SECURITY APPROACH

Trust belongs in the architecture.

WatchForm is being built with tenant isolation, server-enforced permissions, private object storage, append-only accountability, and fail-closed access as core requirements.

This is a development-stage security overview, not a certification, penetration-test result, warranty, or statement of launch readiness. Independent professional security review remains an external launch gate.

Access boundaries

  • Organizations form the tenant and billing boundary.
  • Channel or client workspaces remain separately scoped inside an organization.
  • Product roles are enforced by the application and database rather than display-only controls.
  • Unknown or unverified access should fail closed.

Content and evidence

  • Private files use workspace-scoped object keys and metadata boundaries.
  • Sources, claims, revisions, approvals, and audit events preserve traceability.
  • Support access is denied by default and must be separately time-bound and authorized.
  • Customer content and secrets are prohibited from source control.

Operational readiness

Development recovery exercises, dependency checks, alert delivery, and owner-administration tests have been performed. These controls reduce risk but do not replace an independent human architecture and application-security review.

Report a concern

Security concerns can be sent to support@watchform.ai. Do not include credentials, private channel content, or exploit details in an initial email; request a secure follow-up channel.