Security & data

Where your work lives, and who can reach it.

Bids, drawings, wage information and job records are sensitive. This page describes how the Watt Systems applications are built and hosted today, in plain language — and it is deliberately explicit about what we do not claim. If a security questionnaire needs an answer that is not on this page, ask us directly and we will answer it in writing rather than guess in marketing copy.

Last reviewed · September 2026

How the systems are separated

Each Watt product is deployed as its own application. A company using BidWatt and JobWatt is using two deployments that share project information through defined connections — not one monolith where every user can reach everything.

  • Applications are served over HTTPS.
  • Access control is enforced in the data layer as well as the interface, so a user who manipulates the front end still cannot read rows they are not entitled to.
  • Roles and scoping are configured per company — for example estimator, manager and administrator levels with visibility limited to the branches or jobs a person belongs to.
  • User administration is handled by your own administrator, not by us on your behalf.

Documents and AI processing

AI features exist to read, search, summarize and draft. They do not price work and they do not make compliance decisions. Where a feature processes a document, the important question is which service sees that document — and the answer depends on the feature.

  • WattBot is designed around local-model deployment on supported hardware, which can keep a document on your own machine for the workflows configured that way.
  • Some product features may call an external model or service. We will tell you exactly which ones do, feature by feature, before you rely on it.
  • The free browser tools — PDFWatt, WordWatt and SheetWatt — are built to work on the file in your browser on your device. Ask us before relying on that for a specific compliance requirement so we can confirm the behavior of the exact features you need.

Hosting and data location

The applications run on managed cloud infrastructure, with application data in a managed Postgres database. We will name the specific providers, regions and data-retention behavior for your deployment in writing on request. That belongs in a document you can hand to your IT reviewer, not in a marketing paragraph.

What we do not claim

Plenty of software marketing implies certifications it does not hold. We would rather be useful than impressive, so to be unambiguous:

  • We do not claim SOC 2, ISO 27001 or any other third-party security certification.
  • We do not publish an uptime guarantee or service-level commitment on this page.
  • We do not claim penetration-test results, insurance limits or compliance attestations.
  • We do not publish absolute “your data never leaves your building” statements for cloud-hosted products.

If any of those become true and verifiable, they will appear here with a date and evidence — not as adjectives.

What to ask us before you sign

  • Which provider, region and database host your deployment uses.
  • Backup frequency and restore expectations for your data.
  • Exactly which features call an external AI service, if any.
  • How access is revoked when an employee leaves.
  • What happens to your data if you stop using the product, and in what format you get it back.

Email hello@watt-systems.com with your questionnaire and we will complete it. If the honest answer to a line item is “not yet,” that is what you will get.

Security & data

Send us the questionnaire.

Bring your IT reviewer’s list. We will answer it in writing, including the parts where the answer is not yet a yes.