Watchario

Trust — security & privacy

"Encrypted tunnel" is not an answer. These are the answers.

You are giving a vendor a path to your cameras and routers. That deserves specifics. Where a fact is not yet public, this page tells you where the real answer lives — our security review or your contract — instead of rounding up, and we publish no badge we have not earned.

The connection

Who dials whom, over what, and what your firewall needs to know.

What initiates the connection?The on-site Watchario hub. It opens an encrypted WireGuard tunnel outbound through your NAT. Cameras, routers, and NVRs never connect to the internet themselves, and nothing at the site listens for inbound traffic.
Which outbound ports and protocols?WireGuard over UDP to Watchario relay endpoints. The exact ports, endpoint addresses, and fallback behavior for UDP-blocked networks are provided as an egress allow-list for your network.
Where does tunnel encryption terminate?The exact encryption-termination model is detailed in our security review, available under NDA.
What does the browser use?Standard TLS to the Watchario service, with your login and permissions deciding which sites and cameras are reachable in that session.

Video & data handling

What we can see, what we keep, and where it lives.

Can Watchario decrypt or inspect live video?What Watchario infrastructure can and cannot decrypt or inspect as video transits the relay is detailed in our security review, available under NDA.
Does the relay buffer or retain anything?The relay buffering and retention behavior — transient forwarding versus any persisted data, and for how long — is detailed in our security review, available under NDA.
How are recordings stored, encrypted, retained, deleted?Cloud recordings are retained per your configured per-camera policy and deleted at expiry. Encryption at rest, key management, and deletion verification are detailed in our security review, available under NDA.
Where are video and metadata processed?The regions where video and metadata are processed and stored are available on request. Enterprise can pin to a regional relay; subprocessor list below.

Who can access what

Both inside your org and inside ours.

Who at Watchario can access sites or video?Which roles can access what, under which controls, and with what logging is detailed in our security review, available under NDA. The design intent: nobody, absent your explicit grant.
Is support access customer-approved, time-limited, logged?That is the model we hold ourselves to: support reaches a site only with your approval, for a bounded window, leaving an audit entry you can read. How that is enforced today is detailed in our security review, available under NDA.
MFA, RBAC, audit, session revocation?Per-user, per-site permissions in every plan; RBAC and audit log on Multi-site Operations; SSO/SCIM at Enterprise. MFA and mid-session revocation specifics are detailed in our security review, available under NDA.
How are device credentials and keys stored and rotated?Camera and router credentials are held to operate on your behalf. How they are vaulted, encrypted, and rotated is detailed in our security review, available under NDA.

When things fail

Behavior during internet, relay, or tunnel failure.

Site internet failsThe tunnel drops; monitoring flags the site immediately and history records the window. The hub reconnects automatically. Whether recording continues locally during the gap is detailed in our security review, available under NDA.
Relay failsSites keep running; remote visibility pauses. Relay redundancy, failover behavior, and any committed recovery targets are detailed in our security review and your contract.
Tunnel interrupted mid-sessionLive views and router sessions terminate safely rather than hanging open, and resume from the browser once the hub re-establishes its outbound connection.
Committed uptime / RTO / RPOPublished only when contractually real: these figures live in your agreement, not on a marketing page. Enterprise carries a contractual SLA; nothing on this page substitutes for it.

Deployment & ownership

The operational fine print, stated before you sign.

Network & bandwidth requirementsOutbound-only connectivity; bandwidth scales with cameras, resolution, and recording mode, and is sized with you before rollout.
Who installs?Your contractor or ours, quoted separately — the hub is one powered box on the site network. Remote commissioning from $199/site.
Who owns the hardware, who replaces it?Hub ownership and replacement terms — purchase versus included, the RMA process, and replacement timelines — are answered in your contract.
Offboarding & deletionLeaving takes your data with you: recordings exportable before expiry, configuration deleted on request, and a written deletion confirmation. The full offboarding process is provided on request.

Subprocessors & data locations

The current list of subprocessors, hosting providers, and the regions where video and metadata are processed and stored is available on request. Enterprise plans can pin traffic to a regional relay.

Vulnerability disclosure & security contact

Found something? We want it reported and fixed, not auctioned. Report it to our security team. We acknowledge reports, keep reporters informed, and credit fixes when reporters wish.

Certifications & committed service levels

No badges appear here until they are earned and verifiable. SOC 2 / ISO 27001 / GDPR certification is in progress; we share our current security posture on request. Committed uptime, support response, and RTO/RPO figures are set in your agreement. Enterprise agreements carry a contractual SLA.

Request our security questionnaire answers →

Bring your security team to the demo.

We would rather answer the hard questions before you buy than after you deploy.

Book a technical demo