Transparency
Data & Security
A record is only trustworthy if you can see how it is protected. This page describes how the platform handles your files, who can reach a record, and why verified history cannot be quietly rewritten.
Last updated: 27 August 2026
Files are private by default
- Photos and documents are stored in private buckets that are not publicly reachable.
- Access happens through short-lived signed links generated for the person who is allowed to see the file.
- Serial numbers are masked in the interface and on shared passports unless you deliberately reveal them.
Access is enforced per record
- Every record is bound to its owner at the database level, not just in the interface.
- A professional sees only the record submitted to them, for the duration of the case.
- A passport link exposes only the fields you choose, is unlisted and is excluded from search engines.
- Professional status is granted only by platform vetting — an account cannot promote itself.
History cannot be quietly rewritten
- Verification records, ownership events and the audit trail are append-only: entries can be added, not edited away.
- A correction is recorded as a new entry that references the previous one, so the sequence stays readable.
- Documents referenced by a verification, appraisal or service entry are archived rather than erased, so evidence keeps its support.
- Privileged and administrative actions are logged.
Where the AI boundary sits
The identification assistant proposes a brand, model or reference from your photos and notes. Every suggestion is stored with its model, confidence value, timestamp and status, and is shown as a suggestion until you confirm it.
- AI never sets a “professionally verified” status.
- AI never states that a watch is authentic.
- A confirmed suggestion remains labelled as owner-confirmed, with its original provenance visible.
Reporting a problem
If you believe a record misrepresents a watch, or you find a weakness in the platform, write to security@watchtrust.app. We investigate reports and do not pursue researchers acting in good faith. For data requests see the Privacy Policy.
What we do not claim
We describe the controls we operate. We make no certification, compliance-audit or breach-proof claim, and we do not guarantee the authenticity of any watch. Verification is always attributed to the professional who signed it.