{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/onvif-profile-m-analytics-metadata-boundaries/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/",
        "slug": "onvif-profile-m-analytics-metadata-boundaries",
        "url": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/onvif-profile-m-analytics-metadata-boundaries/"
        },
        "title": "ONVIF Profile M: what analytics metadata interoperability does—and does not—prove",
        "summary": "Profile M standardizes analytics metadata and events between products. It does not certify analytic accuracy, lawful use, model quality, or every conditional feature.",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            },
            {
                "slug": "video-surveillance",
                "name": "Video Surveillance",
                "url": "https://update.dsesecurity.com/topic/video-surveillance/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-19T21:28:39+00:00",
        "modified_at": "2026-07-19T21:28:39+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 2,
        "word_count": 425,
        "potentially_affected": "Organizations evaluating or operating cameras, analytics services, VMS platforms, NVRs, cloud services, MQTT integrations, or access workflows that exchange analytics metadata.",
        "dse_recommendation": "Specify the exact metadata and events required, verify both producer and consumer conformance, and test interoperability separately from analytic performance and privacy.",
        "primary_source": {
            "name": "ONVIF — Profile M",
            "url": "https://www.onvif.org/profiles/profile-m/",
            "published_on": null,
            "authority": "ONVIF"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>What Profile M standardizes</h2>\n<p><strong>Source fact:</strong> ONVIF Profile M addresses metadata and events for analytics applications. Its defined interfaces include analytics configuration and information queries, metadata configuration and streaming, filtering, generic object classification, and specified metadata for geolocation, vehicles, license plates, human faces, and human bodies.</p>\n<p>The profile also includes event interfaces for object counting, face recognition, and license-plate recognition. ONVIF explains that these interfaces apply when a conformant product natively supports the corresponding feature. Events can travel through a metadata stream, the ONVIF event service, or MQTT when MQTT is supported. Rule configuration and images in metadata are also subject to the product&#8217;s supported capabilities.</p>\n<p>A Profile M producer can be an edge device such as an IP camera or a server- or cloud-based analytics service. A client can be a VMS, NVR, analytics application, or server/cloud service that consumes or controls metadata. Profile M can be combined with video and access-control profiles, but each claimed profile and exact software version must be verified independently.</p>\n\n<h2>What conformance does not measure</h2>\n<p>Profile M defines interfaces and data structures. It does not certify detection accuracy, false-alarm rate, demographic performance, training data, model security, image suitability, evidentiary value, or compliance with privacy law. It also does not mean every possible object, event, MQTT function, or rule is present; the distinction between mandatory and conditional features still applies.</p>\n<p>Two conformant products can exchange metadata and still produce different operator experiences, search results, event timing, or analytic outcomes. Accuracy and suitability must therefore be evaluated with representative scenes and a documented purpose, separate from the protocol test.</p>\n\n<h2>DSE evaluation checklist</h2>\n<p><strong>DSE recommendation:</strong> The following is DSE operational synthesis, not an ONVIF accuracy or privacy standard.</p>\n<ol>\n<li>Write the security or operational use case before selecting object classes or events.</li>\n<li>List required fields, event transports, images, rules, timestamps, identifiers, and downstream actions.</li>\n<li>Verify the exact Profile M record and feature documents for every producer and consumer.</li>\n<li>Bench-test configuration, filtering, event delivery, metadata preservation, time alignment, reconnect behavior, and search.</li>\n<li>Measure false positives and false negatives with representative site conditions; do not infer accuracy from conformance.</li>\n<li>Complete a privacy assessment covering purpose, notice, access, retention, sharing, and any biometric or identifying data.</li>\n<li>Require human review and a safe failure path before metadata triggers a consequential physical or business action.</li>\n<li>Retest after model, camera, VMS, rule, or firmware changes.</li>\n</ol>\n\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://www.onvif.org/profiles/profile-m/\" target=\"_blank\" rel=\"noopener noreferrer\">Profile M</a> — current feature, producer, client, event, and conditional-capability scope.</li>\n<li><a href=\"https://www.onvif.org/blog/2021/06/30/onvif-announces-the-release-of-profile-m/\" target=\"_blank\" rel=\"noopener noreferrer\">ONVIF announces the release of Profile M</a> — the June 30, 2021 release and interoperability use cases.</li>\n<li><a href=\"https://www.onvif.org/conformant-products/\" target=\"_blank\" rel=\"noopener noreferrer\">Conformant Products</a> — authoritative model and version verification.</li>\n</ul>",
        "content_text": "What Profile M standardizes\nSource fact: ONVIF Profile M addresses metadata and events for analytics applications. Its defined interfaces include analytics configuration and information queries, metadata configuration and streaming, filtering, generic object classification, and specified metadata for geolocation, vehicles, license plates, human faces, and human bodies.\nThe profile also includes event interfaces for object counting, face recognition, and license-plate recognition. ONVIF explains that these interfaces apply when a conformant product natively supports the corresponding feature. Events can travel through a metadata stream, the ONVIF event service, or MQTT when MQTT is supported. Rule configuration and images in metadata are also subject to the product’s supported capabilities.\nA Profile M producer can be an edge device such as an IP camera or a server- or cloud-based analytics service. A client can be a VMS, NVR, analytics application, or server/cloud service that consumes or controls metadata. Profile M can be combined with video and access-control profiles, but each claimed profile and exact software version must be verified independently.\n\nWhat conformance does not measure\nProfile M defines interfaces and data structures. It does not certify detection accuracy, false-alarm rate, demographic performance, training data, model security, image suitability, evidentiary value, or compliance with privacy law. It also does not mean every possible object, event, MQTT function, or rule is present; the distinction between mandatory and conditional features still applies.\nTwo conformant products can exchange metadata and still produce different operator experiences, search results, event timing, or analytic outcomes. Accuracy and suitability must therefore be evaluated with representative scenes and a documented purpose, separate from the protocol test.\n\nDSE evaluation checklist\nDSE recommendation: The following is DSE operational synthesis, not an ONVIF accuracy or privacy standard.\n\nWrite the security or operational use case before selecting object classes or events.\nList required fields, event transports, images, rules, timestamps, identifiers, and downstream actions.\nVerify the exact Profile M record and feature documents for every producer and consumer.\nBench-test configuration, filtering, event delivery, metadata preservation, time alignment, reconnect behavior, and search.\nMeasure false positives and false negatives with representative site conditions; do not infer accuracy from conformance.\nComplete a privacy assessment covering purpose, notice, access, retention, sharing, and any biometric or identifying data.\nRequire human review and a safe failure path before metadata triggers a consequential physical or business action.\nRetest after model, camera, VMS, rule, or firmware changes.\n\nOfficial references\n\nProfile M — current feature, producer, client, event, and conditional-capability scope.\nONVIF announces the release of Profile M — the June 30, 2021 release and interoperability use cases.\nConformant Products — authoritative model and version verification.",
        "content_markdown": "## What Profile M standardizes\n\nSource fact: ONVIF Profile M addresses metadata and events for analytics applications. Its defined interfaces include analytics configuration and information queries, metadata configuration and streaming, filtering, generic object classification, and specified metadata for geolocation, vehicles, license plates, human faces, and human bodies.\n\nThe profile also includes event interfaces for object counting, face recognition, and license-plate recognition. ONVIF explains that these interfaces apply when a conformant product natively supports the corresponding feature. Events can travel through a metadata stream, the ONVIF event service, or MQTT when MQTT is supported. Rule configuration and images in metadata are also subject to the product’s supported capabilities.\n\nA Profile M producer can be an edge device such as an IP camera or a server- or cloud-based analytics service. A client can be a VMS, NVR, analytics application, or server/cloud service that consumes or controls metadata. Profile M can be combined with video and access-control profiles, but each claimed profile and exact software version must be verified independently.\n\n## What conformance does not measure\n\nProfile M defines interfaces and data structures. It does not certify detection accuracy, false-alarm rate, demographic performance, training data, model security, image suitability, evidentiary value, or compliance with privacy law. It also does not mean every possible object, event, MQTT function, or rule is present; the distinction between mandatory and conditional features still applies.\n\nTwo conformant products can exchange metadata and still produce different operator experiences, search results, event timing, or analytic outcomes. Accuracy and suitability must therefore be evaluated with representative scenes and a documented purpose, separate from the protocol test.\n\n## DSE evaluation checklist\n\nDSE recommendation: The following is DSE operational synthesis, not an ONVIF accuracy or privacy standard.\n\n- Write the security or operational use case before selecting object classes or events.\n\n- List required fields, event transports, images, rules, timestamps, identifiers, and downstream actions.\n\n- Verify the exact Profile M record and feature documents for every producer and consumer.\n\n- Bench-test configuration, filtering, event delivery, metadata preservation, time alignment, reconnect behavior, and search.\n\n- Measure false positives and false negatives with representative site conditions; do not infer accuracy from conformance.\n\n- Complete a privacy assessment covering purpose, notice, access, retention, sharing, and any biometric or identifying data.\n\n- Require human review and a safe failure path before metadata triggers a consequential physical or business action.\n\n- Retest after model, camera, VMS, rule, or firmware changes.\n\n## Official references\n\n- [Profile M](https://www.onvif.org/profiles/profile-m/) — current feature, producer, client, event, and conditional-capability scope.\n\n- [ONVIF announces the release of Profile M](https://www.onvif.org/blog/2021/06/30/onvif-announces-the-release-of-profile-m/) — the June 30, 2021 release and interoperability use cases.\n\n- [Conformant Products](https://www.onvif.org/conformant-products/) — authoritative model and version verification."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/",
                "url": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "ONVIF Profile M: what analytics metadata interoperability does—and does not—prove",
                        "item": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/#article",
                "identifier": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/",
                "url": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/",
                "headline": "ONVIF Profile M: what analytics metadata interoperability does—and does not—prove",
                "description": "Profile M standardizes analytics metadata and events between products. It does not certify analytic accuracy, lawful use, model quality, or every…",
                "abstract": "Profile M standardizes analytics metadata and events between products. It does not certify analytic accuracy, lawful use, model quality, or every conditional feature.",
                "articleBody": "What Profile M standardizes\nSource fact: ONVIF Profile M addresses metadata and events for analytics applications. Its defined interfaces include analytics configuration and information queries, metadata configuration and streaming, filtering, generic object classification, and specified metadata for geolocation, vehicles, license plates, human faces, and human bodies.\nThe profile also includes event interfaces for object counting, face recognition, and license-plate recognition. ONVIF explains that these interfaces apply when a conformant product natively supports the corresponding feature. Events can travel through a metadata stream, the ONVIF event service, or MQTT when MQTT is supported. Rule configuration and images in metadata are also subject to the product’s supported capabilities.\nA Profile M producer can be an edge device such as an IP camera or a server- or cloud-based analytics service. A client can be a VMS, NVR, analytics application, or server/cloud service that consumes or controls metadata. Profile M can be combined with video and access-control profiles, but each claimed profile and exact software version must be verified independently.\n\nWhat conformance does not measure\nProfile M defines interfaces and data structures. It does not certify detection accuracy, false-alarm rate, demographic performance, training data, model security, image suitability, evidentiary value, or compliance with privacy law. It also does not mean every possible object, event, MQTT function, or rule is present; the distinction between mandatory and conditional features still applies.\nTwo conformant products can exchange metadata and still produce different operator experiences, search results, event timing, or analytic outcomes. Accuracy and suitability must therefore be evaluated with representative scenes and a documented purpose, separate from the protocol test.\n\nDSE evaluation checklist\nDSE recommendation: The following is DSE operational synthesis, not an ONVIF accuracy or privacy standard.\n\nWrite the security or operational use case before selecting object classes or events.\nList required fields, event transports, images, rules, timestamps, identifiers, and downstream actions.\nVerify the exact Profile M record and feature documents for every producer and consumer.\nBench-test configuration, filtering, event delivery, metadata preservation, time alignment, reconnect behavior, and search.\nMeasure false positives and false negatives with representative site conditions; do not infer accuracy from conformance.\nComplete a privacy assessment covering purpose, notice, access, retention, sharing, and any biometric or identifying data.\nRequire human review and a safe failure path before metadata triggers a consequential physical or business action.\nRetest after model, camera, VMS, rule, or firmware changes.\n\nOfficial references\n\nProfile M — current feature, producer, client, event, and conditional-capability scope.\nONVIF announces the release of Profile M — the June 30, 2021 release and interoperability use cases.\nConformant Products — authoritative model and version verification.",
                "datePublished": "2026-07-19T21:28:39+00:00",
                "dateModified": "2026-07-19T21:28:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Video Surveillance"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Video Surveillance",
                    "Explainer",
                    "Information priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Video Surveillance",
                        "url": "https://update.dsesecurity.com/topic/video-surveillance/"
                    }
                ],
                "wordCount": 425,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "ONVIF — Profile M",
                    "url": "https://www.onvif.org/profiles/profile-m/"
                }
            }
        ]
    }
}