GC SurgeDocumentation

Security and Data Retention Policy

On this page
  1. Summary
  2. Security controls
  3. Data retention

Summary

Genie URL: gcsurge-docs.nxgen.cloud/gcsurge/doc…/security-and-data-retention-policy

This page summarizes the security controls and data-retention behavior that customers most often ask about during onboarding, legal review, and operational governance. Covers: Security controls, Data retention.

Security controls

  • Encrypted transport — all platform traffic is encrypted in transit using TLS 1.2 or higher.
  • Encryption at rest — credentials and sensitive data are stored encrypted at rest (AES-256).
  • Role-based access control — access is controlled at the application layer based on each user's assigned role.
  • Authenticated agents — field and edge components authenticate to the platform using signed tokens before they can send data.
  • Tenant isolation — each customer's users, sites, and camera data are isolated from every other tenant.

Data retention

GC Surge retains data for the following default periods:

Data typeDefault retention
Alarm dataMinimum 12 months
Audit logsMinimum 12 months (write-once — not editable or deletable)
Billing recordsMinimum 7 years
Video snapshots90 days (configurable)

GC Surge does not provide long-term video storage. Only the snapshots attached to alarms are retained, for 90 days; full video retrieval requires your own NVR/VMS. Where a retention period in your service agreement differs from these defaults, your agreement takes precedence.

Was this page helpful?

Thank you — your feedback goes to the team that owns this page.

Release notes

Know when something ships

New features, fixes and integration updates for GC Surge, delivered to your inbox as they are released.

We send a confirmation link first. Every message has an unsubscribe link.