Exposure Watch Home Sign in

Exposure Watch Security and Subprocessors Notice

Effective date: June 15, 2026

Company: Exposure Watch, Inc.

Security contact: security@exposurewatch.co

This notice summarizes Exposure Watch's security and vendor posture.

1. Security posture

Exposure Watch publishes only controls that are implemented:

  • We use role-based access controls for customer accounts.
  • We use encryption in transit for web traffic.
  • We use commercially reasonable safeguards designed to protect customer data.
  • We monitor the Service for security, reliability, and abuse.
  • We restrict employee/contractor access based on business need.
  • We review vendors that process customer personal data.

Exposure Watch does not claim SOC 2, ISO 27001, HIPAA compliance, penetration testing, or 24/7 security operations unless those controls or certifications are expressly stated in writing.

2. Customer security responsibilities

Customers are responsible for managing authorized users, removing departed personnel, maintaining accurate alert contacts, securing email accounts, protecting devices, and using strong authentication where available.

3. Subprocessor list

Exposure Watch uses the following service providers to operate the Service. Additional providers may be listed as the Service evolves.

ProviderPurposeData processedLocationLink to vendor privacy/security page
Amazon Web ServicesApplication hosting and infrastructureAccount, facility, alert, log, and application dataUnited Stateshttps://aws.amazon.com/privacy/
StripePayments and subscriptionsBilling contact, subscription, and transaction dataUnited States and other regions where Stripe operateshttps://stripe.com/privacy
Email service providerSign-in links, service notices, and alertsEmail addresses and message metadataUnited StatesProvider documentation or privacy notice
SMS service providerText alerts when enabledPhone numbers and message metadataUnited StatesProvider documentation or privacy notice
Analytics or error-monitoring providerProduct analytics, debugging, and reliabilityUsage data, device data, logs, and error detailsUnited States or provider-defined regionsProvider documentation or privacy notice
Customer support toolsCustomer support communicationsSupport communications and account contextUnited States or provider-defined regionsProvider documentation or privacy notice

4. Incident notice

If Exposure Watch confirms unauthorized access to Customer Personal Data, Exposure Watch will notify affected customers without undue delay and provide information reasonably available about the nature of the incident, affected data, mitigation steps, and customer actions.

5. Vulnerability reporting

Report suspected vulnerabilities to security@exposurewatch.co. Do not access, modify, delete, export, or disclose data that is not yours. Do not disrupt the Service or run tests without written authorization.

6. PHI exclusion

Exposure Watch is not designed to process PHI. Customers must not submit PHI, patient records, resident names, medical information, or clinical data.

Terms of Service Privacy Policy Cookie Policy Accessibility Statement Public Data and Emergency Decision-Support Disclaimer Acceptable Use Policy Data Processing Addendum SMS Alert Terms Subscription Billing, Cancellation, and Refund Policy Security and Subprocessors Notice Contact HIPAA BAA Position Statement

Exposure Watch, Inc. | Decision support from public and third-party data sources. Not emergency response, evacuation, clinical, regulatory, or life-safety instructions.