Security & privacy
When a building checks visitor IDs at the desk, the most important thing to know is what Veni does not keep: there is no photograph of anyone's ID anywhere in the system. Veni records the result of the check and a small amount of information about the document, and nothing else.
With Visitor ID check set to Optional or Required, the front desk scans the barcode on the back of the visitor's driver's licence or state ID using the Bluetooth scanner paired to the desk. The tablet's own camera faces the desk, not the counter, so it is never used for this.
The scan is read on the device. Veni compares the name to the name on the guest pass, then keeps the result. It does not run facial recognition, and it takes no picture.
Kept, tied to that entry:
Read on the device and immediately discarded, never sent to Veni:
The expiry is stored to the month rather than the day on purpose. A full expiry date sitting next to a name is meaningfully identifying, and month precision does everything the record is for.
Under Building Settings → Privacy & retention you set the ID-check retention window: 30, 60, or 90 days. When a record reaches the end of its window, Veni deletes it. Because there is no image and no file, the purge is a straight delete of the record itself, with nothing left behind in storage.
Every time someone reveals the name on an ID-check record, Veni writes an audit entry recording who looked and when. Audit ID-check access is always on and cannot be turned off.
The Document access rules in the same section control which roles can open visitor document artifacts at all, with separate settings for ID checks and Signed forms.
More in Security & privacy