Our mission

Enterprise monitoring capability. Without the enterprise price tag or the data residency compromise.

WatchTower15 was built for engineering teams that are fed up paying enterprise platform prices for features they'll never use, or compromising on where their infrastructure data lives.

Why we built this

Monitoring tools weren't designed for your threat model

Every mainstream monitoring agent installs with elevated privileges because the vendors decided telemetry data was worth the security trade-off. We disagreed.

WatchTower15 was designed from first principles: what is the minimum privilege required to collect useful monitoring data? The answer, it turns out, is none. No root. No Linux capabilities. Not even CAP_NET_BIND_SERVICE.

That same principle guides everything we build. Governance features shouldn't be a paid upgrade. Data residency shouldn't require a phone call to legal. The bill shouldn't require a spreadsheet to understand.

Zero-privilege by default

The agent runs as an unprivileged service user with ProtectSystem=strict and no Linux capabilities. This isn't a mode — it's the only mode.

Data residency by choice

Your data lives in the region of your choice — no extra cost, no premium tier. We currently cater to UK, EU, USA, Latam, and SE-Asia regions.

Honest pricing

One billing dimension. One number to understand before you sign. No compounding per-seat × per-host × per-feature model.

Security included, not upsold

SSL analysis, DNS anomaly detection, and domain expiry monitoring are part of the platform — not a premium add-on.

Data residency

Data residency options by default

The market leaders gate data residency behind premium plans or increased rates. We make it a given option for every customer.

🌍

Your region, your choice

Your data lives in the region of your choice without extra configuration, extra cost, or a separate support tier. We currently cater to UK, EU, USA, Latam, and SE-Asia regions.

🇪🇺

Transfer protections

GDPR Chapter V transfer restrictions respected by default — we don't cross adequacy decision boundaries without your instruction. No personal data routed outside your chosen region.

Sub-processors

Full sub-processor list available on request. We will notify you before any new sub-processor that touches customer data is added. DPA available at signing.

Security model

The agent cannot escalate. Period.

Most monitoring agents ask for root at install and rely on process isolation promises. We removed the need for those promises.

systemd hardening
  • NoNewPrivileges=yes — the process cannot elevate under any exploit
  • ProtectSystem=strict — filesystem is read-only except the state dir
  • PrivateTmp=yes — isolated /tmp namespace
  • ProtectHome=yes — home directories inaccessible
  • AmbientCapabilities= — empty, intentionally
Credential isolation
  • Agent token stored in the agent's own state directory, mode 0600
  • State directory owned exclusively by the wt15-server-agent service user
  • No root-owned credential files that require privilege to read
  • Credential rotation supported via --upgrade flag without stopping monitoring
Network posture
  • Agent initiates outbound connections only — no inbound listener
  • All communication over TLS 1.2+ with certificate validation
  • No docker socket required for container metrics — reads /sys/fs/cgroup directly
  • DNS resolution uses the host's resolver — no custom DNS dependency
Audit & access control
  • Full audit log of every action on your WatchTower15 account
  • SAML 2.0 / OIDC SSO — enforce MFA at your identity provider
  • RBAC with admin, editor, and viewer roles
  • Organisation-level isolation — no cross-org data access
GDPR & compliance

Built for teams that can't afford compliance surprises

Data Processing Agreement

A standard DPA is available to all customers. We act as a data processor for monitoring data your servers collect. The DPA is available at account sign-up; no negotiation required for the standard form.

GDPR & data protection

WatchTower15 Ltd processes personal data in accordance with GDPR. We act as a data processor for monitoring data your servers collect, and as a data controller for account and contact information.

Data transfer protections

Personal data of EU and UK data subjects is not transferred outside the EEA or to countries without an adequacy decision without your explicit instruction and an appropriate transfer mechanism in place.

Breach notification

In the event of a personal data breach, we will notify you within 72 hours of becoming aware — in line with GDPR obligations — so you can meet your own notification timelines.

Get in touch

Talk to us

Whether you want a demo, a pricing quote, a copy of the DPA, or just to understand if WatchTower15 fits your infrastructure — we're happy to talk.

Contact Sales

Tell us about your infrastructure and we'll come back with a transparent quote. No auto-renewals, no surprise invoices.

Email sales@watchtower15.com

Response within one business day