Skip to content
Domi Gate
Menu

Security and privacy

How Domi Gate is built, what it stores, where, and for how long. No marketing adjectives. If something is not done yet, it says so.

Seven design principles

  1. One meeting point

    All devices connect outward to the Domi Gate server. Phones and panels never connect to each other, and no port is opened in the building.

  2. Access works offline

    Credentials are stored encrypted on the panel. The decision to open the door is made at the door.

  3. The panel never switches the lock

    A separately powered door controller does, and only on authenticated, replay-protected commands from its paired panel.

  4. Recordings stay local by default

    Clips leave the panel only on an authorised request, through an expiring link, and every fetch is logged.

  5. Everything sensitive is audited

    Unlocks, credential changes, clip access, pairing, administrator actions.

  6. Modular

    Calling, access, recording and the portal are separable. A building can start with some of them.

  7. Built for one building now, many later

    Every record carries the building it belongs to from the first day.

What is stored where, and for how long

DataWhereHow long
Live call video and audioRelayed between the panel and the phoneNever stored
Motion clipsPanel only, encrypted48 hours rolling, plus a storage cap
Missed-call clipsPanel, encrypted. A temporary server copy exists only while someone watches48 hours. Deleted at once if the call was answered or dismissed. After the first viewing, replay for 30 minutes
Retrieved clipsServer, temporaryUntil the link expires, then deleted automatically
PINsServer and panelOne-way hash only (Argon2id), until revoked
NFC tag numbersServer: the number. Panel: a keyed hash onlyUntil revoked; erased with the person
Guest QR codesServer: the 40-digit number. Panel: a keyed hash onlyUntil revoked, expired or used up; listed for 30 days after revocation
Call history and access eventsServerKept; the operator sets the limit (automatic purge in development)
Audit logServer, pseudonymous actor idsRetained for security and legal reasons
Push registration and sessionsServerUntil the app is reinstalled or the person is erased; refresh tokens 30 days

Encryption, as it is today

  • TLS for every connection between the apps, the panel, the portal and the server.

  • Call media is encrypted between the panel and the phone. The relay forwards packets it cannot decode and does not record them.

  • The database on the panel is encrypted (SQLCipher).

  • Clips are encrypted at rest (AES-GCM) with keys protected by the Android Keystore.

  • The panel's identity is an ECDSA P-256 key in the Android Keystore that never leaves the device.

  • The link between the panel and the door controller is authenticated with that identity. Keys are agreed per connection (signed ephemeral ECDH, HKDF-SHA256, AES-256-GCM), replays are rejected, and a past session cannot be decrypted later.

  • PINs and passwords are hashed with Argon2id.

  • Tag numbers and QR numbers reach the panels only as HMAC-SHA256 under a key that belongs to the building.

  • Short-lived access tokens with rotating refresh tokens.

Audit

Every sensitive action is written to an audit log with who did it and when: a remote unlock, a PIN created or revoked, a tag enrolled, a clip requested, a controller paired, a person disabled.

A clip fetched by a manager leaves a complete chain: request, upload from the panel, download through the expiring link, deletion of the temporary copy.

The door controller

The panel never switches the lock. A separately powered controller does, on commands that are authenticated with the panel's hardware key, encrypted and protected against replay. The strike is fail-secure: with no power, the door stays locked. If the controller is down, nothing opens the door and the manager is alerted.

Fire alarm and emergency-egress functionality must not depend only on BLE, Android or normal application software.

What we do not do

  • No analytics and no crash reporting in the apps. The only Google library is the push service.

  • No advertising.

  • No cloud streaming and no permanent cloud recording.

  • No face recognition. It is not part of this system.

  • No location, contacts or files from your phone.

  • Nothing is sold or shared for anyone else's purposes.

Reviews and certifications

Internal security and dependency review: July 2026. No independent audit yet. No product certifications claimed yet.

Where the data lives

Where the data lives The entrance panel and the resident phone each connect outward to the Domi Gate server, which relays the call. The panel talks to a separately powered door controller over Bluetooth, and the controller switches the electric strike. Entrance panel 48 h · encrypted · local Domi Gate server (EU) call media relayed, never recorded Resident's phone outbound only · TLS outbound only · TLS push wake-up no direct connection Bluetooth · authenticated · AES-GCM Door controller (own power) Electric strike (fail-secure) works offline: PIN · tag · QR

Recordings stay on the panel. Credentials reach the panel as keyed hashes. Live calls are relayed and never stored.

Questions about security or privacy?

Write to privacy@domigate.com. The full privacy notice is at /privacy.