Live The Lab is open — real Canary firmware, running in your browser Try it →

Privacy-first, open-source cameras

Three things. One witness.

New here? The two-minute version
Home
use cameras to:
detect events
not people|

SecuraCV runs on your own hardware — no cloud, no subscription — and turns cameras into witnesses.

Two ways in

One of these is you. Pick it and skip the rest of this page.

📹
Software · best supported

I already have cameras

RTSP cameras and a Pi, running next to Frigate. +$0 on an existing Home Assistant stack — no new hardware, nothing to print.

On Home Assistant — one command in the Terminal app
curl -fsSL https://raw.githubusercontent.com/kmay89/securaCV/main/scripts/install.sh | bash

Paste it into the Terminal app (or any SSH session into the box) and it sets up the whole stack — the Mosquitto MQTT broker, Frigate with a curated config, the Privacy Witness Kernel app, the SecuraCV integration, blueprints, and dashboards — narrating each step as it goes. It detects what you already have and is safe to re-run.

Prefer buttons? Two clicks, in your own Home Assistant

Each button opens your Home Assistant and pre-fills the repository — you approve every step there. This path is click-through rather than hands-off; the one command above does everything for you.

No Home Assistant? Run it next to Frigate

One compose file starts the sidecar: quickstart.compose.yml — or the with-broker variant if you don't run an MQTT broker yet. Events announce themselves over MQTT discovery to anything that listens, and if you add Home Assistant later it discovers everything with nothing to reconfigure.

Read the full install guide → See what it does first →
🐤
Hardware · print it yourself

I want to build one

Print the case, buy the board anywhere, flash it from your browser — $27–$55 a node. Kits are the roadmap, not the store, until FCC authorization is complete. Try it first: the Lab runs the real device firmware in your browser — no hardware, no install, no sign-up.

Start in the Lab — nothing to buy → 🚀 Already have a board? Flash it → 💎 See the hardware →

Neither, yet? Is it for me? · Find your path

This is the output. All of it.

Notice there are no images on this site. That's intentional. The system outputs semantic events — text that describes what happened. It outputs events like "package at front door", never faces, plates, or identities. The surveillance data on the right? That code doesn't exist. Not disabled. Not hidden. Missing.

Event Output
HOME
Not Captured — No Code Exists
facial_identity:███████
race:███████
gender:███████
age_estimate:███████
body_description:███████
license_plate:███████
gait_signature:███████
tracking_id:███████
What leaves the device
Camera ──▶ RawFrame ──▶ InferenceView ──▶ Module ──▶ SealedEvent
            (private)    (no pixels)               (hash-chained)
               │
               ▼
         FrameBuffer ──▶ BreakGlass ──▶ VaultEnvelope
           (30s max)       (N-of-M)       (if authorized)

Your robot vacuum needs to see. Your doorbell needs to see. Your elder care system needs to see. None of them need to identify, track, or remember faces.

The cameras of the future will have eyes — they just don't need to surveil.

Made for people who want cameras, not surveillance

Three kinds of people use SecuraCV today. If you're one of them, there's a path in — and if you're someone else entirely, find your path: every door, sorted by what you came to do.

🏠
Start here — best supported

Home Assistant & homelab users

You have RTSP cameras and a Pi. Frigate keeps recording as usual — SecuraCV runs alongside it, adding the privacy boundary and a tamper-evident witness log. No subscription, ever.

Install in 5 minutes →
⚖️

People who need a record where any rewrite shows

Tenants, journalists, activists, abuse survivors. Every event is signed and hash-chained — evidence of what was recorded, where any later edit, by anyone including you, becomes detectable.

See how it's enforced →
🔧

Builders & tinkerers

Cheap ESP32 boards become independent "Canary" witnesses — camera, radar, and WiFi-sensing variants with printable enclosures. Try the real firmware in your browser before you solder anything.

Meet the Canaries in the Lab →

Three things. One witness.

When Steve Jobs unveiled the iPhone, he fused three things you already owned — an iPod, a phone, an internet communicator — into one. A Canary does the same, with one twist.

It sees

A camera

The job Ring and Nest sell.

It watches the doorway — but only a sentence leaves the sensor, package at front door, never a face or a plate.

It proves

A notary

The job a signature does.

Every event is Ed25519-signed and hash-chained, so tampering doesn't get blocked — it gets seen, verifiable offline.

It protects

A vault

The job a two-key safe does.

The rare frame that matters is sealed — opening it takes a quorum of trustees. No single person, not even us.

Camera
Notary
Vault
One witness

The twist: Jobs' three helped each other. These three were always enemies — a camera kills privacy, privacy kills evidence, evidence means a stranger's cloud. So we stopped making you pick two. See how it fits together →

Same camera. Same question. Different futures.

Watch how "is the coffee ready?" becomes something else entirely.

Traditional System
Full Capture
☕
Break Room Camera
System Output — illustrative, not a real person or benchmark
[09:14]motion_detected zone:coffee_area
[09:14]face_identified: SUBJECT_04 (94%) · illustrative
[09:14]badge_correlation: EMP-4821
[09:15]coffee_pot_lifted duration:12s
[09:15]dwell_time: 47s added_to_profile
30-day Storage
847 face events 12.4 GB video
witness-kernel
Events Only
☕
Break Room Camera
System Output
[09:10]coffee_pot: EMPTY
[09:10]motion: zone_A activity
[09:20]coffee_pot: BREWING
[09:30]coffee_pot: READY
[09:30]notification: sent_to_channel
30-day Storage
2,341 events 4.2 MB total

Six months later, a policy changes...

"We need to identify who's been using the break room excessively."

See the next 180 days
Day 1

HR requests usage report

"Generate a list of employees who spend more than 15 minutes in the break room daily."

✕
Traditional
Report generated: 23 employees flagged, with timestamps, durations, and photos
✓
witness-kernel
Cannot comply. No identity data exists to query.
Day 30

Legal requests footage

"Lawsuit filed. Preserve all break room footage showing employee interactions."

✕
Traditional
6 months of footage preserved. All faces, conversations, behaviors now legal evidence.
✓
witness-kernel
Event log preserved. Shows coffee/motion patterns. No footage to subpoena.
Day 90

New vendor integration

"Our wellness platform wants camera data to track employee stress patterns."

✕
Traditional
API enabled. Facial expressions, posture, interaction frequency now shared with third party.
✓
witness-kernel
Nothing to share. System outputs "coffee ready" — not biometrics.
Day 180

Retroactive analysis request

"Apply our new 'productivity scoring' algorithm to the last 6 months of footage."

✕
Traditional
Analysis complete. Employees scored and ranked by break room behavior. Used in performance reviews.
✓
witness-kernel
Impossible. New rules cannot be applied to historical data. Forward-only by design.
☕ Did you know?

The first webcam just watched a coffee pot.

In 1991, Cambridge researchers pointed a camera at their break room coffee maker. The only question: is it ready yet?

Thirty years later, that same question requires facial recognition, behavioral tracking, and cloud storage. We think the original idea had it right.

What's built, what's in progress

This is prototype software. Here's where we are.

✓

Frame isolation types

✓

Hash-chained event log

✓

Break-glass quorum

✓

Event contract enforcement

✓

Cryptographic signatures

✓

Encrypted vault envelopes

◐

RTSP video ingestion

○

WASM module sandboxing

Reading the two open tiles: RTSP decoding is built in but sits behind opt-in build features (rtsp-ffmpeg, rtsp-gstreamer), so a default build does not ingest RTSP itself. And WASM sandboxing is planned; what ships today is process isolation, with detection modules run in forked, seccomp-restricted child processes on Linux.

2 of 4 designed Canaries shipped; Watch Station & Canary Dash are next out of the shop, running their real firmware in the Lab today — counted from the kit cards on Compare; every design is drawn in the fleet, drawn. No fake countdown, no invented backer count: join the waitlist to say “I want one.”

Don't trust us — check the code

Every claim on this page can be verified by reading the source.

1

Verify the log can't be tampered with

Run the verification tool to confirm the hash chain is intact.

cargo run --bin log_verify -- --db witness.db
2

Verify frame data is inaccessible

In src/frame.rs, confirm the raw bytes have no public getter.

3

Verify export requires quorum

In src/break_glass.rs, confirm approval counting before token issuance.

Don't read code? Start here. A plain-language walkthrough of what the kernel actually does and how the cryptography really works — sign a real claim, then forge it; break a real hash chain and watch the math catch you. No install, no cloud, nothing to trust but the math.

🧠 See exactly how it works 🔐 Break the glass yourself ✍️ Watch a claim get signed — then forge it View Source

Read the source. Verify the claims.

Everything on this page is checkable. We're not asking for trust — we're asking for review. Or skip the reading and poke the running firmware yourself.