The site runs on Cloudflare Pages + D1 (Cloudflare's edge database). There's no server to hack in the traditional sense - no VPS, no exposed ports.
What the registry stores: serial number, reference, sub-reference, caliber, dial/bezel/caseback variant. No names, no emails, no IP addresses, no accounts. The submitter hash is a one-way SHA-256 of the request IP - used only for rate limiting, not identification. It can't be reversed.
I have no interest in owners' details. Only in creating a maximally usable and searchable database of the timepieces we are all obsessed with.
What it doesn't store: proof images are used to verify submissions and discarded. There's no photo gallery of a watch. No location data, purchase prices. Nothing that connects a watch to a person.
The concern about "casing your own home" assumes the registry links watches to owners. It doesn't. Knowing that a 145.022-69 with serial 31003555 exists tells you exactly as much as seeing it in a Christie's auction catalogue.
Every serial in the database is already publicly documente. I only aggregated public data. individual submissions have no identity to them. They're purely data points.
The source code for the site is inspectable.