Watchtower

Security

Security principles for Watchtower.

This page describes how we are designing the product. It is not a certification claim or a substitute for a formal security review.

Watchtower is in early access. Controls will mature as the product moves toward broader availability. We do not claim SOC 2, PCI, or “bank-level security” here unless and until substantiated.

Financial data is sensitive

We treat transactions, balances, and provider connections as high-trust data. Access is limited to what the product needs.

Data minimization

We prefer storing what is needed for budgets, categories, and careful alerts, not hoarding raw exports “just in case.”

Private household product

Watchtower is built for your household’s money, not social feeds, comparison leaderboards, or public sharing of your finances.

Raw facts stay separate from interpretations

Original statement text, balances, and derived categories or alerts remain distinct layers so re-sync and audit stay trustworthy.

Careful automation and language

Budget math and categorization defaults are deterministic. Optional alerts should stay quiet and factual. When language models help with polish, we avoid sending unnecessary raw financial detail.

Secrets stay out of logs

Provider tokens and credentials must not appear in application logs or client-visible errors.

Connections without storing bank passwords

Bank linking uses provider-mediated flow (for example Plaid), not household banking passwords stored on our servers.

Security questions during early access? Contact security@watchtower.money.