Powered by KVault — US Patented Split & Spread
A forward post that's overrun, or a utility's NVR that's ransomed, surrenders footage that still can't be opened — because no single location it was seized from ever held enough to open it.
Most CCTV storage is a single target. Whatever sits in the recorder — at a forward post, an airport, a power station, a government building — is only as safe as whatever protects that one box. An overrun post surrenders its footage the moment it's seized. A ransomed on-site NVR hands over the same footage to the attacker holding it hostage. Defence and public-infrastructure operators additionally need footage to hold up as evidence — for a court of inquiry, a regulatory finding, or a criminal case — not just as playback.
Direct RTSP/ONVIF ingest from the camera — no vendor cloud in between.
Cut into fixed time-slices — never one continuous, single-key file.
Each slice sealed under AES-256-GCM with its own unique 256-bit key.
Footage, slice key and master key written to three separate custodies.
Aged out automatically on a retention policy — not a manual sweep.
Reopened only by decrypting all three pieces together — tampering fails outright.
A forward post that's physically overrun surrenders footage that can't be opened without custody it never held — and the same GCM authentication tag makes that footage admissible before a court of inquiry.
Hundreds of cameras across one site or many — the same split-custody model applies uniformly, with retention handled by policy, not manually per site.
Ransomware that reaches the on-site NVR finds ciphertext with no key to hold to ransom — there is nothing to encrypt a second time that isn't already unusable.
The existing NVR estate stays in place — CCTV Vault's split-storage model sits alongside it rather than demanding a rip-and-replace on day one.
A unique key for every time-slice — never reused across a segment, camera or site.
One altered byte anywhere in a slice fails its decryption outright — not silently accepted.
Direct RTSP/ONVIF ingest — footage never has to leave the operator's own network to work at all.
Four deployment models — full replacement through to side-by-side coexistence — none demand a rip-and-replace.
Segments past their retention window are pruned automatically, consistently, across every site.
The difference between a single-site pilot and a hundred-camera deployment is a configuration change.
AES-256 is the cipher the NSA's Commercial National Security Algorithm Suite names for protecting information up to Top Secret — a statement about the algorithm, not a certification held by KGreen or any specific deployment.