Security practices
A short list of what keeps an OpticWatch installation, its cameras and its license safe.
Protect the administrator account
- Create the administrator as soon as OpticWatch first starts, before the web port is reachable from anywhere you do not trust.
- Use a long, unique password and keep it in a password manager. Whoever holds this account can make the OpticWatch computer open connections to addresses on your network, as a camera monitor must.
Keep the dashboard off the public internet
- OpticWatch is designed for a trusted local network. Do not publish port 38080 directly to the internet.
- For access from outside, use your own VPN, or put a reverse proxy that provides HTTPS in front of port 38080. The proxy must pass the original
Hostheader through. The releaseREADME.mdcovers the details, includingWEB_BINDandTRUSTED_PROXIESfor a proxy on the same machine. - Only port 38080 is published. The database and the API are never reachable from your network.
Protect camera credentials
- Camera addresses and passwords are encrypted on your server and never displayed after saving.
- Where your cameras support it, give OpticWatch a viewing-only camera account rather than an administrator account.
Protect your license key
Keep your purchase email private. The license key is what you activate on a new server; OpticWatch does not store or log it.
Keep backups, and keep them private
Make regular backups and store copies away from the OpticWatch computer. A backup contains the key to your stored passwords, so store it like a password and never send it to anyone.
What leaves your server
- Camera streams, credentials, health data and incidents never leave your server. OpticWatch has no telemetry.
- Activating a paid license sends the key and the installation ID to the licensing service, once. Deactivating sends the license ID, the installation ID and the activation credential stored at activation.
- Alerts go only to the mail server and webhook addresses you configure.