Casino and Tribal Gaming Floors under Two Regulators

Two regulators watch the same floor, and the cameras are not the problem. Asking them a question, and showing afterwards who asked and on what grounds, is where a surveillance department runs out of road.

The Capability

Exclusion Lists, the Valet Lane, and the Record

Exclusion is the anchor use case. Banned-patron and self-exclusion lists are person lists like any other: the platform matches the live stream against the list your property enrolled, how close a match has to be is set camera by camera, and a hit reaches the surveillance desk with the frame attached for an officer to verify. The constraint is the one that applies everywhere else on this platform. Only pre-registered people are recognized, the database available for real-time biometric identification is deliberately restricted in size, and the system cannot identify or track a guest who is not on a list.

The vehicle side is the valet lane and the self-park entrance. Plate recognition reports make, model, color and type alongside the plate, and the same list mechanics that gate a parking barrier apply here.

What makes this vertical different is who reads the record afterwards. A gaming operation answers to a state regulator, and on tribal land to the nation’s own gaming authority as well. Every privacy-sensitive action on the platform requires a Case ID naming its lawful grounds, the log is append-only, and it is exported daily under signature so an oversight body can review it without being given access to the platform. Reviewing the record leaves a record.

Coverage

What a Surveillance Department Runs

Exclusion and Self-Exclusion

Real-time matching at entrances and on the floor against lists the property maintains, each match arriving with its frame for an officer to verify before anyone is approached.

See Ethical Facial Recognition

Valet and Self-Park

Plate plus make, model, color and type at the valet lane and the garage entrance, with permitted-vehicle control at the barrier.

See License Plate Recognition

Weapon Detection

A firearm shown at an entrance or on an approach, raised at the top priority. It is the one detector here that wants a GPU on the server.

See Weapon & Gunshot Detection

Crowd Density

Up to 3,000 people estimated across an area of a camera view, with real-time alerts and precise counting afterwards for the event review.

See Crowd Management

Investigations

From an incident to an evidence package: search the archive across the estate, follow the subject camera to camera, export what the file needs.

See Ask IREX & Video Search

Property-Specific ConditionsBeta

What your floor actually worries about, written as a sentence rather than waiting for a vendor module.

Explore StreamVLM™

For the Compliance File

What a Surveillance Director Can Put in Writing

  • The platform recognizes only pre-registered people. It cannot identify or track a guest who is not on a list, and that limit is enforced in the architecture rather than by policy alone.
  • The database available for real-time biometric identification is restricted in size, deliberately, and facial biometrics are handled as special-category personal data.
  • Every privacy-sensitive action requires a recorded lawful reason before it runs, list enrollment and live video viewing included. The record cannot be erased.
  • The log is exported daily under signature to an external archive, so an ethics committee, an auditor or a regulator can review it without platform access.
  • The property owns its data. IREX neither owns nor accesses it, and on-premises or tribally governed hosting keeps it inside the jurisdiction that governs the property.

Facts

Sovereignty
On-premises, private cloud, or fully air-gapped with no runtime internet dependency, on an open-source and inspectable stack. For a tribal operator that means data residency on infrastructure the nation itself governs.
No Certification Claimed
IREX holds no gaming-regulator approval, no ISO 27001 certificate and no SOC 2 attestation. The security management system is aligned with ISO/IEC 27001:2022, and compliance is established per deployment rather than asserted as a product property.
Support Tier
Premier Support adds 24×7 deployment health monitoring, weekend coverage for L1 and L2 escalations and mission-critical response times. A floor that cannot go dark is the case it exists for.

FAQ

Do you hold a gaming-regulator approval?

No, and we will not imply one. IREX holds no gaming-regulator certification, no ISO 27001 certificate and no SOC 2 attestation; the information-security management system is aligned with ISO/IEC 27001:2022. What the platform provides is the evidence a compliance review actually asks for: a mandatory recorded lawful reason on every privacy-sensitive action, an append-only log exported daily under signature, and a data-protection impact assessment before face recognition is switched on, which IREX requires on any instance it manages and advises on any instance you host yourself. Compliance is established per deployment, with your regulator, not claimed on a datasheet.

Can all of it run on our own infrastructure?

Yes. On-premises, private cloud, or fully air-gapped with no internet dependency at runtime, on an infrastructure stack that is open source and inspectable end to end. For a tribal operator that is usually the deciding requirement: the video, the events, the lists and the log stay on infrastructure the nation governs. Where the security organization also needs its own communications, Sover is a self-hosted, end-to-end encrypted platform that deploys the same way.

Is matching against a self-exclusion list lawful?

It depends on your jurisdiction and on the legal basis for the list itself, which is a question for counsel and your regulator before deployment rather than after. The platform is built to support the answer either way: only pre-registered people are recognized, the operator records the lawful grounds before the action runs, and the whole chain is auditable. IREX also runs background checks on prospective clients and declines business it judges high-risk on data collection and security.

Do we have to replace our cameras?

No. Reusing the existing fleet is the standard deployment model: any camera that supports ONVIF or streams RTSP with H.264 or H.265 on a static IP can be connected, and each module then sets its own resolution and placement requirements, which a site survey confirms. Note that connection is not plug-and-play: a qualified network engineer configures each camera and router.

Who owns the data?

You do. Customers retain 100% ownership and control of their data, and IREX neither owns nor accesses customer video, events, logs, watchlists, or floor plans. On-premises deployment is the data-residency mechanism.

How do we start?

With a pilot: one site, three to five use cases, six to twelve weeks, and two or three measurable success criteria agreed in writing before it begins. Accuracy is benchmarked on your own cameras, and the measured numbers go into the contract.

Pilot It on One Entrance

One entrance, one valet lane and your own exclusion list, measured over six to twelve weeks, is the honest way to judge this.