Security and privacy
How Domi Gate is built, what it stores, where, and for how long. No marketing adjectives. If something is not done yet, it says so.
Seven design principles
-
One meeting point
All devices connect outward to the Domi Gate server. Phones and panels never connect to each other, and no port is opened in the building.
-
Access works offline
Credentials are stored encrypted on the panel. The decision to open the door is made at the door.
-
The panel never switches the lock
A separately powered door controller does, and only on authenticated, replay-protected commands from its paired panel.
-
Recordings stay local by default
Clips leave the panel only on an authorised request, through an expiring link, and every fetch is logged.
-
Everything sensitive is audited
Unlocks, credential changes, clip access, pairing, administrator actions.
-
Modular
Calling, access, recording and the portal are separable. A building can start with some of them.
-
Built for one building now, many later
Every record carries the building it belongs to from the first day.
What is stored where, and for how long
| Data | Where | How long |
|---|---|---|
| Live call video and audio | Relayed between the panel and the phone | Never stored |
| Motion clips | Panel only, encrypted | 48 hours rolling, plus a storage cap |
| Missed-call clips | Panel, encrypted. A temporary server copy exists only while someone watches | 48 hours. Deleted at once if the call was answered or dismissed. After the first viewing, replay for 30 minutes |
| Retrieved clips | Server, temporary | Until the link expires, then deleted automatically |
| PINs | Server and panel | One-way hash only (Argon2id), until revoked |
| NFC tag numbers | Server: the number. Panel: a keyed hash only | Until revoked; erased with the person |
| Guest QR codes | Server: the 40-digit number. Panel: a keyed hash only | Until revoked, expired or used up; listed for 30 days after revocation |
| Call history and access events | Server | Kept; the operator sets the limit (automatic purge in development) |
| Audit log | Server, pseudonymous actor ids | Retained for security and legal reasons |
| Push registration and sessions | Server | Until the app is reinstalled or the person is erased; refresh tokens 30 days |
Encryption, as it is today
-
TLS for every connection between the apps, the panel, the portal and the server.
-
Call media is encrypted between the panel and the phone. The relay forwards packets it cannot decode and does not record them.
-
The database on the panel is encrypted (SQLCipher).
-
Clips are encrypted at rest (AES-GCM) with keys protected by the Android Keystore.
-
The panel's identity is an ECDSA P-256 key in the Android Keystore that never leaves the device.
-
The link between the panel and the door controller is authenticated with that identity. Keys are agreed per connection (signed ephemeral ECDH, HKDF-SHA256, AES-256-GCM), replays are rejected, and a past session cannot be decrypted later.
-
PINs and passwords are hashed with Argon2id.
-
Tag numbers and QR numbers reach the panels only as HMAC-SHA256 under a key that belongs to the building.
-
Short-lived access tokens with rotating refresh tokens.
Audit
Every sensitive action is written to an audit log with who did it and when: a remote unlock, a PIN created or revoked, a tag enrolled, a clip requested, a controller paired, a person disabled.
A clip fetched by a manager leaves a complete chain: request, upload from the panel, download through the expiring link, deletion of the temporary copy.
The door controller
The panel never switches the lock. A separately powered controller does, on commands that are authenticated with the panel's hardware key, encrypted and protected against replay. The strike is fail-secure: with no power, the door stays locked. If the controller is down, nothing opens the door and the manager is alerted.
What we do not do
-
No analytics and no crash reporting in the apps. The only Google library is the push service.
-
No advertising.
-
No cloud streaming and no permanent cloud recording.
-
No face recognition. It is not part of this system.
-
No location, contacts or files from your phone.
-
Nothing is sold or shared for anyone else's purposes.
Reviews and certifications
Internal security and dependency review: July 2026. No independent audit yet. No product certifications claimed yet.
Where the data lives
Recordings stay on the panel. Credentials reach the panel as keyed hashes. Live calls are relayed and never stored.
Questions about security or privacy?
Write to privacy@domigate.com. The full privacy notice is at /privacy.