Watchtower <research@watchtower.team>

We're a small independent security research team.

We find security risks in data that is already public. When something looks like it belongs to you, we email you privately and tell you what we saw and where. Some companies pay for reports like this; we won't chase it either way.

Checking it was really us

We write from
research@watchtower.team — this address and no other. Read it character by character.
Every message has
WT-2026-4F3A — a reference code near the top. Quote it back to us and we'll confirm.
We never ask for
Your password, a 2FA code, or remote access to anything.

Anything that doesn't match isn't us. Treat it as phishing and delete it.

Our contact address is also published at /.well-known/security.txt, signed by the same domain — a second, independent way to confirm it.

Not sure about a message? research@watchtower.team — a new email, not a reply.