Cybersecurity Policy
Last updated: June 14, 2026
1. Introduction & Scope
Watchgar ("we," "us," or "our") is a financial intelligence platform operated by ZENSOFT LLC, a limited liability company organized under the laws of the State of Arizona. This Cybersecurity Policy describes the technical and organizational controls we maintain to protect the confidentiality, integrity, and availability of the data entrusted to us.
This policy applies to all Watchgar production systems, the personnel who operate them, and the third-party services we rely on to deliver the platform. It is published alongside our Privacy Policy and Terms of Use, which govern how we collect and use your information.
We review this policy at least annually and after any material change to our architecture, vendors, or threat landscape. Security is a continuously improving practice; the controls below describe our current program and may be enhanced over time.
2. Data Classification and Handling
We classify the data we process into tiers and apply controls proportionate to each tier's sensitivity:
- Secret / Credentials: Third-party API keys and brokerage tokens, authentication secrets, and encryption keys. These receive the strictest handling — encrypted at rest, scoped to the owning account, transmitted only over TLS, and never written to application logs.
- Confidential / Personal: Account identity (name, email), connected brokerage account data (equity, cash, positions, orders), and user-generated content such as notebooks, agents, and strategies. Access is restricted to the systems and personnel that require it to operate the service.
- Internal: Operational logs, queue and job metadata, and aggregated usage analytics used to run and improve the platform.
- Public: Market data, news, filings, and economic indicators ingested from public and licensed sources and served to all users.
Handling rules follow the classification: credentials are isolated and encrypted, personal data is collected only as needed to provide the service, and data is retained only as long as required to operate the platform or meet legal obligations. We do not sell user data. Data is securely deleted when no longer needed or upon a valid deletion request.
3. Access Control and Privileged Access Management
Access to systems and data is governed by the principles of least privilege and need-to-know:
- User authentication: End users sign in through Google authentication; we do not store user passwords. Application sessions are managed with signed, expiring tokens.
- Administrative access: Privileged administrative functions are protected behind a separate authenticated console and are available only to authorized ZENSOFT personnel.
- Least privilege: Accounts, services, and credentials are granted the minimum permissions required for their function. Each user's data — including connected brokerage credentials — is scoped to that user and is not accessible to other users.
- Privileged access management: Access to production infrastructure (hosting, databases, and secret stores) is limited to a small number of authorized operators, secured with strong credentials and multi-factor authentication on the underlying provider accounts, and granted only for legitimate operational need.
- Revocation: Access is removed promptly when it is no longer required. Users can disconnect linked brokerage accounts at any time, which revokes and deletes the stored credentials.
4. Encryption of Data at Rest and in Transit
- In transit: All traffic between users and Watchgar, and between Watchgar and its third-party providers, is encrypted using industry-standard TLS.
- At rest: Sensitive credentials such as third-party API keys and brokerage tokens are encrypted at rest using strong, industry-standard cryptography and are stored separately from general application data.
- Infrastructure encryption: Our databases and storage are hosted with reputable cloud providers whose managed storage is encrypted at rest at the platform level.
- Key management: Encryption keys and application secrets are kept outside of source control, restricted to production systems, and never exposed to end users or written to application logs.
5. Vulnerability Management and Patch Management
- Dependency monitoring: We track our software dependencies and apply security updates to address known vulnerabilities. High-severity issues are prioritized for remediation.
- Patching: Underlying operating systems, runtimes, and managed infrastructure are kept current through our cloud providers' maintenance and our regular update cycle.
- Secure development: Changes are reviewed before release, secrets are kept out of the codebase, and we follow secure-by-default practices such as parameterized database access and server-side validation of requests.
- Hardening: Production services expose only the interfaces required to operate, and administrative endpoints are authenticated and segregated from public routes.
- Responsible disclosure: If you believe you have found a security vulnerability, please report it to hello@watchgar.com. We investigate all good-faith reports and ask that you avoid accessing or modifying other users' data while testing.
6. Incident Response and Disaster Recovery
Incident response. We maintain an incident response process to detect, contain, investigate, and remediate security events. In the event of a security incident that affects your personal information, we will take steps to contain and remediate the issue and will notify affected users without undue delay and in accordance with applicable law, including any regulatory notification obligations.
Disaster recovery & business continuity. Production data is hosted on managed cloud infrastructure with provider-level redundancy and durable storage. We maintain backups of critical data to enable recovery in the event of data loss or service disruption, and we rely on our providers' resilient infrastructure to restore service. Our goal is to recover critical functionality promptly while preserving the integrity of user data.
7. Physical Security
Watchgar is a cloud-hosted service and does not operate its own data centers or host customer data on self-managed physical hardware. Physical security of the servers, networks, and facilities that store and process data is provided by our reputable cloud infrastructure providers, which maintain industry-standard physical and environmental controls (such as access-controlled facilities, surveillance, and environmental protection) at their data centers. Company-managed endpoints used by personnel to operate the service are protected with access controls and encryption.
8. Vendor Risk Management
We rely on a limited set of trusted third-party providers (sub-processors) to operate Watchgar, and we share data with them only to the extent needed to deliver the service. Current categories include cloud hosting and database infrastructure, payment processing, authentication, brokerage integration, and AI model providers.
- Selection: We choose vendors with established security practices and review the protections they offer before integrating them.
- Data minimization: Vendors receive only the data necessary for their function. We do not send account credentials or stored API keys to AI providers, and we select AI providers and configure their settings with the intent of preventing your data from being used to train their models.
- Contractual safeguards: Sub-processors are subject to confidentiality obligations and process data under their own terms and privacy policies, which we account for in our assessment.
- Ongoing review: We periodically reassess our vendors and remove or replace those that no longer meet our requirements.
The current list of sub-processor categories and named providers is maintained in our Privacy Policy.
9. User Responsibilities
Security is a shared responsibility. We encourage you to protect the account you use to sign in to Watchgar, enable multi-factor authentication on that account, keep your devices secure, and disconnect any linked brokerage account you no longer use. When you enable live trading, you remain responsible for monitoring your positions and managing risk as described in our Terms of Use.
10. Changes to This Policy
We may update this Cybersecurity Policy from time to time as our platform and practices evolve. We will post the updated policy on this page with a revised "Last updated" date. Material changes will be communicated through the platform where appropriate.
11. Contact
For security questions, vulnerability reports, or due-diligence requests, contact our security team at: