Everything About People Counting Solutions & Features

SOC2 people counting platform — Security Requirements for Soc2 People Counting Platform | Vemco Group

Written by Admin | Sep 4, 2026, 11:19:29 PM

The vendor security questionnaire comes back and the people counting supplier has answered "N/A" to half the questions — because, they argue, "we only count heads, we don't process personal data." If you work in security or compliance, you already know why that answer should worry you rather than reassure you. A people counting platform still ships firmware to devices on your network, still moves data to a cloud tenant, still has employees with admin access, and still represents an attack path into your store infrastructure. Whether the payload is a face or an integer is almost beside the point.

That gap — between "the data is harmless" and "the system is trustworthy" — is exactly what a SOC 2 evaluation of a people counting platform is meant to close. This article sets out what to actually demand, section by section, so your procurement team can push past marketing language and get evidence.

Why SOC 2 matters for a system that "only counts"

SOC 2 is not a product certification. It is an attestation, produced by an independent auditor, that a service organisation's controls meet the Trust Services Criteria — Security always, and optionally Availability, Processing Integrity, Confidentiality and Privacy. For a people counting platform, three of those criteria carry real weight:

  • Security: the sensors sit on your LAN or a dedicated VLAN. A compromised counting device is a foothold, regardless of what it counts.
  • Availability: if conversion rates and staffing decisions depend on footfall data, gaps in counting are gaps in revenue analytics. Ask how the auditor tested uptime commitments and incident response, not just what the SLA says.
  • Processing Integrity: this is the underrated one. A counting platform that silently drops data during a network outage, or double-counts after a firmware update, fails its core purpose. Processing Integrity coverage in the SOC 2 report tells you the vendor's data pipeline has been examined, not just their laptops.

One distinction procurement teams frequently miss: insist on a SOC 2 Type II report, not Type I. Type I says the controls existed on a single day. Type II says they operated effectively over a period, usually six to twelve months. A vendor waving a Type I report at you has passed a snapshot, not a marathon.

The questions that separate serious vendors from the rest

When you receive the SOC 2 report under NDA — and you should always request the full report, not the bridge letter or a badge on a website — read three sections closely. First, the scope: does it cover the platform you are actually buying, including the sensor fleet management layer, or only the vendor's corporate IT? Scoping games are the most common way a weak vendor holds a legitimate-looking report. Second, the exceptions: nearly every honest report contains some. What matters is whether the vendor remediated them and can show you how. Third, the complementary user entity controls — the things the auditor assumed you would do, such as network segmentation and access reviews on your side. Those become your obligations the moment you sign.

Beyond the report itself, put these on the questionnaire:

  • How are sensor firmware updates signed, delivered and rolled back? Who can push an update, and is that action logged?
  • Is data encrypted in transit from device to cloud, and at rest in the tenant? Which cipher suites, and when were they last reviewed?
  • Can the platform run in a private cloud or customer-controlled environment if your data-residency policy requires it?
  • What identity options exist for dashboard access — and does the vendor support your SSO standard? Verify this in a technical call, not from a feature list.
  • What are the data retention defaults, and can you set your own? Aggregate footfall data ages into commercial intelligence; you should decide how long it lives.

Where SOC 2 meets GDPR — and where it doesn't

Compliance officers should treat SOC 2 and GDPR as complementary, not interchangeable. SOC 2 tells you the vendor's controls work; GDPR asks whether personal data is processed lawfully at all. The cleanest position for a people counting deployment is one where the second question barely arises: counting that produces aggregate figures only, with no personal identification, dramatically shrinks the GDPR analysis your DPO has to perform. Vemco's approach is built on exactly that principle — anonymous aggregate counts rather than identity-linked tracking, with staff exclusion so employee movement never enters the customer dataset. That last detail matters more than it sounds: staff exclusion is a data-minimisation control and an accuracy control at the same time, since a store team crossing the entrance forty times a day will distort conversion metrics as surely as any privacy audit finding.

A practitioner note from deployments in the field: the security review almost always underestimates the physical layer. Sensors mounted above entrances are reachable from a stepladder, and I have seen audits pass an entire cloud architecture while nobody asked whether the device's Ethernet port sits behind 802.1X or whether the local configuration interface still had default credentials. Add "physical and local access to counting devices" as an explicit line in your assessment. Vendors who have thought about it will answer immediately; vendors who haven't will go quiet.

Accuracy is a security requirement too

Enterprise buyers rarely connect accuracy clauses to the security review, but they should. Data you cannot trust is data you should not be storing, and a vendor's willingness to contract on accuracy tells you something about their processing discipline. Insist on a contractual accuracy floor — Vemco commits to a 96% contractual minimum, with real-world performance typically reaching 98–99% when lighting, store layout and visitor behaviour allow. Treat any vendor quoting a flat "99% accuracy" with no conditions and no contractual backing the same way you would treat an unaudited security claim.

Finally, confirm certifications directly rather than relying on sales decks — ask any vendor, Vemco included, for current attestation documents, audit periods and scope statements as part of due diligence. A supplier that has been securing retail counting deployments across dozens of countries for two decades will have this paperwork ready and a process for sharing it under NDA. That readiness is itself a signal.

If you are drafting security requirements for a people counting procurement, or you want Vemco's current compliance documentation, architecture options and deployment references reviewed against your questionnaire, contact the Vemco Group team here and ask for a security and compliance walkthrough tailored to your environment.