Defined authority
Every application, automation, integration, assistant, and operator receives only the access required for the agreed work. Authority is not assumed from convenience.
Security-first engineering
Northwatch designs software, automations, integrations, and diagnostic products around explicit access, documented boundaries, controlled failure behavior, and human ownership of consequential decisions.
Every application, automation, integration, assistant, and operator receives only the access required for the agreed work. Authority is not assumed from convenience.
Discovery identifies systems, data, credentials, permissions, trust boundaries, dependencies, risks, and supported environments before implementation is proposed.
Integrations and automations define what information may move, where it may go, which system owns it, and what happens when validation or delivery fails.
AI-assisted recommendations and other consequential actions remain subject to defined human review or authorization when the project requires it.
Security behavior is validated against documented requirements and acceptance criteria. Northwatch does not describe a control as implemented merely because it appears in a design.
Discovery identifies identity, authorization, data ownership, integrations, deployment boundaries, logging needs, failure behavior, and supported environments. The project proposal defines the security work included in implementation and the responsibilities retained by the customer or other providers.
Automations are bounded by defined inputs, permitted actions, credentials, review points, exceptions, and outputs. Discovery examines how the workflow fails, what may be retried, what requires human attention, and how unintended or duplicate actions are prevented.
AI-assisted features receive bounded context and defined tools. They may explain, classify, summarize, extract, or recommend within the accepted project scope, but they do not automatically inherit authority over customer systems or consequential decisions.
Software assurance
Northwatch selects testing according to the system's risks, architecture, supported environment, and Statement of Work. Automated checks are used where practical, and results are recorded before a capability is described as complete.
Validation may include focused business-rule tests, database and API integration tests, input validation, malformed requests, and end-to-end acceptance scenarios.
Security-sensitive work may test permitted and rejected access, credential handling, sensitive output, customer separation, and the absence of unintended authority.
Applicable tests may cover timeouts, retries, duplicate actions, partial failure, rollback, recovery behavior, deployment, and supported-environment assumptions.
Project scope may include manual review, static analysis, dependency review, and applicable vulnerability scanning. AI-assisted code is treated as untrusted implementation material until it passes the same review and validation controls as other code.
Automated tests reduce risk, but passing tests does not prove that software is free of defects or vulnerabilities. The project agreement defines the environments, scenarios, tools, and acceptance criteria included in validation.
Portable and Systems Diagnostics
Portable and Systems Diagnostics require additional controls because they collect evidence from customer computers and use AI-assisted interpretation. These product-specific controls do not describe every Northwatch engagement.
The server determines which customer, machines, conversations, and evidence a user may access. Customer context, retrieved material, tool results, and machine evidence must not cross customer boundaries.
Each enrolled Windows agent has protected credentials. The AI cannot invent or impersonate an endpoint.
Only defined operations can be requested, and each request is checked before it reaches a computer.
Northwatch is designed to minimize diagnostic evidence before AI analysis. Identifying values are replaced with operation-scoped placeholders, secrets are removed, and the substitution mapping remains outside the AI worker. If evidence cannot be anonymized safely, analysis stops rather than sending the raw data.
Diagnostic explanations are designed to remain connected to the evidence and findings that support them.
The AI may help propose a future repair, but it cannot silently approve or release a change to a customer computer.
Northwatch is designed around a signed Windows agent, encrypted connections, protected machine identity, server-controlled diagnostic tools, worker-bound data minimization and anonymization, a durable operations queue, and auditable evidence storage. These controls allow the assistant to investigate without receiving raw customer identity, substitution mappings, or broad infrastructure authority.
Security requirements vary by project, environment, data, integrations, and customer responsibilities. Specific controls, testing, documentation, maintenance, monitoring, regulatory requirements, and acceptance criteria are defined in the applicable discovery deliverables and Statement of Work. Northwatch does not imply certification, compliance, continuous monitoring, or ongoing support unless expressly included.
