generated: '2026-09-02' method: searched source: >- https://veesion.io/en/our-solution/, https://veesion.io/en/about/our-technology/, https://veesion.io/en/privacy-policy/, https://veesion.io/en/legal/ name: Veesion conformance description: >- Standards and regulatory conformance Veesion states on its own public pages. Veesion publishes a data-protection posture (EU GDPR / French Loi Informatique et Libertes, CNIL as supervisory authority, SCCs for third-country transfers) and asserts that its models perform no biometric identification. It publishes NO third-party certification — no SOC 2 report, ISO 27001 certificate, PCI DSS attestation or trust center was found on any Veesion host, and probe-security-programs.py returned no trust center and no vulnerability-disclosure programme. Because there is no published machine-readable contract, none of the contract-borne conformance signals (OAuth2/OIDC metadata, RFC 9457 problem+json, pagination, idempotency) can be asserted either way; they are recorded as unknown rather than false. conformance: - id: gdpr name: EU General Data Protection Regulation (Regulation 2016/679) conforms: true evidence: type: published-claim url: https://veesion.io/en/privacy-policy/ status: 200 quote: >- "undertakes to comply with the provisions of Regulation 2016/79, known as the 'GDPR', Law No. 78-17 known as the 'Data Protection Law' currently in force" note: >- Privacy policy names the CNIL as supervisory authority and states third-country transfers are framed by European Commission standard contractual clauses under GDPR Article 46. - id: gdpr-product name: GDPR-compliant product claim (no biometric identification) conforms: true evidence: type: published-claim url: https://veesion.io/en/our-solution/ status: 200 quote: >- "A secure, GDPR-compliant product" / "No biometric identification of individuals by our RGPD-compliant algorithms" note: >- Reiterated on https://veesion.io/en/about/our-technology/ (200): "ensuring safe and respectful surveillance, in full compliance with the GDPR and in line with the ethics of AI". - id: soc2 name: SOC 2 conforms: false evidence: type: absent url: https://veesion.io/en/ status: 200 note: >- No SOC 2 claim on any page of the English site; no trust center found on veesion.io, trust.veesion.io or portal.veesion.io. - id: iso-27001 name: ISO/IEC 27001 conforms: false evidence: type: absent url: https://veesion.io/en/about/our-technology/ status: 200 note: No ISO 27001 certification claimed anywhere on the public site. domain_standards: - id: onvif name: ONVIF (IP video interoperability profiles) market: retail video surveillance / VMS-CCTV integration declared: unknown evidence: type: no-contract url: https://veesion.io/en/our-solution/ status: 200 note: >- ONVIF is the domain standard for this market and Veesion integrates with a store's existing CCTV, but the company publishes no contract, integration guide or partner technical page in which a profile could be declared, so conformance cannot be read either way. Recorded as unknown, never inferred. Reward-only check: absent evidence is not a penalty. contract_borne_signals: status: not-assessable reason: >- No OpenAPI, AsyncAPI, GraphQL SDL, WSDL, protobuf or Postman collection is published on any Veesion-controlled host, so oauth2/oidc metadata, RFC 9457 error format, pagination and idempotency conventions cannot be read from a contract.