Protection
How your collection is protected.
Written plainly, because the people who need this most are not security specialists. If anything here is unclear, ask us — a question about how your data is held is always a fair one.
A list of what you own is worth more than any one watch.
A complete inventory — makes, references, serial numbers, values, photographs, and the address it all sits at — is precisely the document you would least like to see circulating. Cloud collection apps assemble exactly that list, on a server you do not control, alongside everyone else’s. Watch Register is built so the list never exists anywhere but your own machine.
What it protects against
The laptop is gone. The register is not exposed.
Your collection is stored as a single encrypted file. Someone who takes the machine, pulls the drive and reads it directly gets unreadable data — not a locked document they can work on, but scrambled information with no lock to pick. Your watches, values, serial numbers, photographs and documents are all inside it.
There is no vendor database to breach.
No accounts, no servers, no cloud storage, no copy held by us. The category of headline where a company loses its customer records cannot apply here, because we do not hold any.
The application has no network capability at all.
Not disabled, not opt-out — absent. There is no analytics, no telemetry, no crash reporting, no update check and no price feed, because there is no mechanism to send or fetch anything. The application behaves identically on a machine that has never been connected to the internet.
Even your own backups only ever hold ciphertext.
If your machine backs up to an external drive or a cloud service, what gets copied is the encrypted file. Whoever holds that backup — Apple, Microsoft, a backup provider, or someone who steals the drive — cannot read it without your passphrase.
We cannot produce your data for anyone.
Because the key is derived from your passphrase and never leaves your machine, there is no mechanism by which we could hand over your collection in response to a subpoena, an insurer, or a support request. Not a policy we could change — an absence of the thing itself.
How the encryption works
Standard, well-understood cryptography. Nothing invented in-house.
AES-256, in an authenticated mode.
The same standard used to protect classified government information and banking systems. Authenticated means tampering with the stored file causes it to fail to open, rather than quietly producing altered records.
It unlocks the key rather than encrypting your data directly.
A random key encrypts the register; your passphrase unlocks that key, through a deliberately slow derivation that makes guessing expensive. One practical benefit: changing your passphrase takes milliseconds and re-encrypts nothing, so you can change it as often as you like.
An independent second way in.
Shown once during setup, printable, and formatted so it can be transcribed from paper without ambiguity between characters that look alike. It opens the register on its own. Neither secret can be worked out from the other.
Locking discards the key.
The application opens locked, and locks again on an idle timer. A locked register is not a screen drawn over readable data — the key is discarded from memory and there is nothing to read until you supply a valid secret.
There is no reset
No backdoor, no escrow, no security questions, no support line that can let you back in. If you lose both your passphrase and your recovery key, the register cannot be opened by anyone, permanently. This is the unavoidable other side of a design where nobody but you holds the key — and it is why the recovery key is worth writing down the day you set up.
What it does not protect against
Stated in full. A security claim that only lists its strengths is telling you something about the people making it.
- Malware on your machine while the register is unlocked. Once you have entered your passphrase, the records are readable to the application — and to anything that has taken over your computer. Encryption at rest protects a file at rest; it cannot protect a session in progress.
- Someone watching you type. A keylogger, a camera, or a person over your shoulder defeats any passphrase.
- A passphrase kept badly. Written on a note attached to the laptop, or stored in a file on the same machine, it protects nothing.
- Anything you export yourself. The application can produce readable insurance schedules and estate registers on request. Once you have created one, protecting it is up to you.
- Someone guessing offline. Anyone holding your encrypted file can attempt passphrases against it without limit. The derivation is slow by design to make that expensive, but the protection ultimately rests on choosing a passphrase that is long enough. Length matters more than punctuation.
- Deletion is not shredding. Deleting the register removes the file; it does not overwrite the underlying storage. On modern drives, genuine erasure is not reliably achievable, and we do not claim it.
- A compromised machine at setup time. The recovery key is displayed on screen once. If the computer is already compromised at that moment, it can be captured then.
- First-launch warnings. macOS and Windows currently show a warning the first time you open the application. This is a signing matter on our side, not a fault with the download — the download page explains it in full.
Independent review — and how to reach us
Watch Register is proprietary software, and its internals are not published. It is built by a systems architect whose day job is engineering air-gapped infrastructure. Security questions, findings and requests for detail from insurers, advisors or your own technical counsel are genuinely welcome: support@watchregister.app. Third-party components used within the application are credited at open-source attributions.
Still have a question?
The full FAQ covers encryption, backups, the recovery key, and what to do if something looks wrong.