---
title: "Security and Data Retention Policy"
source: /gc-surge/support/security-and-data-retention-policy
locale: en
updated: 2026-09-23
---
## Summary

This page summarizes the security controls and data-retention behavior that customers most often ask about during onboarding, legal review, and operational governance. Covers: Security controls, Data retention.

## Security controls

- **Encrypted transport** — all platform traffic is encrypted in transit using TLS 1.2 or higher.
- **Encryption at rest** — credentials and sensitive data are stored encrypted at rest (AES-256).
- **Role-based access control** — access is controlled at the application layer based on each user's assigned role.
- **Authenticated agents** — field and edge components authenticate to the platform using signed tokens before they can send data.
- **Tenant isolation** — each customer's users, sites, and camera data are isolated from every other tenant.

## Data retention

GC Surge retains data for the following default periods:

| Data type | Default retention |
| --- | --- |
| Alarm data | Minimum 12 months |
| Audit logs | Minimum 12 months (write-once — not editable or deletable) |
| Billing records | Minimum 7 years |
| Video snapshots | 90 days (configurable) |

GC Surge does not provide long-term video storage. Only the snapshots attached to alarms are retained, for 90 days; full video retrieval requires your own NVR/VMS. Where a retention period in your service agreement differs from these defaults, your agreement takes precedence.