Firewatch Cloud

Security

How Firewatch approaches access, alert integrity, and the infrastructure behind managed paging.

Designed for a critical path

Firewatch treats alert delivery, identity, and audit history as production infrastructure. Cloud environments isolate organization data, restrict administrative actions by role, and keep provider credentials out of the browser.

Application controls

  • Passkeys, passwords, and optional two-factor authentication.
  • Organization-scoped roles and auditable administrative actions.
  • Signed inbound and outbound webhooks with replay protection.
  • API keys with explicit ownership and revocation.
  • Provider secrets retained server-side and excluded from UI responses.

Transparency

The Firewatch core is open source, and its API contracts and deployment model are documented. Cloud reliability and incident updates are published through the status page.

Report a vulnerability

Send security reports to security@onfirewatch.com. Include reproduction steps and avoid accessing data that is not your own. We will acknowledge credible reports and coordinate remediation.