SECURITY APPROACH
Trust belongs in the architecture.
WatchForm is being built with tenant isolation, server-enforced permissions, private object storage, append-only accountability, and fail-closed access as core requirements.
This is a development-stage security overview, not a certification, penetration-test result, warranty, or statement of launch readiness. Independent professional security review remains an external launch gate.
Access boundaries
- Organizations form the tenant and billing boundary.
- Channel or client workspaces remain separately scoped inside an organization.
- Product roles are enforced by the application and database rather than display-only controls.
- Unknown or unverified access should fail closed.
Content and evidence
- Private files use workspace-scoped object keys and metadata boundaries.
- Sources, claims, revisions, approvals, and audit events preserve traceability.
- Support access is denied by default and must be separately time-bound and authorized.
- Customer content and secrets are prohibited from source control.
Operational readiness
Development recovery exercises, dependency checks, alert delivery, and owner-administration tests have been performed. These controls reduce risk but do not replace an independent human architecture and application-security review.
Report a concern
Security concerns can be sent to support@watchform.ai. Do not include credentials, private channel content, or exploit details in an initial email; request a secure follow-up channel.
