Security
How we protect client systems and our own.
Last updated July 19, 2026
Placeholder content. This page is a structural draft written in plain language, not reviewed legal text. It must be replaced by qualified counsel before this site goes live.
Reporting a vulnerability
If you believe you have found a security issue in this site or in a system we operate, email security@blackwatch.tech. Include enough detail to reproduce the issue.
We acknowledge reports within two business days. We will not pursue action against good-faith researchers who report responsibly, avoid privacy violations and service degradation, and give us reasonable time to remediate before disclosure.
Our practices
Access to client environments follows least privilege and is time-bound. Production access requires named approval and is logged.
All engineering staff complete security training on joining and annually thereafter. Devices are managed, encrypted, and remotely wipeable.
Client code and data stay within the client's own cloud accounts wherever the engagement structure allows.
Certifications
Details of current certifications and audit reports are available under NDA. Contact your engagement lead or security@blackwatch.tech.