New Read the founder's letter: "For All of Humanity"
Security & Trust

Trust is the architecture.

Watoko protects the data of farmers in remote highlands, cooperatives across the African continent, research universities, biotech partners, and sovereign programs. Encryption, jurisdictional sovereignty, biological sample chain-of-custody, and the discipline of operating in complexity where others cannot — on Earth and beyond.

Five commitments we will not break

Security at Watoko is not a checklist. It is a posture — the same posture that allows us to operate in environments that break everything else.

Farmer data belongs to the farmer

Every farmer who joins the network owns the data their land produces. We hold it in trust. They can withdraw it. We never sell individual-level data.

Sovereign data, sovereign rules

Sovereign customers — ministries of agriculture, space agencies, central banks — can require in-country residency, dedicated tenancy, and audit rights. We meet them where they are.

Biology before convenience

Biological samples and biomolecular data move under chain-of-custody discipline derived from clinical trials and aerospace material handling. We do not cut corners on the science of life.

Audit by default

Every agent decision — from a satellite alert to a payment instruction — is logged, signed, and replayable. Customers can inspect the chain at any moment.

Resilience over performance theater

We design for the worst environment, not the best demo. Offline operation, degraded network conditions, mesh resilience, encryption at rest and in transit — in the field, on satellites, in sealed habitats.

The infrastructure beneath the trust

A production-grade security architecture across data, identity, infrastructure, and application layers.

  • AES-256 encryption at rest, TLS 1.3 in transit, hardware-backed key management
  • Zero-trust network architecture with mTLS between every internal service
  • OAuth 2.0 and OIDC with hardware security key (WebAuthn) support for staff and partner administrators
  • Role-based access control with least-privilege defaults and quarterly entitlement reviews
  • Immutable, tamper-evident audit logs of every agent action, exported on demand to customers
  • Secrets managed in dedicated vaults — never in code, configuration, or chat
  • Continuous vulnerability scanning, dependency monitoring, and automated patching
  • Penetration testing by independent third parties on every major release

Built for environments that break everything else

Most security architectures assume the cloud, the office, and a stable network. Watoko assumes none of them. The platform was designed from day one for the highlands, the harbor, the research lab, and the closed-loop habitat — environments where the cost of failure is measured in harvests, in samples, and in human lives.

Standards we are aligned to

Watoko's security and privacy program is built to meet the obligations of every counterpart we serve — from a smallholder cooperative to a research university to a sovereign program.

SOC 2 Type II

Continuous audit of security, availability, and confidentiality controls. Report available under NDA to enterprise and institutional customers.

ISO 27001

Information security management system aligned to ISO 27001 controls, with formal certification on the 2026 roadmap.

GDPR & African data laws

Full compliance with GDPR, the African Union Convention on Cyber Security and Personal Data Protection, and country-level data protection acts across our operating jurisdictions.

EUDR & supply chain regulation

Cryptographically verifiable lot passports, satellite-grounded deforestation evidence, and audit-ready due diligence statements for the EU Deforestation Regulation.

Research & biosample standards

Chain-of-custody, consent, and biomolecular data handling aligned to GCP, the Nagoya Protocol, and institutional review board requirements of partner universities.

Aerospace-grade discipline

For closed-loop life-support and astrobiology partnerships, Watoko applies the documentation, traceability, and configuration management practices required of payload-class systems.

If you find something, tell us

Watoko welcomes responsible disclosure from security researchers. We commit to a 24-hour acknowledgment, a clear remediation timeline, and public credit when requested.

  • Email security@watoko.ai with technical detail and reproduction steps
  • Use our PGP key for sensitive reports (published at /.well-known/security.txt)
  • Do not access data beyond what is necessary to demonstrate the issue
  • Allow us reasonable time to remediate before public disclosure

Recognition over bounty

Watoko maintains a researcher hall of fame and provides public recognition for valid findings. Cash bounties are offered case-by-case for high-severity issues affecting production systems.

Need a deeper conversation?

Enterprise customers, sovereign programs, and research partners can request a security review, our SOC 2 report, or a custom data residency arrangement. Write to security@watoko.ai or talk to us directly.

Talk to security

Talk to security.

Tell us what you need. We respond within 24 hours.

"Watoko's security posture is the reason we trusted them with sovereign agricultural data from day one."
— Government Partner

Thank you!

Our security team will respond within 24 hours.