Encrypted credentials
Proxy usernames and passwords, provider API tokens, and Discord webhook URLs are encrypted with AES-256-GCM before they are stored.
Security
BoundWatch stores the minimum information needed to organize and monitor your pools. We do not sell, share, or repurpose proxy lists.
Proxy usernames and passwords, provider API tokens, and Discord webhook URLs are encrypted with AES-256-GCM before they are stored.
Encryption keys remain in the server environment. Credentials are decrypted only inside authenticated server processes when a feature needs them.
Database row-level security limits each signed-in account to its own groups, proxies, settings, and check history.
Scheduled reachability monitoring checks only the proxy host and port. Credentials are used when you request a forwarding or retailer check through the proxy.
Proxy hostnames or IP addresses, ports, protocols, health results, and timestamps remain queryable so BoundWatch can schedule checks and display your dashboard. They are protected by account-scoped database policies but are not encrypted with the credential key.
A retailer or forwarding check sends a request through the selected proxy to the destination shown in your group configuration. Background TCP monitoring connects only to the proxy endpoint and does not send the username or password to a retailer.
Email support@boundwatch.com with security questions or suspected vulnerabilities.