How Safience Works on Your Campus
One sensor. One image. One question answered in 60 seconds: is the person entering this building a known threat or a known victim? Here is exactly how the architecture works, from edge capture to informed action.
Single encrypted JPEG face crop per entry event — no video, no audio, no continuous monitoring
From edge capture to human-verified, actionable alert delivered to campus police dispatch
Sensor, Platform, RAC, Data, and QAPLA layers — each independent with separate access controls
99.99%+ of individuals generate zero data — image deleted instantly upon no-match determination
Five Layers. Each Independent. All Privacy-by-Architecture.
Layer 1: Sensor Layer (RTIS/RVIS Edge Devices)
Dedicated edge sensors deployed at building entrances. Purpose-built hardware, not repurposed CCTV cameras. Single <100KB JPEG face crop per entry event. No video recording. No audio capture. No on-device watchlist storage. No on-device data retention. Images are encrypted, transmitted, and deleted from the device immediately. Power over Ethernet — single cable for power and data. A compromised sensor reveals nothing because it stores nothing.
Layer 2: Platform Layer (Matching Engine)
Cloud-hosted matching infrastructure where all identity comparison occurs. SOC 2-compliant. Encrypted in transit and at rest. Simultaneous RTIS threat and RVIS victim matching on every image. Non-match images deleted immediately upon no-match determination. No persistent storage of non-match data at any point in the pipeline. Peak bandwidth per sensor is measured in kilobytes per event, not megabytes per second.
Layer 3: RAC Layer (Human Verification)
The Rapid Action Center — a 24/7 staffed operations center where trained analysts verify every candidate match before any alert is generated. Analysts confirm visual match against source record. Verified matches generate documented alerts with analyst identification and timestamp. Rejected matches result in image deletion and zero notification. RAC analysts cannot access institutional data or student records. This step is mandatory, not optional.
Layer 4: Data Layer (UMbRA, X-LST, eMotive)
Three distinct data stores with separate access controls, separate purposes, and separate data handling rules. UMbRA provides 56.7M+ law-enforcement-sourced identities updated hourly. X-LST enables institution-controlled compartmented watchlists that Safience cannot see. eMotive delivers FCRA-compliant continuous criminal monitoring with patented dual face+name matching for workforce integrity.
Layer 5: QAPLA Layer (Investigative Tool)
A standalone, browser-based 1:1 facial image comparison tool for authorized investigators. Strictly 1:1 comparison — one reference photo vs. one trigger image. No database search, no one-to-many matching. Does not connect to UMbRA, X-LST, RTIS, or RVIS. Human-initiated, human-interpreted. Used by campus police investigators when they need to confirm whether a specific individual in one image is the same person in another image.
Network Impact and Deployment for Your CISO
Your CISO will ask three questions: how much bandwidth does this consume, how does it sit on our network, and how long does deployment take? Here are the answers.
-
Bandwidth and Network Load
Single <100KB JPEG per event (typical ~30KB). Encrypted transmission over HTTPS. No video or audio streaming. VLAN-segmented — sensors operate on a dedicated network segment isolated from campus production networks. A sensor generating 100 events per hour transmits approximately 3MB per hour total.
-
Peak Load Capacity
Athletic venue with 80,000 attendees and 20 gates: each gate sensor processes entries independently. Total bandwidth across all gates remains in the single-digit megabytes per hour range. No bottleneck. No queuing.
-
IoT Device Management
Purpose-built edge sensor, not a repurposed IP camera. Power over Ethernet (PoE). No on-device storage or watchlist data. Firmware updates managed remotely by Safience with no on-campus IT labor required. Tamper-resistant housing with indoor and outdoor models.
-
Zero On-Premises Infrastructure
No on-premises server infrastructure. No local database. No video management system. The entire Safience platform is cloud-hosted and SOC 2-compliant. Your campus provides network connectivity and physical mounting points. Safience provides everything else.
FERPA Data Flow Summary
| Data Flow Stage | Data Created | Data Stored | FERPA Classification |
|---|---|---|---|
| Edge Capture | Single <100KB face crop JPEG | None — image deleted from sensor immediately after encrypted transmission | Not an education record — no student identifier attached, no institutional maintenance |
| Platform Matching (Non-Match) | Comparison result: no match | None — image deleted immediately | Not an education record — data does not exist after deletion |
| Platform Matching (Candidate Match) | Comparison result: candidate match to LE record or institution watchlist | Temporarily held pending human verification | Not an education record — data relates to criminal history or institutional restriction |
| Human Verification (Rejected) | Verification decision: match rejected | None — candidate image deleted | Not an education record — no data retained |
| Human Verification (Confirmed) | Verification decision: match confirmed | Alert documentation with LE source data, timestamp, and analyst ID | Not an education record — documentation relates to criminal identity intelligence |
| Alert Delivery | Alert notification to authorized campus personnel | Alert record in audit trail | Not an education record — notification concerns criminal history or safety restriction |
60 Seconds from Campus Entry to Informed Action
Every Safience deployment — whether at a residence hall, an athletic venue, a research facility, or a child-care center — follows the same architecture and the same timeline. The scenario changes. The process does not.
-
Edge Capture
0:00An RTIS sensor at the building entrance captures a single face-crop image as an individual enters. Approximately 30KB, never exceeding 100KB. No video. No audio. No continuous monitoring. The sensor captures one image per entry event, encrypts and transmits it, and deletes it from the device immediately.
-
Platform Matching
0:05Two matching operations run simultaneously on every image. RTIS compares against UMbRA’s 56.7M+ law-enforcement-sourced identities and X-LST watchlists. RVIS simultaneously searches NCMEC, NamUs, and LE-designated missing persons. If no match: image deleted instantly. Zero data. Zero record.
-
Human Verification at the RAC
0:15A trained analyst at the Safience Rapid Action Center reviews and confirms the candidate match. No autonomous decisions. No automated alerts. This step is mandatory on every candidate match — RTIS, RVIS, and X-LST alike. False-positive liability is eliminated here.
-
Documentation
0:30A verified match is documented with the matched identity record, verification decision and analyst identifier, timestamp of detection, and supporting evidence sufficient for a defensible law enforcement response. This audit trail supports Clery Act compliance and litigation defense.
-
Informed Action
0:60A verified, documented alert is delivered to the appropriate campus personnel. Warrant matches route to campus police. Sex offender matches route to police and facility directors. X-LST matches route only to authorized personnel for that watchlist category. RVIS matches route to police with case details. Alert routing is compartmented — no cross-contamination.
See the Architecture. Ask the Hard Questions.
Schedule a Technical Architecture Review with your CISO, General Counsel, and Chief of Campus Police in the room. Walk through the data flows, the privacy architecture, the network specifications, and the FERPA alignment documentation. We built this platform for the people who ask the hardest questions. Bring yours.