WHITECORE.AI

Legal

Security Policy

Effective Date: January 1, 2026 · Website: whitecore.ai · Contact: future@whitecore.ai

WhiteCore is committed to maintaining enterprise-grade security standards across its software platform, cloud infrastructure, media player ecosystem and AI analytics services.

This Security Policy outlines the measures WhiteCore implements to protect customer data, system integrity and platform availability.

By using WhiteCore services, customers acknowledge and accept the security practices described within this policy.

1. Security Commitment

WhiteCore is designed as a secure, enterprise-grade digital signage and AI analytics platform built with security-first architecture principles.

We continuously work to protect:

Customer account information

Subscription and billing data

Media content uploaded to the platform

Device communication between media players and cloud services

Analytics data generated through AI systems

Platform infrastructure and APIs

Customer configuration settings and deployment data

Security is integrated into both software architecture and operational processes.

2. Infrastructure Security

WhiteCore utilises commercially reasonable security measures designed to protect platform infrastructure.

Security measures may include:

Secure cloud hosting infrastructure

Encrypted network communications

Firewall protection

Intrusion monitoring systems

Server hardening procedures

Role-based administrative access controls

Continuous infrastructure monitoring

Infrastructure is regularly reviewed for security improvements.

3. Encryption Standards

WhiteCore protects customer communications using modern encryption standards.

Security protections may include:

SSL/TLS encrypted web traffic

Secure HTTPS communication

Encrypted API communication between player devices and cloud systems

Encrypted authentication sessions

Secure credential transmission

Sensitive information is never intentionally transmitted over unsecured channels.

4. Account Security

Customer account protection measures include:

Secure password authentication

Encrypted login sessions

Multi-factor authentication where supported

Account session management controls

Login activity monitoring

Access restrictions based on account permissions

Role-based user management controls

Customers remain responsible for protecting their account credentials.

5. Multi-Tenant Data Separation

WhiteCore operates a multi-tenant cloud platform architecture.

To protect customer isolation:

Customer accounts are logically separated

Each customer environment is isolated from unrelated customer accounts

Account permissions are restricted to authorised users only

Internal access controls prevent unauthorised cross-account access

WhiteCore continuously monitors tenant isolation integrity.

6. Device Security

WhiteCore media players and connected hardware devices implement security controls designed to reduce unauthorised access.

Security features may include:

Device authentication with cloud services

Secure player registration processes

Pairing code validation

Kiosk mode restrictions

Device status monitoring

Secure software updates

Local access restrictions where applicable

Customers remain responsible for physical security of deployed hardware.

7. Payment Security

WhiteCore does not directly store full payment card information.

Subscription payments may be processed using approved third-party providers including:

Stripe

Payment processors maintain independent security and compliance standards.

WhiteCore does not retain complete credit card details on internal systems.

8. AI & Camera Security

Where Vision AI analytics services are enabled:

Video processing may occur locally on edge devices

Video footage is not permanently stored by default

AI analytics may transmit metadata only rather than raw video streams

Camera systems communicate using secured approved protocols

No facial recognition systems are deployed by default

WhiteCore prioritises privacy-first AI architecture.

9. Software Updates

WhiteCore may periodically release software updates to improve security.

This may include:

Security patches

Infrastructure improvements

Vulnerability mitigation

API security updates

Player software improvements

Performance optimisations

Customers may be required to update player software periodically.

10. Incident Response

In the event of a suspected security incident, WhiteCore may:

Investigate unusual platform behaviour

Restrict access to affected accounts

Temporarily suspend services where necessary

Apply emergency security updates

Monitor suspicious activity

Notify affected customers where required by law

Security incidents are prioritised for immediate investigation.

11. Customer Responsibilities

Customers are responsible for maintaining security practices within their own environment.

This includes:

Protecting login credentials

Maintaining secure local networks

Restricting physical access to deployed hardware

Securing camera systems and network infrastructure

Maintaining device security within customer premises

Using authorised personnel only

WhiteCore is not responsible for customer security failures occurring outside our platform.

12. No Absolute Security Guarantee

While WhiteCore implements commercially reasonable security measures:

No software platform can guarantee absolute security

Internet-based services inherently carry security risks

Customers acknowledge use of cloud services involves shared security responsibility

WhiteCore does not warrant absolute immunity from cyber threats.

13. Security Improvements

WhiteCore reserves the right to improve, modify or strengthen security systems at any time without prior notice where required to protect platform integrity.

Security updates may be deployed automatically where necessary.

14. Contact

For security-related enquiries or incident reporting:

WhiteCore · Email: future@whitecore.ai · Website: www.whitecore.ai

By using WhiteCore services, you acknowledge and accept this Security Policy.