Draft
Security
Duskwatch is in development and not available yet. This page covers how this website protects waitlist data, and the security design of the app.
Draft, not yet in force.
This website
- Every page and the signup form are served over HTTPS. Plain HTTP requests are redirected to HTTPS.
- The key to our email provider stays on the server. It never reaches your browser.
- Our code never logs email addresses, names or IP addresses. Abuse protection uses a salted hash of the IP address, kept in memory for a few minutes.
- The site sets no cookies and loads no advertising or cross-site trackers.
- The signup answers the same way whether or not an address is already on the list, so nobody can use it to check who signed up.
Sign-in in the app
The app signs you in on DigitalOcean's own page, using OAuth 2.0 with PKCE in the iOS system sign-in sheet. There is no token to paste, and Duskwatch never sees your password. Using an access token instead is also an option.
Full access stays on your iPhone
The permission that can make changes lives in the iOS Keychain, only on your device and never synced to iCloud. Duskwatch never sends it to its own server, to analytics or to crash reports. Home Screen widgets never read your sign-in; they show a snapshot the app wrote.
How alerts work
Alerts are optional. To watch your team while the app is closed, the alert server asks for its own read-only permission, which you approve on DigitalOcean's page and can revoke there. It can see status, but it cannot reboot, deploy, change or delete anything.
The server checks the granted permissions every time it receives or renews one, and rejects and revokes any that can write. Alert data is kept in the EU and deleted within 24 hours of turning alerts off.
Changes to your resources
Every action that changes a resource names the action, the resource and the team, and asks for Face ID right before it runs. Disruptive actions, such as a reboot or a roll back, are armed by a swipe, never a tap. Duskwatch has no delete actions, and it never asks for delete permissions.
Reporting a vulnerability
A security contact and a security.txt file will be published before the waitlist opens.