From a case in the corridor to a signed report.
One power lead. One lap of the room. Everything else happens inside the column. This page is the whole of it, including the parts that are not flattering.
- CASE One case. The column, its cameras, its network and its power supply are already inside it.
- PLACED At the front of the room, facing the seats. Nothing runs across the floor.
- POWER 90 s One lead into the wall. Press once, walk away, and it answers.
- PAIR once One press on your laptop. The window then closes for good.
- WALK one lap You walk the room while every camera reads you at the same time.
- DOORS live Measurement runs on the tower. You can close the laptop and go and work.
- SEAL A second, deeper pass over the whole session, then a signed report.
- PURGE The footage is deleted by the same step that issues the report.
The physical journey.
What an operator actually does, in the order they do it — from the moment the case is wheeled in to the moment the doors open.
One case. Nothing to assemble.
IRIS ships as a single sealed column. The compute, the two cameras, the network and the power supply are already inside it and already wired to each other. There is nothing to connect, and nothing to configure before the first event.
It has no screen, no keyboard and no status lights. Everything you learn about it, you learn from a laptop — which is a decision, not an omission. A screen on the tower is a screen the audience reads.
Shipping and installation are quoted per venue rather than listed here — a ballroom and a training room are not the same job. Tell us about the room and we will tell you what it takes.
At the front, facing the audience.
This is the one decision an operator can get wrong in a way that no amount of software recovers from, so it is worth being blunt about it.
The tower faces the people, because faces are what carry attention. Point it at the stage and you have built a very expensive camera pointed at a speaker who already knows what they did.
Getting it wrong is not silent. The calibration walk ends at the back wall, and if the tower cannot read you standing there, it says so in words before the doors open:
It stands at the front. The stage is behind the lenses.
could not read you at the back wall. The back rows will be counted at best, and may not be read at all — move the tower closer, or tell the client the back of the room is out of range.
That sentence is the product's own, and it is the reason placement is a five-minute conversation rather than a post-mortem. Rooms that cannot be covered by one column are worth a conversation too — tell us the dimensions.
One lead into the wall. It brings its own network.
Press the power button once and walk away. In about ninety seconds it is up. There is no screen to watch, so you ask it from your laptop — and it answers in one line, with no login:
READY nb-h1-k4m7q2xa cameras=2 disk=412.3GB session=none up=3m12sSpecimen answer — the shape of it, not your tower's numbers.
Every state it can be in names itself: STARTING while it comes up, PAIRING if it has never been claimed, READY, RECORDING, FINALIZING, or ERROR with the reason in the same line. READY is the only one that means there is nothing to do — which is the entire point of a machine with no screen.
There is no internet inside the tower, and that is the design: no SIM, no connection out of the room. The network your laptop joins is the router inside the column. No venue IT ticket, no guest-wifi password, no captive portal to click through — the tower cannot click I agree, so it is never asked to.
If that router ever fails you lose the way in, not the measurement. The tower keeps recording, a missing network shows up as a warning rather than an error, and an ethernet cable straight from your laptop to the column always works.
One press, once, and the door closes behind you.
A tower with cameras attached refuses to serve anything without a credential. A brand-new one generates its own on first boot and holds a short pairing window open so that you can collect it: open the console on the same network, press Collect token, and it is stored in that browser.
The window is fifteen minutes from boot, and the first successful claim closes it permanently — a power cycle does not reopen it. Claims from outside the local network are refused outright.
If a claim is ever refused as already claimed and it was not you who claimed it, treat that token as stolen: somebody else on that network holds admin on that tower. Power it down, reset it, take a fresh token, and tell whoever owns the venue network.
Write the token down. It is not shown a second time, and a second laptop needs it typed in. A tower that has never been claimed is not lost either — power-cycling it opens a fresh window, because the alternative on a screenless box is a brick.
One lap of the room, and it calibrates itself off you.
Setup asks for exactly one measurement — how far the back wall is, paced out. One long stride is close enough. Everything else the tower measures for itself while you walk.
Stand in the front row and face the tower
The nearest seat a guest will actually use. The stage is behind the tower, so facing it is exactly where the audience will be looking all evening.
Walk to the middle, and move your head four times
Face the tower. Turn your head to your left. Look down, as if at a phone in your hands. Look up at the ceiling. Those four positions are what the tower will read as attention, distraction and boredom for the rest of the event — measured on you, in this room, rather than assumed.
Walk to the back wall and face the tower
The furthest anyone will sit. If the tower loses you here, it will lose the back rows all night — which is exactly what this stop is for.
One lap, not one lap per camera. A single labelled position fans out to every camera that can currently see you, so a two-camera room costs the same walk as a one-camera room.
The direction of the stage is measured from your own head direction at each stop, never typed in — that reading is what makes the attention number mean anything. The floor plan is the one thing the walk cannot do for you: you draw the room, the stage and the zones you want attention measured against, and that step cannot be skipped.
How far it reads is a property of your room, not of a datasheet.
Every camera has a distance past which a face stops being a face and becomes a shape. IRIS does not pretend otherwise. It divides the room into read tiers and shows the operator where the line falls — in that room, before the doors open.
Close enough that the face is usable. These people contribute to the unique count, to attention, and to aggregate emotion.
Too far for the face, close enough for the body. They count as present, and they contribute nothing that needs a face.
Outside coverage. The walk says so out loud, so you can move the tower or add a second one. It is never quietly absorbed into the total.
The axis has no numbers on it. That is the honest version of this diagram.
Where each tier ends moves with the camera, the light, the shape of the room and where you put the tower. Printing a number here would be printing a number measured in somebody else's room, so the walk measures it in yours instead — and the report records what it found.
Light moves that line, and the tower says so out loud.
A dark room is a shorter room. The tower checks the light level on every camera on every frame, lifts what it can out of the shadows before it looks for faces, and raises the alert anyway:
The room is too dark for reliable face reading at distance. Numbers keep flowing, but the usable range is shorter until the lighting improves.
A shorter range you are told about during the reception is a different thing from a shorter range you discover in the report a week later. That is the whole reason the alert exists.
The data journey.
What is computed inside the column, what a single frame turns into, what is allowed out of the room, and what is deleted the moment the report is signed.
What a frame becomes — and what is left of it afterwards.
Every inference runs on the compute inside the column: finding faces, working out which way a head is pointing, grouping one person to themselves, reading expression in aggregate. There is no cloud step anywhere in the measurement path, and therefore no connection out of the room that can fail during an event.
Follow one frame all the way through and you can see exactly what is kept:
-
FRAME
An image from one of the two cameras, held on encrypted storage inside the column.
Deleted at export -
FACE
A box around each face, and the direction that head is pointing.
Deleted at export -
SIGNATURE
A mathematical signature of that face — a list of numbers, not a picture. It is what lets the tower tell one person from another without knowing who either of them is.
Deleted at export -
SESSION ID
An integer that groups a person to themselves. It is valid inside this one session and meaningless outside it.
Deleted at export -
AGGREGATE
Counts, attention shares, aggregate expression over time. No row about anybody.
Kept
The first four stages exist only while the event is running and only on the tower that captured them, on encrypted storage. The fifth is what the report is made of. There is no stage in that list where a name, an identity or a per-person record is created, because none is ever created at all.
One reading while you can still act on it. One after everyone leaves.
The live pass runs on the tower while the room is full and gives you what is worth acting on in the moment — who is present now, where attention is going, how the mood is moving. You can close the laptop; the tower does not need it.
When the event ends, a second and deeper pass re-reads the whole session at once. That is the pass that produces the final unique count, because grouping a person to themselves is more accurate with the entire evening in view than it can ever be as it happens. It takes minutes — on a long event, up to about thirty — and it has to be the last thing before the report is issued.
The number in the report is the second pass's number. The gap between it and the live figure is not hidden, and it is not an embarrassment: it is information about the room.
Three doors, and what is allowed through each one.
Worth stating precisely, because the interesting column is the last one.
| Path | What travels | What never travels |
|---|---|---|
| Tower → your laptop | The console itself, the live numbers, and the report. During setup, a still camera preview — that is how a camera gets aimed. | Nothing goes to the internet on this path. There is no internet on this path. |
| Tower → tower, same room | An anonymous per-person signature and a handful of small numbers, so that one person standing in both fields of view is counted once. | Images, frames, crops, thumbnails, video — in either direction. |
| Tower → cloud | Aggregate numbers only, and only if somebody switched it on. | Raw footage, and anything shaped like a per-person record. Off by default. |
The image rule between towers is enforced rather than promised: every message is checked before it is sent and checked again after it is received, and anything image-shaped — raw bytes, an image-shaped field name, a data URI — is refused with an error. A tower that tried to send a thumbnail would fail on the attempt rather than succeed quietly.
Signed — and then the footage is gone.
Export does two things in one step: it seals the report with a cryptographic signature and a verification id, and it deletes the raw footage. They are the same action deliberately, because a deletion that is a separate step is a deletion somebody forgets.
The signature covers the report's own content, so moving one number after issue breaks the seal. Verification runs against the file, locally — you do not need to contact us, or trust us, to confirm it.
Every transition above is written to a hash-chained audit log, so a step deleted or altered afterwards shows up as a break in the chain. If an operator deliberately switches retention on, the tower says so on its own notice and the footage stays until it is purged by hand — the worst outcome would be a notice asserting something the configuration contradicts.
Frames and everything derived from them on encrypted storage inside the tower. The only stage at which raw data exists.
The deep re-read across the whole session: the true unique count and the final metrics.
A signed report and aggregate numbers. This is the only thing that leaves the room.
Every frame and everything derived from it, deleted. What remains is aggregates and the signed report.
There is no accuracy figure on this site. Here is why, and what replaces it.
A number like ±3% means nothing without the distance it was measured at, the room it was measured in and the count it was measured against. We have not published one, because we have not yet measured one across enough real rooms to state it per distance band — and a single global percentage is exactly the kind of number that survives a sales meeting and dies in a venue.
The protocol that produces it is already written, and it is deliberately dull. At a pilot, one person walks the covered area every fifteen minutes with a tally counter and a phone: count everyone inside it, including the people facing away, and note roughly how many were near the tower, how many mid-room, how many beyond. Afterwards each of those walks is compared against the report's own timeline at the same timestamp, per distance band.
Three pilots of that, and there is a figure worth printing. Until then there is a method, which is more than a percentage in a brochure is.
Pilot terms — including accuracy — are agreed in writing with every founding client.
When there is a measured figure it will be published with its range and per distance band — never as one number, and never before it exists.
See it in your room.
Register your interest. No payment is taken, and we talk to you before ordering opens.