Security practices

A short list of what keeps an OpticWatch installation, its cameras and its license safe.

Protect the administrator account

  • Create the administrator as soon as OpticWatch first starts, before the web port is reachable from anywhere you do not trust.
  • Use a long, unique password and keep it in a password manager. Whoever holds this account can make the OpticWatch computer open connections to addresses on your network, as a camera monitor must.

Keep the dashboard off the public internet

  • OpticWatch is designed for a trusted local network. Do not publish port 38080 directly to the internet.
  • For access from outside, use your own VPN, or put a reverse proxy that provides HTTPS in front of port 38080. The proxy must pass the original Host header through. The release README.md covers the details, including WEB_BIND and TRUSTED_PROXIES for a proxy on the same machine.
  • Only port 38080 is published. The database and the API are never reachable from your network.

Protect camera credentials

  • Camera addresses and passwords are encrypted on your server and never displayed after saving.
  • Where your cameras support it, give OpticWatch a viewing-only camera account rather than an administrator account.

Protect your license key

Keep your purchase email private. The license key is what you activate on a new server; OpticWatch does not store or log it.

Keep backups, and keep them private

Make regular backups and store copies away from the OpticWatch computer. A backup contains the key to your stored passwords, so store it like a password and never send it to anyone.

What leaves your server

  • Camera streams, credentials, health data and incidents never leave your server. OpticWatch has no telemetry.
  • Activating a paid license sends the key and the installation ID to the licensing service, once. Deactivating sends the license ID, the installation ID and the activation credential stored at activation.
  • Alerts go only to the mail server and webhook addresses you configure.

Search every OpticWatch guide, down to the section.