WT–01 Independent security research

We find security risks in public data—and tell the people who can fix them.

Watchtower is a small independent research team. We examine lawfully available public data, document credible security concerns, and contact affected organizations privately.

01 / Outreach protocol

If we contacted you

Unexpected security email deserves scrutiny. These are the boundaries every genuine Watchtower message follows.

  1. Check the sender

    Genuine outreach is sent from [email protected]. Links in the message point only to HTTPS pages on watchtower.team.

  2. Verify independently

    Start a new email to our research address and include the reference from your message. You do not need to reply to the original thread.

  3. Keep control

    We never ask for passwords, one-time codes, remote access, or software installation.

  4. Private by default

    We contact the affected organization directly. We do not publish the finding.

02 / Method

How we work

Public source

We look for security-relevant signals across lawfully available public datasets and archived web material.

Careful review

A researcher reviews the context and records the available provenance before outreach.

Direct handoff

We send a concise notice to the organization best placed to assess and resolve the concern.

03 / Contact

Unsure whether a message is ours?

Start a fresh thread. Include the reference from the message and we will confirm whether it came from Watchtower.

[email protected]