Security & trust

Built for data you
can't afford to lose.

Watchroom holds patient care reports, personnel records, and controlled-substance logs — the data your department is legally on the hook for. Here's exactly how we protect it.

Isolation

Your database is yours alone.

Every department runs on its own dedicated Postgres database — not a shared table with a tenant ID bolted on. Your PHI never shares a row, a schema, or a backup with another agency's data.

Most fire and EMS platforms pool every customer into one multi-tenant database, then sell "isolation" as a premium add-on. Watchroom is single-tenant by default — the only way your ePCR ends up next to another agency's is if they're in the same room looking over your shoulder.

Encryption & infrastructure

Encrypted in transit. Encrypted at rest.

TLS everywhere

Every page load, every API call, every background sync runs over TLS. There is no unencrypted path to your data.

Encrypted at rest

Watchroom runs on enterprise cloud infrastructure in US data centers. Sensitive data fields (such as Social Security numbers) and uploaded file attachments are encrypted at rest with AES-256.

Isolated, durable storage

Every department runs on its own isolated database, and uploaded files are stored in encrypted cloud object storage built for high durability — never mixed with another department's data.

HIPAA & PHI

Designed around HIPAA's safeguards.

Electronic patient care reports are protected health information. The platform is built to support your HIPAA obligations — not as a checkbox bolted on later, but in the data model itself.

  • Per-tenant isolation so PHI never co-mingles between agencies
  • Encryption in transit and at rest
  • Role-based access — members see only what their role allows
  • A complete audit trail on every record touch

Agencies with formal compliance requirements can request our security overview.

Access

Who gets in, controlled.

  • Passwordless magic-link or password sign-in. Passwords are hashed (bcrypt), never stored in plain text.
  • Automatic lockout after repeated failed attempts.
  • Role-based permissions across every module.
  • Need SSO or hardware keys? Agencies with stricter requirements, talk to us.

Audit & integrity

Nothing changes silently.

  • Every change is logged — who, what, and when.
  • ePCR and incident reports are signed and locked.
  • Corrections are tracked as amendments — the original is never overwritten.
  • The trail holds up the day a record is subpoenaed.

Ownership

Your data is yours.

Export your records anytime in standard formats — NFIRS XML, NEMSIS, CSV. No lock-in, no hostage fees, no "export is a premium feature." If you ever leave, you leave with everything, in formats your next system can actually read.

Standards built in

The standards your audit cares about.

Baked into the data model, not bolted on after the fact.

HIPAA-aligned
PHI encryption + audit + isolation
NFIRS 5 → NERIS
National fire incident reporting
NEMSIS 3.5
EMS data standard
DEA chain of custody
Controlled substances
NFPA 1582
Medical + fitness records
NFPA 1403
Live fire training
NFPA 1851 / 1962 / 1932
PPE / hose / ladder
TCFP / SFFMA
Texas state reporting

Questions about security?
Ask us anything.

Compliance officer doing due diligence? County IT with a checklist? We'll walk you through the architecture and answer the hard questions.

Found a security issue? Report it to hello@watchroomapp.com and we'll respond quickly.