Watchtower
Provable compliance for Microsoft 365. What it is, who it is for, and what it deliberately is not.
Watchtower is the compliance system of record for Microsoft 365, built for the people personally accountable for their organization's security posture: CISOs, the MSP practice leads whose reputation rides on every client's configuration, and the compliance engineers who sign the attestation.
It is built on one premise: a vendor dashboard you have to take on faith is not good enough. Every claim Watchtower makes about your posture, and every change it makes to it, is something you can independently prove.
The trail is tamper-evident and any tampering is provably detectable. It is not tamper-proof: anyone with sufficient database access can destroy data, but no one can alter history undetectably. Where a capability cannot be made cryptographically absent (Microsoft all-or-nothing consent), that boundary is named, not hidden.
Start here
- What Watchtower is - the thesis in five minutes.
- Who we are not - the honest boundary, including the parts we cannot make cryptographic and say so.
- Where we are going - direction, not dated promises.
- Architecture overview - how the pieces fit, at a level safe to publish.
Setup guides, day-to-day workflows, the full API reference, and the deep trust and architecture material live behind a Watchtower account. This public area is the part you can read before you talk to us.