WATCHING AGENTS
    Security

    Built so the questions stay yours.

    Watching Agents handles forward-looking questions that often touch sensitive ground — investment theses, client engagements, in-flight stories. Here's how we protect them.

    Encryption in transit & at rest

    All traffic to Watching Agents runs over TLS 1.2+. Your data is encrypted at rest using AES-256 inside our managed Postgres infrastructure.

    Authentication & sessions

    Standard email/password and OAuth (Google) authentication, JWT-based sessions with refresh-token rotation, and secure password reset flows. No anonymous accounts.

    Row-level security on every table

    Privacy is enforced at the database — not in the UI. Private agents are inaccessible to other users by design, via Postgres row-level security policies, not just hidden views.

    Auditable, sourced evidence

    Every claim an agent makes is linked back to a source. You can review the evidence base, the hypotheses behind a forecast, and the signals that moved it.

    Infrastructure

    Watching Agents is hosted on managed Postgres + edge-function infrastructure (Lovable Cloud / Supabase) running in EU regions, with automated backups and point-in-time recovery enabled.

    AI workloads are routed through the Lovable AI Gateway. We do not train any third-party model on your private data, and prompts / outputs related to private agents are not stored beyond what's necessary to render and audit them.

    Privacy & data handling

    • Public agents are public by definition. Private agents are visible only to their owner, enforced at the database level via row-level security.
    • We comply with GDPR. You can request export or deletion of your personal data via our contact form.
    • Account-level data is retained while your account is active and deleted on request. Backups are rotated on a fixed schedule.
    • See our Privacy Policy, Cookie Policy, and AI Disclosure for full detail.

    Reporting a vulnerability

    We take security reports seriously. If you've found a vulnerability, please reach out before disclosing it publicly. We'll acknowledge your report within 72 hours and work with you on a fix and timeline.

    Report a vulnerability →

    Need a deeper security review?

    Enterprise customers get DPAs, SSO, audit logs, and direct security contacts.