Security
Security principles for Watchtower.
This page describes how we are designing the product. It is not a certification claim or a substitute for a formal security review.
Watchtower is in early access. Controls will mature as the product moves toward broader availability. We do not claim SOC 2, PCI, or “bank-level security” here unless and until substantiated.
Financial data is sensitive
We treat transactions, balances, and provider connections as high-trust data. Access is limited to what the product needs.
Data minimization
We prefer storing what is needed for budgets, categories, and careful alerts, not hoarding raw exports “just in case.”
Private household product
Watchtower is built for your household’s money, not social feeds, comparison leaderboards, or public sharing of your finances.
Raw facts stay separate from interpretations
Original statement text, balances, and derived categories or alerts remain distinct layers so re-sync and audit stay trustworthy.
Careful automation and language
Budget math and categorization defaults are deterministic. Optional alerts should stay quiet and factual. When language models help with polish, we avoid sending unnecessary raw financial detail.
Secrets stay out of logs
Provider tokens and credentials must not appear in application logs or client-visible errors.
Connections without storing bank passwords
Bank linking uses provider-mediated flow (for example Plaid), not household banking passwords stored on our servers.
Security questions during early access? Contact security@watchtower.money.