How WaterMark is secured · updated August 23, 2026
Security at WaterMark
WaterMark holds your customers' addresses, gate codes, and billing. We treat that as the job. Everything on this page is true today, and each claim our own code can enforce is checked by a test in our release gates; when something here changes, this page changes with it.
The database is not on the internet
Our production database accepts no connections from the public internet. Inbound rules block all external traffic; the application reaches it only over the hosting provider's private network. There is no password to guess because there is no door to knock on.
Encryption
Every connection to WaterMark uses TLS. Off-site backup snapshots are written daily to independent storage with AES-256 server-side encryption, and our test suite checks that the backup code matches this published claim.
The outside providers that hold any of this data on our behalf are named, with the purpose each one serves and the category of data it receives, in our sub-processor list.
Payments
Payments are processed by Stripe. Card numbers are entered on Stripe's hosted pages and never touch or rest on WaterMark's servers.
Your company's data is isolated
Every record is scoped to your company. Cross-company reads are blocked at the query layer, and our release gates include tests that fail if any endpoint leaks across that boundary.
Access controls
Owners control team roles and per-person office and field access. Office logins support two-factor authentication with recoverable backup codes.
Your data rights
Your data outlives your subscription. You can export your data or request deletion at any time, including after cancellation; deletions complete within a published 30-day window that we track on an operations dashboard. The full picture is in the Privacy Policy, the Data Processing Addendum, and the account deletion guide.
Copyright
WaterMark's DMCA designated agent is registered with the U.S. Copyright Office; the notice process is published in our Terms of Service.
What we do not claim
We do not currently hold a SOC 2 or ISO 27001 certification, and we will not imply otherwise. What we publish here is what we have built and what our own tests enforce.
We also make no encryption-at-rest claim of our own for the primary database. The backup sentence above is published because our own code sets that encryption and our own tests read the provider's answer back; we have no equivalent test for our hosting provider's disks, so we will not publish their configuration as a WaterMark claim. What we can state about the database is at the top of this page: it accepts no connections from the public internet.
Reporting a security concern
Found something? Tell us at security@watermarkapp.online and include steps to reproduce. We read every report. Our machine-readable contact record is published at /.well-known/security.txt.
Current uptime and incident history are on our status page, which is public and needs no account to read.