← all legal documents

Monitoring Risk Disclosure

version 2026-08-09·sha256 b48b4703812505703a7517f5ddc144aeea090b3095bc3276b37589558152536b
NetWatch Cloud observes network activity on every host where you install the agent. Depending on the features you enable, that includes: active TCP/UDP connections and the remote addresses they reach; the names and command paths of processes opening those connections; the operating-system user each process runs as; DNS queries made by the host; and, where live capture is explicitly enabled per host, packet header metadata such as TLS SNI hostnames and HTTP/3 request targets. This is surveillance-capable data. Understand and accept the following before you continue: 1. LEGAL EXPOSURE. Monitoring network traffic on machines you do not own, or without informing the people who use them, may be unlawful. Depending on jurisdiction this can engage wiretap and interception statutes, computer-misuse law, data-protection law (including the GDPR and equivalents), and employment or works-council obligations. You are responsible for having a lawful basis and for any notices or consents your jurisdiction requires from the people whose activity is observed. 2. PERSONAL DATA. Hostnames, usernames, IP addresses, DNS queries and visited domains can identify individuals and can reveal health, political, religious or sexual-orientation information by inference. Treat what NetWatch collects as personal data. 3. AUTHORIZATION. Only install the agent on hosts you own or are explicitly authorized in writing to monitor. Do not use NetWatch to monitor third parties, shared or public networks, or another organization's infrastructure without that authorization. 4. DATA LEAVES YOUR HOST. The agent transmits collected telemetry to NetWatch Cloud, where it is stored for your account's retention period. Live packet capture, where enabled, streams metadata off the host in real time. Capture is metadata-only and always redacted — no payload bodies are transmitted — but metadata alone is still revealing. 5. NO WARRANTY, NOT A COMPLIANCE CONTROL. NetWatch Cloud is provided as-is. It is a diagnostic and observability tool. It is not certified for, and must not be relied upon as, a regulatory monitoring, lawful-intercept, data-loss-prevention or security-compliance control. Detections can miss events and can produce false positives. 6. YOUR OPERATIONAL DUTIES. You are responsible for keeping API keys secret, revoking credentials for decommissioned hosts, setting a retention period appropriate to your obligations, restricting who you invite into your workspace, and enabling per-host capture only where you have a specific and lawful reason. By acknowledging, you confirm that you have read this disclosure, that you accept these risks, and that you are authorized to monitor every host on which you install the agent.

Questions about this document? Email admin@netwatchlabs.com.