Solution

Two types of data
Oddity uses

Metadata

Metadata

Log and monitoring data, confidence scores, and performance metrics. Always numeric/textual; never image or video; never personal information. Stored for diagnostics.

  • No images/video
  • No personal data
Alert video clips

Alert video clips

Short clips only when an alert occurs; may contain PHI under HIPAA. Default retention is 30 days (silent phase and normal ops), and can be reduced per customer policy. VMS storage is customer-controlled.

  • Contains PHI
  • Strict retention

Oddity.ai adheres to
strict security policies

Encryption

Encryption (in transit & at rest)

In transit: IPSec VPN; TLS between services; SSH (AES) for maintenance.

At rest:AES-256 for Google Cloud; All data is transmitted and stored encrypted.

Authentication & authorization

Authentication & authorization

  • Google Cloud access via OAuth 2.0 + mandatory 2FA, least-privilege access.
  • Tailscale SSH (OAuth 2.0; identity-based, ACL-managed).
  • VMS/RTSP authentication per platform (For example: Digest authentication for RTSP).
  • Microsoft Teams: Secure API authentication.
HIPAA & BAA

HIPAA & BAA

Oddity signs a BAA upon request and implements required administrative, physical, and technical safeguards; breach notification and mitigation; subcontractor controls; and access/amendment processes for PHI. For more information, visit Privacy & HIPAA alignment.

Privacy by design

Privacy by design

Security and privacy are built into the product lifecycle to ensure high availability and protection of sensitive data.

Cloud platform security

Cloud platform security

Hosted on Google Cloud Platform with isolated per-customer VPCs. Google Cloud provides state-of-the-art security and aligns with HIPAA and SOC 2 Type II.