer.

3.2 Biometric and Video Data

Video streams and analytic outputs (including Face Recognition vectors and License Plate readings) are considered highly sensitive. The Customer is responsible for ensuring the lawful basis for collecting this data.

3.3 Subprocessors

Nesher uses top-tier cloud providers (AWS/GCP) as subprocessors for hosting. A 30-day notice will be provided to Customers before adding any new subprocessors.