Union Home Minister Amit Shah inaugurated the latest phase of Delhi Police's Safe City project in February 2026. By that point, according to the Internet Freedom Foundation, roughly 25,000 CCTV cameras, new AI-enabled installations plus feeds from the Delhi Metro and Indian Railways, were already tied into the force's Integrated Command, Control, Communication and Computer Centre, known internally as C4I. That single command room now sits at the middle of video analytics, distress detection, and dispatch coordination that used to run as separate, disconnected efforts across different units.
That consolidation is the real story behind most modern law enforcement technology procurement, and it applies well beyond video. Agencies that buy an OSINT tool, a dark web monitoring service, and an AI-based video surveillance system as three separate line items usually end up with three separate vendors, three separate logins, and three teams that only compare notes after something has already gone wrong. A case rarely respects those boundaries. A missing-person investigation might need a dark web check, a facial or gait match from a CCTV feed, and a social media trace, all at once, and a converged product suite exists specifically so those three do not sit in three different silos waiting for someone to connect them manually.
Here is where a lot of vendor material stops short. Pulling OSINT, dark web intelligence, and AI-driven video analytics into one operational picture is not just a technical integration question. It is also a legal and governance one, since video surveillance and open-source monitoring both touch personal data at scale, and courts in India have already set out a clear standard, the Puttaswamy proportionality test, that any state deployment of this kind has to satisfy. Build the technical convergence without the governance layer and the programme becomes exactly the kind of surveillance effort currently facing litigation and public scrutiny elsewhere in the country.
This guide covers what a converged OSINT, dark web, and AI surveillance suite actually needs to do, how SecNinjaz's WebMine and NAINA map onto those three capability areas, how the legal framework around DPDP and constitutional privacy law applies, what happens when the governance layer is missing, and a readiness playbook for agencies building this out. It is written for state cyber cells, Smart City command centre teams, and the procurement and legal officers who have to sign off on all of it together.
Talk to Our Security Experts →
Three Capabilities, One Operational Picture
| Capability | What it covers | Where it fits in an investigation |
|---|---|---|
| OSINT and dark web intelligence | Collection and correlation across 250+ open and dark web sources, in 41+ languages, with real-time monitoring for active cases | Building a case file: tracing an alias, a wallet, a vendor listing, or a leaked dataset |
| AI-based video surveillance and imagery analytics | Turning raw CCTV and imagery feeds into structured alerts and narratives rather than hours of footage nobody has time to watch | Real-time situational awareness: flagging an incident, a distress signal, or a pattern worth an operator's attention |
| Command and case coordination | A shared reference that ties findings from both of the above to the same case, the same authorization, and the same audit trail | Ensuring a lead from one system reaches the team working the other before the trail goes cold |
SecNinjaz builds the first two of these directly, through WebMine and NAINA, both part of the company's Product Engineering practice alongside its Sovereign Messenger, textr. The third, coordination, is less a product than a discipline, and it is the piece an agency has to build deliberately rather than assume a purchase order will deliver on its own.
Why Indian Agencies Are Converging Toward This Model

The scale involved makes the case on its own. Delhi's Safe City project alone is expected to bring around 10,000 new AI-enabled cameras online alongside roughly 15,000 existing ones once every phase is complete, funded through the central government's Nirbhaya Fund at an estimated cost of about 800 crore rupees, with more than 30 separate data sets being integrated into the system. Noida's own Safe City rollout, a smaller Rs 212 crore project covering close to 2,000 cameras, follows the same pattern: a centralized command and control centre, automatic number plate recognition, and a unified monitoring platform rather than a scattering of disconnected feeds. Bengaluru has been running a comparable system since 2023.
Market growth reflects the same direction. Industry estimates put India's AI-powered CCTV market at roughly 827 million dollars in 2023, projected to reach 3.66 billion dollars by 2030, a compound annual growth rate above 21%. None of that growth is really about buying more cameras. It is about what sits behind the cameras, the analytics layer that decides which of a thousand simultaneous feeds actually deserves a human being's attention right now, and whether that layer can be connected to the intelligence work happening on OSINT and dark web sources at the same time.
WebMine: OSINT and Dark Web Intelligence
WebMine, SecNinjaz's AI-powered OSINT platform, draws from more than 250 sources spanning the open web and the dark web, runs real-time monitoring for active cases, applies AI-driven investigation tools for entity matching and cross-referencing, and supports 41+ languages. In practice, that means an authorized search runs across forums, marketplaces, public records, and leaked datasets in parallel, surfaces candidate matches with a confidence score attached, and routes anything corroborated toward a structured, source-attributed report rather than a pile of unverified screenshots. The depth of how that workflow runs, from intake authorization through corroboration to a courtroom-ready record, is a topic of its own. What matters here is where it sits in the wider suite: it is the intelligence-gathering layer that a video-first command centre typically lacks entirely.
NAINA: AI-Based Imagery Narrative Analytics
NAINA is SecNinjaz's surveillance suite, built around AI-based imagery narrative analytics. The core idea addresses a problem every command centre eventually runs into: a human operator cannot meaningfully watch hundreds of live feeds at once, and reviewing archived footage after the fact is slow enough that the useful window for acting on it often closes first. Systems in this category are built to turn raw video and imagery into structured narratives, a description of what happened, when, and where, rather than leaving an operator to scrub through hours of recording manually.
The pattern already playing out in projects like Delhi's Safe City initiative shows what this looks like operationally: AI video analytics tuned to flag specific situations, an isolated individual surrounded by a group, a distress gesture, an unattended object, generating an alert that reaches a command centre and, from there, the relevant field unit, without waiting for someone to file a formal complaint first. That is the operational model NAINA is designed to support, converting a wall of camera feeds into a manageable stream of prioritized, narrated events for a command centre team to act on.
How the Two Capabilities Reinforce Each Other
| Stage | OSINT and dark web role | AI surveillance role |
|---|---|---|
| Before an incident | Monitoring forums, marketplaces, and social channels for early warning signs tied to a known threat or case | Passive monitoring of public spaces for patterns that warrant attention |
| During an active case | Correlating online activity, an alias, a listing, a leaked record, with what is happening on the ground | Real-time alerts that trigger dispatch and give responding officers immediate context |
| Building the case file | Structured, source-attributed intelligence tied to a specific finding and timestamp | Timestamped imagery and video narratives that corroborate or challenge the online intelligence |
Run separately, each capability answers part of a question. Run against the same case reference, with a shared authorization and audit trail, they answer more of it faster, which is the entire argument for treating this as a suite rather than two unrelated purchases.
The Legal Framework Behind Any of This
Faster intelligence and faster surveillance do not move the constitutional and statutory boundaries this work operates inside, and that framework deserves more attention than most product overviews give it.
The Supreme Court's 2017 judgment in Justice K.S. Puttaswamy v. Union of India recognized privacy as a fundamental right and set out a four-part proportionality test that any state action affecting it has to satisfy: the action must be authorized by a valid law, it must serve a legitimate aim, the means used must be proportionate to that aim, and it must include procedural safeguards against abuse. That test now governs how courts assess surveillance programmes, interception orders, and facial recognition deployments across the country, and it is squarely the standard a converged OSINT and video surveillance deployment needs to be built against from the start rather than defended after a challenge.
On the statutory side, India's DPDP Act, 2023 gives government bodies a specific route for processing personal data without consent. Section 17(2)(a) permits the state and its instrumentalities to process personal data without consent where necessary to perform a function under any law currently in force, or in the interest of the sovereignty and integrity of India or the security of the state. That is a broader exemption than the one covering criminal investigation specifically, and it is the provision most directly relevant to large-scale public surveillance infrastructure like a Safe City deployment. It is also, worth noting plainly, one of the more contested parts of the Act: civil society groups and privacy researchers have flagged the breadth of this exemption as a gap in oversight, and constitutional challenges to the DPDP Act's state exemptions are currently before a Constitution Bench of the Supreme Court. An agency deploying this kind of technology should expect that scrutiny to continue, not treat the exemption as a settled matter closed to further legal or public debate.
What Happens When the Governance Layer Is Missing
| Gap | Consequence |
|---|---|
| No documented legal basis before deployment | Exposure to exactly the kind of constitutional challenge already running against comparable programmes, and project delays while that plays out |
| No retention policy for stored imagery | Conflicts with the DPDP Act's broader security-safeguard expectations, even where the initial collection itself was lawful |
| OSINT and video surveillance run as separate silos | The slower, disconnected response the convergence model was meant to fix in the first place resurfaces anyway |
| AI-flagged alerts treated as confirmed rather than triggers for verification | Wasted dispatch resources on false positives, and reduced trust in the system among the officers relying on it |
| No audit trail tied to each alert or search | Failure to satisfy the fourth prong of the Puttaswamy test, procedural safeguards against abuse, regardless of how sound the underlying technology is |
A Maturity Model for Converged Intelligence and Surveillance
Most agencies sit somewhere on a five-level path between disconnected tools and a genuinely unified operational picture.
Level 1: Standalone CCTV with no analytics, and OSINT lookups done manually and separately ↓ Level 2: AI video analytics running live, but isolated from OSINT and dark web monitoring entirely ↓ Level 3: A command centre aggregates video alerts, while OSINT and dark web work stays on a separate desk ↓ Level 4: Shared case references link video alerts to open and dark web intelligence for the same investigation ↓ Level 5: A continuous, unified operational picture across all three capability areas, with the legal basis for each use documented as it happens
Jumping straight to Level 4 or 5 without the documented legal basis that Level 5 assumes is how a technically impressive deployment ends up as a case study in exactly the kind of scrutiny described above.
A Readiness Playbook for Building This Out
- Map every current tool across OSINT, dark web monitoring, and video surveillance to find out where the existing silos actually sit before adding anything new.
- Document the legal basis for each capability against the Puttaswamy four-part test before deploying, not as a defence prepared after a challenge arrives.
- Set a retention policy for stored imagery and intelligence findings, consistent with the DPDP Act's broader security-safeguard expectations.
- Establish a shared case reference system so an alert from the video layer and a finding from the OSINT layer can be tied to the same investigation automatically.
- Train command centre operators to treat AI-flagged alerts as triggers for verification, not as confirmed incidents requiring no further check.
- Build audit logging across all three capability areas from the outset, covering who searched what, when an alert fired, and who reviewed it.
- Pilot the convergence on one high-priority case type, missing persons is a common starting point, before rolling it out across every case category at once.
- Review the legal basis and retention policy on a fixed schedule as the deployment scales, rather than treating the initial sign-off as permanent.
Common Mistakes and Edge Cases
Treating an AI-flagged video alert as a confirmed incident. The alert is a reason to look, not a finding on its own, and dispatching resources on that basis alone wastes them when the alert turns out to be a false positive.
Deploying surveillance infrastructure ahead of the legal-basis documentation. Building the technical capability first and working out the Puttaswamy justification afterward is backwards, and it is exactly the sequence current litigation against comparable programmes is challenging.
Letting OSINT and video surveillance teams operate as separate silos regardless of the technology purchased. A converged product suite does not create converged operations on its own; the case-reference discipline connecting the two has to be built deliberately.
Having no defined retention or deletion policy for stored imagery. Data collected lawfully at the point of capture can still create exposure if it is retained indefinitely with no documented reason.
Assuming procurement itself is the safeguard. Buying a system described as compliant does not substitute for the agency's own documented authorization, audit trail, and oversight process.
Ignoring the transparency expectations civil society groups have already raised. Programmes that operate with limited public information about their scope and safeguards invite exactly the kind of legal and public challenge several comparable Indian surveillance projects are currently facing.
When to Use What: A Few Decision Points
A centralized command centre versus distributed station-level access. A city-scale deployment benefits from centralizing both video and OSINT access through one command structure, which keeps authorization and audit practice consistent. A smaller unit with a narrower case load may reasonably keep access more distributed without losing that consistency.
Full convergence from day one versus a phased rollout. An agency with mature infrastructure in both video analytics and OSINT can move toward convergence directly. One building either capability from a standing start typically gets more value from proving out one capability first and connecting the second once the first is operating reliably.
In-house monitoring versus AI-assisted triage at scale. A command centre handling a modest number of camera feeds and cases can manage manual review. Once feed count and alert volume outpace what operators can triage by hand, AI-assisted narrative analytics becomes less of an upgrade and more of a requirement for the system to function at all.
How SecNinjaz Fits Into This
WebMine and NAINA sit within SecNinjaz's Product Engineering practice, alongside the company's Sovereign Messenger, textr, giving an agency the intelligence and surveillance layers of a converged operational picture from a single technology partner rather than several. The governance layer this guide spends most of its time on, documenting the legal basis, building the audit trail, and mapping obligations under the DPDP Act, runs through SecNinjaz's GRC and DPDP practice, covering Regulatory Compliance, Risk Management, and Audit and Gap Assessment.
Because both OSINT intelligence and surveillance imagery represent exactly the kind of sensitive data an attacker would want, SecNinjaz's Cybersecurity practice, Vulnerability Assessment, Penetration Testing, Red Teaming, and AI SOC Automation, also has a direct role in hardening the infrastructure a converged suite depends on. SecNinjaz holds ISO/IEC 27001:2022 for information security and ISO/IEC 27701:2025 for privacy information management, the certifications most directly relevant to handling both the intelligence data a platform like WebMine collects and the imagery data a system like NAINA processes. For agencies building this kind of converged capability rather than assembling it tool by tool, that combination of product depth, governance discipline, and security hardening is the pairing worth looking for, whether the agency works with SecNinjaz or anyone else.
Talk to Our Security Experts →
Frequently Asked Questions
What is the difference between WebMine and NAINA?
WebMine is SecNinjaz's OSINT and dark web intelligence platform, covering more than 250 open and dark web sources across 41+ languages with real-time monitoring and AI-driven investigation tools. NAINA is SecNinjaz's surveillance suite, built around AI-based imagery narrative analytics that turn raw CCTV and video feeds into structured alerts and narratives. They cover different data types, online intelligence versus physical-world imagery, and are designed to work together against the same case.
Why should OSINT, dark web monitoring, and video surveillance be run as one system rather than separate tools?
A real investigation rarely stays inside one data type. A missing-person case, for example, might need a dark web check, a facial or pattern match from CCTV footage, and a social media trace at the same time. Running these as separate tools with no shared case reference means findings from one system often reach the team working another only after the trail has gone cold.
What legal standard applies to AI surveillance deployments in India?
The Supreme Court's 2017 Puttaswamy judgment set out a four-part proportionality test for any state action affecting the right to privacy: the action must be authorized by law, serve a legitimate aim, use proportionate means, and include procedural safeguards against abuse. Courts have applied this standard to surveillance programmes, interception orders, and facial recognition deployments since the judgment, and it is the framework any AI surveillance rollout needs to satisfy.
Can Indian government agencies process personal data from surveillance systems without consent?
Section 17(2)(a) of the DPDP Act, 2023 permits the state and its instrumentalities to process personal data without consent where necessary to perform a function under law, or in the interest of the sovereignty and integrity of India or the security of the state. This exemption is broader than the one covering criminal investigation specifically, and it is currently one of the more contested provisions of the Act, with constitutional challenges before a Supreme Court Constitution Bench.
How does AI-based imagery narrative analytics differ from ordinary CCTV monitoring?
Ordinary CCTV requires a human operator to watch live feeds or review archived footage manually, which does not scale past a small number of cameras. AI-based imagery narrative analytics processes feeds continuously and converts them into structured narratives, a description of what happened, when, and where, so operators see a prioritized stream of flagged events instead of hours of undifferentiated footage.
What is the biggest risk in deploying a converged OSINT and surveillance system?
Building the technical capability before documenting its legal basis. Several Indian surveillance programmes are currently facing litigation and public scrutiny in part because the scale of deployment outpaced clear, public documentation of the safeguards behind it. Treating the Puttaswamy proportionality test as a design requirement from the outset, rather than a defence prepared after a challenge, is the most reliable way to avoid that outcome.
Does SecNinjaz offer these capabilities as one integrated product?
WebMine and NAINA are both part of SecNinjaz's Product Engineering practice, alongside the Sovereign Messenger, textr, and are built to support a converged operational picture for agencies that need both intelligence gathering and video surveillance. The governance and security work needed to run them responsibly, legal basis documentation, audit trails, and infrastructure hardening, runs through SecNinjaz's GRC and Cybersecurity practices alongside the products themselves.
Where should an agency start if it is running OSINT and video surveillance as separate systems today?
Start by mapping every current tool across both areas to identify where the existing silos sit, then document the legal basis for each capability against the Puttaswamy four-part test before adding anything new. Piloting convergence against a single high-priority case type, such as missing-person investigations, tends to surface the practical gaps in case referencing and audit logging before a full-scale rollout does.










