Last updated: 18 June 2026
Security
This page is maintained by Overwatch Digital Assistant Diagnostics and describes our current security practices. It is not an independent audit, and Overwatch does not claim SOC 2, ISO 27001, HIPAA, or PCI certification.
Hosting and platform
Overwatch is built on Lovable Cloud, a managed backend platform that provides our database, authentication, file storage, and serverless functions. Lovable Cloud handles infrastructure-level security; we configure and secure the application on top of it.
Authentication
Accounts are protected by email and password, with Google and apple sign-in available as alternatives. Passwords are handled by our managed authentication provider and are never stored by us in plain text. We do not allow anonymous sign-ups.
Access control
User data is protected by row-level security in the database, so one user cannot read another user's saved reports, vehicles or account information.
Data in transit
All traffic between your browser and Overwatch is served over HTTPS.
Payments
Payments are processed by Stripe. Card details are entered directly into Stripe's secure fields and never touch Overwatch servers. Stripe webhooks are cryptographically signed and are verified before we act on them.
Shared responsibility
We secure the platform and the application. You are responsible for keeping your account credentials safe, using a strong unique password, and signing out on shared devices.
Responsible disclosure
If you believe you have found a security issue, please email overwatchdiagsecurity@gmail.com with details and steps to reproduce if possible. We will acknowledge your report, investigate, and keep you updated. Please give us a reasonable opportunity to fix issues before public disclosure.
Incident handling
If we become aware of a security incident affecting your data, we will investigate and notify affected users where required by law.
See also: Privacy Policy · Terms of Service