Skip to main content
Trust & Security

Privacy-first AI for eldercare

SilverGuard AI is built on a simple promise: predict, prevent, and prove — without compromising the privacy or dignity of the people in care.

Introduction

We help Hong Kong residential care homes for the elderly (RCHEs) and care operators upgrade their existing CCTV and compatible sensors into a privacy-first AI safety and compliance co-pilot. This page explains the principles, controls, and processes that protect residents, families, staff, and operators when they use SilverGuard AI.

Last updated: 27 April 2026

Boundaries by design

What we do not do

Privacy is not an afterthought. The following are deliberate product choices and are enforced in our architecture.

No facial-recognition database

We do not build, store, or query a facial-recognition database to identify residents, staff, or visitors.

No biometric identity tracking

We do not enrol, match, or persist biometric identifiers for the purpose of identifying individuals.

No hidden resident scoring for marketing

Risk and care signals are used only to support care decisions and compliance — never sold or repurposed for advertising.

No unnecessary raw video export

Raw footage is not exported by default. Where short evidence clips are needed, access is role-based, time-limited, and logged.

Architecture

Security-by-design architecture

SilverGuard AI is software-first and deployable without ripping out existing infrastructure. Where appropriate, inference happens at the edge, inside the care home’s own network.

Edge-first / on-prem inference

Pose and event detection runs on edge devices inside the care home where appropriate, reducing data movement and latency.

Role-based access

Staff see only what their role requires. Carers, supervisors, administrators, and auditors each have separate, least-privilege roles.

Event-based logging

System actions, alert acknowledgements, and access events are logged with timestamps for review and incident reconstruction.

Short retention

We retain operational data for the minimum period needed to deliver the safety and compliance service and to meet operator obligations.

Encrypted transport

Connections between cameras, edge devices, and the SilverGuard platform use modern TLS. Public web traffic is HTTPS-only with HSTS.

Least-privilege access

Internal access to production systems is restricted, multi-factor authenticated, and reviewed. Secrets are managed outside source code.

Operations

Compliance-ready operations

SilverGuard AI is designed to support the governance expectations placed on Hong Kong RCHE operators, including the privacy expectations of the Office of the Privacy Commissioner for Personal Data (PCPD).

Audit Pack / Trust Pack

Operators can produce tamper-evident packs that document what the system saw, what it did, and who responded — for reviews, audits, and regulator queries.

Action timeline

Each event includes a clear timeline: detection, alert dispatch, staff acknowledgement, and resolution.

Access logs

Who viewed what, when, from where. Logs are append-only and reviewable by operator administrators.

Incident review support

Operators get the artefacts they need to run a fair, evidence-based incident review with clinical and operational stakeholders.

Human-in-the-loop

AI supports carers — it does not replace them

SilverGuard AI surfaces signals to qualified care staff. Final care decisions rest with humans. We do not provide autonomous clinical diagnoses and we do not replace professional care judgement.

Read more about our principles in the AI Governance statement.

Responsible disclosure

Reporting a suspected vulnerability

If you believe you have found a security issue affecting silverguard.ai or any SilverGuard AI public asset, please contact us at security@silverguard.ai with a clear description, reproduction steps, and potential impact.

Please give us a reasonable amount of time to investigate and remediate before any public disclosure. We are grateful for responsible disclosure and will credit researchers on request once an issue is verified and fixed.

Our machine-readable disclosure policy follows RFC 9116 (security.txt). Full guidance is available on our Responsible Disclosure page.

CYBERSEC ONE readiness

SilverGuard AI is strengthening its website and organisational cybersecurity practices through HKIRC CYBERSEC ONE / Healthy Web assessment processes.

We do not claim certifications or endorsements that have not been formally granted. This page will be updated as assessments are completed.

Scope. This page describes the public corporate website (silverguard.ai) and the principles applied to the SilverGuard AI care-home product platform. Detailed technical, contractual, and data-processing terms for deployments are agreed separately with each operator and are not public.