Services · Anonymization as a service

Send us footage. Get it back with every identity removed.

The de-identification pass we run on every dataset we deliver, opened up as a service you can send your own video to. Faces, licence plates, screens, and identifying speech are detected, tracked, and irreversibly blurred — then a human confirms it, per clip, before anything comes back.
Redacts
Faces · plates · screens · speech
Redaction
Irreversible, pixel-level
Confirmed by
100% human review
Scales with
GPU, not headcount
Bounding box + confidence · internal
A first-person cycling frame with a green bounding box labelled face 0.80 drawn around the rider’s detected face.face · 0.80
Stage one. A vision model scans the frame and returns a bounding box around every face, with a confidence score. Nothing is altered yet — this labelled view stays internal.

A real frame at both stages. Detect returns a bounding box and a confidence score; Blur bakes the redaction into the delivered pixels.

What it is

A privacy outcome, delivered — not a tool to run yourself.

Anonymization as a service means you send footage to a managed pipeline and receive it back de-identified, with a record of what was removed. You skip building the detection, the cross-frame tracking, and the human QA that make the result trustworthy.

We built this pass because our own egocentric captures happen in real homes, streets, and workplaces, where bystanders end up in frame. The honest answer was never to pretend they do not — it was to remove them before anyone downstream sees the footage. Teams kept asking to run their own video through the same pipeline, so we made it available on its own.

It is the same discipline CloudPano has applied to spatial capture across 200+ countries for years: collect at scale, but treat the people in the scene as something to protect. The difference from a do-it-yourself model or an open-source detector is not the model — it is the irreversibility, the cross-frame tracking, the human sign-off, and the per-file certificate that lets you prove the pass ran.

The services

Pick the redaction your footage needs.

Each service targets a specific exposure. Faces-only is the cheapest fit; the full video pass covers everything that re-identifies an un-consented person.

Every dataset we collect already ships through this pass by default — see the automatic anonymization pipeline built into our own deliveries, and the provenance and consent chain around it.

How it works

Five stages, run on every clip.

The pass is automatic, but detection alone is never the guarantee — the human review and the per-file certificate are.

1 · Detect
A vision model runs on every frame, returning a bounding box and a confidence score for each face, head, licence plate, and legible screen or document it finds.
2 · Track
Boxes are linked across frames into stable tracks, so a subject that turns away, blurs in motion, or leaves and re-enters is covered for the entire time they are on screen — not just the frames they face the camera.
3 · Redact
Each tracked region is irreversibly blurred into the pixel data of the output. There is no separate mask layer, no metadata toggle, and no key that restores the original region.
4 · Review
A human reviewer scrubs the output and confirms no un-consented person or identifier survives in any frame. If a region is uncertain, the clip is held or dropped rather than shipped.
5 · Certify
The detector version, pass timestamp, reviewer ID, and per-file settings are recorded against the clip, so the anonymization claim is checkable per file rather than asserted in a brochure.

The guarantees

What makes it trustworthy.

Automatic blurring is common. What matters is whether it is reversible, whether it fails safely, and whether you can prove per file that it happened.

Irreversible by construction
Blur is baked into the delivered pixels. No un-redacted master is shipped alongside, and there is no reversible mask or key.
Fails closed
When a reviewer is unsure a region is fully covered, the clip is held or discarded — never downgraded and shipped to hit a deadline.
Consented subjects preserved
Anyone who signed a release — your operator, your talent — can stay in frame. The pass targets un-consented third parties, not your usable signal.
Auditable per file
Every output carries the detector version, timestamp, reviewer sign-off, and redaction settings, so a batch can be spot-checked against its own record.
You keep the source, or we destroy it
Your choice, in writing: we return only the anonymized output and securely delete the source, or return both to you and retain nothing.

FAQ

Questions teams ask first.

What is anonymization as a service?
Anonymization as a service is a managed pipeline you send footage to and receive it back de-identified: faces, licence plates, screens, and identifying speech automatically detected and irreversibly blurred, then confirmed by human review, with a per-file certificate of what was removed. You get the privacy outcome without building and staffing the detection, tracking, and QA yourself.
Why offer this — aren’t you a data-collection company?
It is the same pass we run on every egocentric dataset we deliver, exposed as a standalone service. We built irreversible face, plate, and screen redaction with human sign-off because our own captures happen in real homes, streets, and workplaces where bystanders end up in frame. Teams kept asking to run their own footage through it, so we made it available on its own.
What can you anonymize?
Faces and heads, licence plates, legible screens and documents, badges, distinctive marks on request, and identifying speech in audio — in video, image sets, or frame sequences. Pick the classes per project. Faces-only is the cheapest fit; the full pass covers everything that re-identifies an un-consented person.
Is the anonymization reversible?
No. Every redaction is baked into the delivered pixels — no reversible mask, no metadata toggle, no key. You can also have the un-redacted source securely destroyed, recorded in writing, so no identifiable master exists anywhere.
How do you handle our source footage and privacy?
Your choice, in writing: we return only the anonymized output and delete the source, or return both and retain nothing ourselves. Either way you receive a data-processing record suitable for a DPIA, listing what was redacted, how, and by whom.

Send a sample. See it come back clean.

Tell us what is in your footage and how much of it there is. We anonymize a sample, you confirm the classes and recall meet your bar, and then we run the rest to spec with a delivery date.