Everything About People Counting Solutions & Features

property operations RFP — Security Requirements for Property Operations RFP | Vemco Group

Written by Admin | Aug 17, 2026, 7:19:22 PM

Most security sections in a property operations RFP are copied from an IT procurement template written for enterprise software, and vendors can tell. The result is predictable: bidders paste boilerplate answers about encryption at rest, procurement scores everyone identically on security, and the real risks — an unmanaged sensor on the tenant network, a data processing agreement that never names the sub-processors, an accuracy claim nobody can enforce — sail through unexamined. If your portfolio runs people counting, occupancy monitoring, access analytics or any sensor-driven operations platform, your security requirements need to be written for that reality, not for a generic SaaS purchase.

Start with the data, not the vendor's brochure

Before you write a single requirement, map what data the system actually creates. Footfall and occupancy platforms generate three distinct categories: raw sensor output (video frames, depth maps, Wi-Fi probes), processed counts, and aggregated analytics pushed into BI or leasing dashboards. Each category carries different risk and needs different treatment in the RFP. Raw sensor data is where privacy exposure lives; processed counts are where commercial sensitivity lives (a competitor learning your anchor tenant's traffic decline is a leasing problem, not just an IT problem); aggregated dashboards are where access-control failures cause the most day-to-day damage.

Your RFP should therefore ask, per data category: where is it processed, where is it stored, how long is it retained, and who can see it. A vendor that processes counting on the edge device and never transmits identifiable imagery is answering a fundamentally different privacy question than one streaming video to a central server. Force bidders to state this explicitly — many will not volunteer the distinction.

Hosting requirements that reflect how portfolios actually work

Property owners increasingly operate across jurisdictions with conflicting data residency rules — a Gulf-based mall operator and a German REIT will get different answers from their legal teams about where visitor data may sit. Rather than mandating one hosting model, require bidders to offer a choice and price both. Platforms like Vemco Analytics support hosted or private cloud deployment precisely because tender committees in different markets reach different conclusions; a vendor that only offers one model has effectively made your compliance decision for you.

Ask specifically about sub-processors. The counting platform may be one company, but the cloud infrastructure, the support desk, and sometimes the sensor firmware updates involve others. Require a named sub-processor list in the response, with contractual notice before changes. This is standard under GDPR-style regimes but routinely missing from property-sector RFPs.

The sensor network is your biggest unwritten requirement

Here is what implementers see repeatedly on site: the counting sensors get installed on whatever network drop is nearest — sometimes the tenant's, sometimes the property's guest Wi-Fi, occasionally a forgotten VLAN from a previous vendor whose devices are still physically on the ceiling. Nobody removed the old hardware because the decommissioning clause in the previous contract said nothing about it. Those orphaned devices, still powered, still on the network, are a genuine attack surface, and no RFP the property issued ever mentioned them.

Write requirements that address the physical layer:

  • Network segmentation: sensors must operate on a dedicated VLAN with documented firewall rules, and the bidder must state exactly which outbound ports and destinations the devices require.
  • Firmware governance: who pushes updates, how they are signed, and what the rollback process is when an update breaks counting overnight before a peak trading day.
  • Credential management: no default passwords on delivered hardware, and a stated process for rotating device credentials when your integrator's staff change.
  • Decommissioning: contractual obligation to remove or wipe devices at contract end, with a certificate of data destruction.

A sensor-agnostic platform helps here more than most procurement teams realise. When the software layer is device-independent, you can standardise security policy across mixed hardware estates — the 3D sensors installed in 2019 and the newer stereo cameras from a different manufacturer all report into one governed environment, rather than three vendor portals with three password policies.

Integration security: the question hiding inside VemFusion-style connections

Modern footfall platforms rarely stand alone. Vemco's VemFusion, for example, connects counting data with POS, BI, ERP and CRM systems — which is exactly what makes the data valuable for leasing negotiations and conversion analysis, and exactly what your security section must interrogate. Every integration is a data flow crossing an organisational boundary. Your RFP should require: authentication method per integration (API keys versus OAuth, and key rotation policy), whether data flows are push or pull, and a data flow diagram as a mandatory response artefact. A bidder who cannot produce that diagram in a tender response will not produce it during an incident either.

Make security claims contractual, or they are marketing

The single most useful discipline in a property operations RFP is refusing to accept any claim that cannot be written into the contract with a remedy attached. This applies beyond security. Take counting accuracy: many vendors quote 98% or 99% in sales material with nothing behind it. Vemco offers a contractual minimum of 96% accuracy — typically achieving 98–99% where lighting, layout and visitor behaviour allow — and that structure is instructive. The honest number is the guaranteed floor, not the best-case ceiling, and the same logic should govern uptime, incident response times and breach notification windows.

For security specifically, require in the contract: breach notification within a defined number of hours (not "without undue delay"), named certifications with the obligation to maintain them for the contract term, an annual right to request penetration test summaries, and SLA credits that actually sting. Confirm certifications such as ISO 27001 or SOC 2 during evaluation — request the certificate, check the scope statement covers the service you are buying, and verify expiry dates. A surprising number of "certified" claims refer to a parent company or a different product line.

Weight your scoring for vendor longevity

Security posture is partly a function of vendor maturity. A platform operating since 2005, serving 2000+ customers and processing 85M+ counts per day across partners in 95+ countries has survived the incidents, audits and infrastructure migrations that harden a company's practices — and has enterprise customers whose own procurement teams have already stress-tested the answers. That does not mean incumbents automatically win; it means your scoring matrix should reward evidenced operational history (reference customers of comparable scale, incident track record, support model with defined tiers) rather than the most polished security narrative. Ask references one question the vendor cannot script: describe the last time something went wrong and how it was handled.

Get a second pair of eyes on your requirements

If you are drafting security requirements for a property operations RFP covering footfall analytics, occupancy monitoring or portfolio-wide counting infrastructure, it is worth pressure-testing your specification against what vendors can actually contractually commit to — before the tender goes out, not during evaluation. The Vemco team responds to tenders across 95+ countries and can walk you through realistic requirements for hosting models, sensor network security, integration governance and enforceable accuracy guarantees. Contact us at vemcogroup.com/contact-us to discuss your RFP security section before you publish it.