FaceOff Technologies has launched FaceOff Privacy and Security in a Box, an appliance that runs the company’s entire data security and data privacy suite on hardware sitting inside the customer’s own premises. Nothing is sent outside for processing. The product was introduced at the 15th Eastern India Information Technology Fair, held at Hotel The Park in Kolkata and organised by VARINDIA under the theme “Alliances for Growth in a DPDP-Ready India”.
The unit itself is small. It is a low weight small box, which puts it on a desk or in a branch cabinet rather than in a rack. Inside that footprint it carries around one petaFLOP of AI compute, coherent unified memory shared between processor and graphics units, and self-encrypting solid-state storage. That capacity is what allows models of up to 200 billion parameters to run locally, with two units paired together handling up to 405 billion. Connectivity covers 10 Gigabit Ethernet, high-speed interconnect for pairing, Wi-Fi and four USB Type-C ports. The appliance is described as plug and play, portable, and able to operate in a fully air-gapped environment.
The appliance carries the security engines FaceOff sells individually. SyntheticMediaGuard examines images, video, audio, documents, browser media and live virtual meetings for signs that the material was generated or edited rather than captured by a camera. BehaviorID handles liveness checks and behavioural analysis, so an approval arrives with a record of who gave it. Voice Forensics combines speaker verification, acoustic profiling and real-time screening of inbound calls, which the company positions against cloned voices and caller fraud. Zero-Trust Identity verifies credentials using post-quantum signatures and secure QR, and runs identity-graph analysis on the result. TrustShield OSINT works through public information and the connections between identities across platforms. Video Intelligence makes an existing camera network searchable by attribute, follows movement from one camera to the next and watches protected zones.
On the privacy side, the same unit runs consent management with region-aware banners and versioned records of what each person agreed to, continuous cookie scanning that holds scripts until policy allows them to run, and an Intelligent Data Mapper that classifies personal data across clouds, warehouses and SaaS applications rather than relying on a declared inventory. Guided PIA and DPIA assessments, DSAR intake and fulfilment tracked against the statutory clock, and an evidence timeline that builds itself are all part of the same package. A copilot reads more than 1,200 regulations against the customer’s own controls and answers with citations attached. PromptShield inspects prompts, files and context before they reach any model, masking, redacting or blocking sensitive data, secrets and injection attempts. An in-house small language model keeps prompts and findings inside the perimeter. All fifteen engines feed a single scoring layer, and each verdict is returned with the observations behind it instead of a bare number.
FaceOff’s argument for the format is that certain risks stop existing rather than being managed. With no outbound route, there is nothing in flight to intercept or mirror. The models run on the customer’s own hardware, so faces, voices and documents are never uploaded or pooled into training data. The append-only log of what was checked, what was found and what was done stays on equipment the customer owns. If the network link is thin or goes down entirely, enforcement carries on unchanged, which the company points at branch offices, hospitals and remote sites.
The pressure behind all of this is the DPDP Act, where a failure of reasonable security safeguards attracts penalties of up to Rs 250 crore, assessed per instance, with compliance due by May 2027. FaceOff Technologies is CERT-In empanelled and holds ISO/IEC 27001, 27701 and 42001:2023 certification, along with a SOC 2 Type II audit.
