Read-only by design
The guarantee
Midwatch only ever issues GET requests against your n8n API. There is no code path that writes: it cannot edit a workflow, execute a run, toggle active state, or delete anything. This is enforced in the connector itself, not by promise.
Cloudflare accounts
A Cloudflare account connects with an API token scoped to exactly two read-only permissions: Account Analytics: Read and Workers Scripts: Read. Cloudflare enforces those scopes, so read-only is a property of the key rather than of our code. Midwatch never calls a mutating endpoint: it cannot deploy, edit, or delete a Worker, change a cron trigger, or touch anything else in your account. Analytics queries are GraphQL, which is an HTTP POST by protocol, but the token cannot write regardless of the verb.
The token is encrypted at rest exactly like an n8n API key: AES-256-GCM, with the master key held as a platform secret outside the database.
What we store / what we never store
What we store
- Workflow metadata (names, ids, active state, definition hashes and normalized definitions for drift diffs)
- Execution rollups (counts, statuses, timestamps)
- Alert history
What we never store
- Execution payload bodies
- The business data flowing through workflows
- Credential values or secrets
How your API key is held
Your API key is encrypted with AES-256-GCM before it is stored - the database only ever holds ciphertext. The master encryption key lives as a platform secret on Cloudflare, outside the database entirely, so neither can expose your key without the other. Keys are never logged and never rendered back to a page.
Tenant isolation
Every row is org-scoped with row-level security. Client-mapped views mean an agency's clients are separated inside the org too.
Report share links
A client report link is an unguessable token. Only approved reports resolve; drafts and unknown tokens 404 identically, and every share page carries noindex headers - a guessed URL leaks nothing and search engines index nothing.
Data deletion
Ask and it is gone: we delete an org's rows on request, and the read-only design means there is nothing of your business data to delete beyond monitoring metadata.
Questions
Ask us anything about how Midwatch handles your fleet's data.