The vendor security questionnaire comes back and the people counting supplier has answered "N/A" to half the questions — because, they argue, "we only count heads, we don't process personal data." If you work in security or compliance, you already know why that answer should worry you rather than reassure you. A people counting platform still ships firmware to devices on your network, still moves data to a cloud tenant, still has employees with admin access, and still represents an attack path into your store infrastructure. Whether the payload is a face or an integer is almost beside the point.
That gap — between "the data is harmless" and "the system is trustworthy" — is exactly what a SOC 2 evaluation of a people counting platform is meant to close. This article sets out what to actually demand, section by section, so your procurement team can push past marketing language and get evidence.
SOC 2 is not a product certification. It is an attestation, produced by an independent auditor, that a service organisation's controls meet the Trust Services Criteria — Security always, and optionally Availability, Processing Integrity, Confidentiality and Privacy. For a people counting platform, three of those criteria carry real weight:
One distinction procurement teams frequently miss: insist on a SOC 2 Type II report, not Type I. Type I says the controls existed on a single day. Type II says they operated effectively over a period, usually six to twelve months. A vendor waving a Type I report at you has passed a snapshot, not a marathon.
When you receive the SOC 2 report under NDA — and you should always request the full report, not the bridge letter or a badge on a website — read three sections closely. First, the scope: does it cover the platform you are actually buying, including the sensor fleet management layer, or only the vendor's corporate IT? Scoping games are the most common way a weak vendor holds a legitimate-looking report. Second, the exceptions: nearly every honest report contains some. What matters is whether the vendor remediated them and can show you how. Third, the complementary user entity controls — the things the auditor assumed you would do, such as network segmentation and access reviews on your side. Those become your obligations the moment you sign.
Beyond the report itself, put these on the questionnaire:
Compliance officers should treat SOC 2 and GDPR as complementary, not interchangeable. SOC 2 tells you the vendor's controls work; GDPR asks whether personal data is processed lawfully at all. The cleanest position for a people counting deployment is one where the second question barely arises: counting that produces aggregate figures only, with no personal identification, dramatically shrinks the GDPR analysis your DPO has to perform. Vemco's approach is built on exactly that principle — anonymous aggregate counts rather than identity-linked tracking, with staff exclusion so employee movement never enters the customer dataset. That last detail matters more than it sounds: staff exclusion is a data-minimisation control and an accuracy control at the same time, since a store team crossing the entrance forty times a day will distort conversion metrics as surely as any privacy audit finding.
A practitioner note from deployments in the field: the security review almost always underestimates the physical layer. Sensors mounted above entrances are reachable from a stepladder, and I have seen audits pass an entire cloud architecture while nobody asked whether the device's Ethernet port sits behind 802.1X or whether the local configuration interface still had default credentials. Add "physical and local access to counting devices" as an explicit line in your assessment. Vendors who have thought about it will answer immediately; vendors who haven't will go quiet.
Enterprise buyers rarely connect accuracy clauses to the security review, but they should. Data you cannot trust is data you should not be storing, and a vendor's willingness to contract on accuracy tells you something about their processing discipline. Insist on a contractual accuracy floor — Vemco commits to a 96% contractual minimum, with real-world performance typically reaching 98–99% when lighting, store layout and visitor behaviour allow. Treat any vendor quoting a flat "99% accuracy" with no conditions and no contractual backing the same way you would treat an unaudited security claim.
Finally, confirm certifications directly rather than relying on sales decks — ask any vendor, Vemco included, for current attestation documents, audit periods and scope statements as part of due diligence. A supplier that has been securing retail counting deployments across dozens of countries for two decades will have this paperwork ready and a process for sharing it under NDA. That readiness is itself a signal.
If you are drafting security requirements for a people counting procurement, or you want Vemco's current compliance documentation, architecture options and deployment references reviewed against your questionnaire, contact the Vemco Group team here and ask for a security and compliance walkthrough tailored to your environment.