Security & privacy

How Vitals AI handles data and privacy

Camera-based vitals raise an obvious question: what happens to the video? Here is how a Vitals AI scan is processed, and what that means for privacy.

On this page

The short answer

Vitals AI processes video on the device where it is captured. During standard scan processing, frames are analysed locally and raw video is not uploaded or stored. Only derived results are sent to the platform. Data is encrypted in transit and at rest. Controls are designed to support HIPAA, GDPR, LGPD, POPIA and APP alongside SOC 2 and ISO 27001*.

For how scan data is technically captured and integrated, see the SDK and integration page; for the research and evidence behind the model, see Vitals AI research.

How a scan is processed

The technique behind this is edge processing: running the model locally, on the device, close to where the video is captured, rather than sending it to a server first.

That's the underlying architecture, not an add-on privacy feature. Because the video never needs to leave the device to be processed, it also never needs to be transmitted or stored to produce a result.

What happens to a scan's data

A scan follows the same path every time.

The video frames exist only long enough to be processed. Once the marker output is generated, the frames are discarded. What's stored or sent onward is the result, not the recording.

WHAT HAPPENS TO THE VIDEO

Camera video

Processed on-device

Video discarded

Output sent

A simplified view of a scan’s data path: video is captured, processed locally, then discarded. Only the resulting markers are sent onward.

Is the data encrypted?

Yes. Data is encrypted in transit and at rest. This covers derived results moving from the point of capture to the Upvio platform, as well as data stored on the platform.

Encryption is one part of the security model. For details on data retention, sub-processors and current certifications, see the Upvio Trust Center.

Compliance status

Controls are designed to support HIPAA, GDPR, LGPD, POPIA, and APP. That spans US health data rules (HIPAA), EU data protection (GDPR), Brazil’s LGPD, South Africa’s POPIA, and Australia’s APP, reflecting that healthcare and wellness customers operate across several regulatory regions and need a platform that accounts for more than one jurisdiction.

Upvio's SOC 2 and ISO 27001 work is in progress. Neither certification is complete. We state this separately from the frameworks the platform is designed to support, because supporting a legal or regulatory framework is different from holding a completed audit certification. You can review current compliance documentation, certifications and supporting policies in the Upvio Trust Center.

What does "privacy by design" mean here?

Privacy by design means minimising what the system collects and keeps. A scan processes the data needed to produce a result. During standard scan processing, raw video remains on the device and is discarded after the result is generated. How skin-tone data is handled in model validation is covered in Vitals AI research.

Does Vitals AI store or retain my data?

During standard scan processing, raw video is not uploaded or stored, and only derived results reach the platform. Retention is governed by your contract and Data Processing Agreement. Vitals AI is hosted in the United States on AWS, with other hosting regions available for large deployments. Details on retention, sub-processors and current certification evidence are available in the Upvio Trust Center.

Is Vitals AI a medical device?

By default Vitals AI is a general wellness tool, and results should be read as wellness indicators rather than clinical findings. A separately certified CE MDR Class IIa model is available for regulated use; the regulatory detail is covered in Vitals AI research.

Regulatory standing

Vitals AI uses a multi-model approach to physiological modelling, combining specialist models within the Upvio platform. These regulatory credentials attach to the model used by Vitals AI, not to Upvio as a company.

CE MDR Class IIa under EU 2017/745, covering blood pressure, heart rate, heart rate variability and breathing rate.

ANVISA registration in Brazil, covering heart rate, heart rate variability, blood pressure and breathing rate.

The general wellness product remains the default for most Upvio customers. A CE MDR Class IIa certified model is available through the Upvio platform for regulated use cases.

Who can see my results?

Upvio provides a configurable security model with role-based permissions, so an organisation controls which roles can view an individual's results. The exact structure depends on how you configure the platform, and your Upvio contact can walk through the access model for your setup.

What should a security or procurement team check?

If you are reviewing Vitals AI as part of a vendor security assessment, this page covers the core of a typical questionnaire: on-device processing and what leaves it, encryption in transit and at rest, the compliance frameworks controls are designed to support, and current audit status for SOC 2 and ISO 27001. For specifics such as sub-processors, security controls, policies and current certification evidence, see the Upvio Trust Center or request documentation from the team.

Questions, answered

Is my video stored?

No. During standard scan processing, raw video is not uploaded or stored. The device processes the video locally, and only derived results, such as calculated vitals, are sent to the platform.

Is Vitals AI HIPAA compliant?

Controls are designed to support HIPAA, alongside GDPR, LGPD, POPIA, and APP. If HIPAA compliance is a hard requirement for your organisation, confirm current documentation and status directly with Upvio as part of your evaluation.

Where is my data processed?

Scan processing happens on the device capturing the video. Derived results are then sent, encrypted, to the Upvio platform.

Are SOC 2 and ISO 27001 complete?

Not yet. Both are in progress.* We list this openly rather than imply certification ahead of when it is actually granted.

Is a Data Processing Agreement or BAA available?

Yes. A Data Processing Agreement and a Business Associate Agreement (BAA) are available to all customers, provided on request.

Can access to results be controlled?

Yes. Upvio provides a configurable security model with role-based permissions, so an organisation controls which roles can view an individual's results.

Is consent captured during the scan?

Yes. The standard scan flow includes a privacy notice and a consent check out of the box. That default notice and check are not editable; a customer who builds their own interface with the SDK provides their own consent flow.

Are audit logs available?

Yes. Audit logs, along with user, webhook and firewall event logs, can be provided on request.

How long is data retained?

Retention is governed by your contract and Data Processing Agreement. Full retention details are provided for procurement and security reviews on request.

Where is data hosted?

Vitals AI is hosted in the United States on AWS. Other hosting regions can be supported for large deployments; talk to the team about requirements.

Is this a diagnostic or medical tool?

By default it is a general wellness tool, not a diagnostic device. A separately certified CE MDR Class IIa model is available for regulated use. Read results as wellness indicators and consult a clinician for any medical concern.