Watchario

How it works

Three parts: a hub at the site, a relay in the middle, a browser in your hand.

No inbound ports. No end-user VPN. No viewer app. Here is exactly what each part does.

01 · AT THE SITE

The Watchario hub

A small appliance on the site network. It discovers cameras and devices, runs the local status checks, pulls video from Hikvision cameras, and initiates the encrypted tunnel — always outward.

connects: outbound WireGuard through NATdiscovers: cameras, routers, clients on the LANinbound ports opened: none

02 · IN BETWEEN

The relay

Matches your signed-in browser session to the right site tunnel and forwards encrypted streams. It brokers connections; whether it can decrypt or buffers anything is answered explicitly on the Trust page.

role: broker + forwardertransport: encrypted end to end in transitregional relay available at Enterprise

03 · IN YOUR HAND

The browser

Live video, device status, playback, and router sessions render as ordinary web pages behind your login. Permissions decide which sites, cameras, and routers each person sees.

requires: a modern browser, nothing elseno VPN client, no viewer appworks from office, home, or phone
site network— encrypted WireGuard, outbound through NAT →relay— TLS session →your browser

Deployment, start to finish

Installation is quoted separately, or your own electrician/IT contractor can rack the hub — it is one box and one cable. Remote commissioning is available from $199/site.

STEP 1

Plug in the hub

One box, powered and cabled to the site network. Any competent contractor can do it — or ship it to the store with a picture instruction sheet.

STEP 2

It phones home

The hub makes its outbound connection and appears in your organization, pending your approval. No firewall changes at the site.

STEP 3

Adopt what it found

The hub lists discovered cameras, the MikroTik router, and connected devices. You choose what to monitor actively, what to record, and who can see it.

STEP 4

Set people & rules

Invite operators, scope permissions per site, set alert routing and recording retention. The site is now one tab among all your others.

Failure modes, answered up front

Site internet goes down

The tunnel drops and monitoring flags the site immediately — the outage is itself the signal. When connectivity returns, the hub reconnects on its own; the outage window stays in history. Local recording behavior during the gap is covered in your demo.

The relay is unreachable

Sites keep operating; you temporarily lose the remote window into them. Multi-region relay behavior and any committed recovery targets are detailed in your contract.

The tunnel is interrupted mid-session

Router sessions and live views end safely rather than hanging half-open; the hub re-establishes the tunnel automatically and your session resumes from the browser.

Network requirements

Connection directionOutbound-only from the hub (WireGuard) — exact egress allow-list provided for your network
Firewall changesNone — standard outbound NAT is enough
BandwidthDepends on camera count, resolution & recording mode — sized with you before rollout
BrowsersCurrent Chrome, Edge, Firefox, Safari (desktop and mobile)
Hardware ownershipHub ownership & replacement terms — detailed in your contract
See compatibility →

Watch the architecture run, live.

Book a demo