Security & data protection

The answers procurement asks for, in public.

Monitoring sits inside your perimeter: it knows your hostnames, your response times and often a credential or two. That earns you a straight answer about how it is run — including the parts we do not have, which are at the bottom of this page rather than left out of it.

Where it runs

German infrastructure, EU only

Application, database and checkers run on Hetzner in Germany. Customer data does not leave the EU in normal operation.

A closed network

The servers talk to each other over a private network. Only port 443 is reachable from the internet — the database, the message bus and the metrics endpoints are not exposed at all.

Published probes

Our checkers come from fixed, published egress addresses and identify themselves in the user agent, so you can allowlist us by IP instead of by trust.

Who gets in

Revocable, opaque sessions

Browser sessions are random opaque tokens in a host-only, HttpOnly cookie. Only their hash is stored server-side, so a database copy does not yield a usable session. You can list your active sessions and revoke any of them — or all the others at once.

Two-factor authentication

TOTP with backup codes, per user. A company can make it mandatory for everyone in the organization from the security settings.

Scoped API keys

Public API access uses pls_ Bearer keys with explicit scopes, created and revoked by you. Test keys (pls_test_) run against a sandbox organization so an integration can be built without touching production.

Separate operator plane

Platform operators authenticate on their own domain with their own session and mandatory 2FA. Customer-facing routes cannot reach operator functions, and operator actions are written to a separate audit trail.

What happens to your data

Encrypted secrets

Credentials you give us for alert channels — Twilio tokens, webhook secrets, API keys — are encrypted with AES-256-GCM before they are stored, not merely hashed or hidden in the interface.

Signed outbound webhooks

Every webhook delivery carries an HMAC-SHA256 signature over the payload so your receiver can reject anything that did not come from us. Verification snippets are in the docs.

Retention you can predict

Individual check results live at most 7 days in the primary database, then as aggregated rollups and a compressed archive for your plan’s window — 30 days on pay as you go, 90 on Team, 365 on Agency.

Deletion that deletes

You can export everything at any time, and deleting your account removes the account and its data rather than flagging it hidden.

What you can prove to your own auditor

A signed DPA

The data processing agreement (AVV) is a download, not a sales call, and it names every subprocessor.

A subprocessor list

Published in the privacy policy, with the legal basis for each transfer outside the EU/EEA.

An organization audit log

Security-relevant changes — sessions revoked, keys rotated, settings changed, status-page access tokens issued — are recorded and readable by the company’s admins.

Access-controlled status pages

A status page can be restricted to an IP allowlist or an access link, so internal or client-only pages are not simply unlisted URLs.

The quiet part, out loud

What we do not have.

A security page that only lists strengths is a marketing page. These are the gaps a careful reader would find anyway.

Not availableThe honest version
SOC 2 / ISO 27001We do not hold either. We are a small company and we are not going to imply an audit we have not had. If a report is a hard requirement for your procurement, we are the wrong vendor today — tell us anyway, because it tells us when to start.
SAML single sign-onBuilt as far as the settings screen and no further; it is honestly labelled as unavailable in the product. TOTP and mandatory 2FA are the current controls.
A bug-bounty programmeNo paid bounty yet. Reports are read by the person who can fix them, usually the same day — see below.
Reporting something

Found a hole? We would rather hear it from you.

Use the contact form with the security topic — it lands with priority — or write to hello@upfour.io with “security” in the subject. Include what you did, what happened, and what you expected; a proof of concept helps but is not required.

We aim to acknowledge within one business day and to tell you honestly whether we can fix it quickly or not. Please give us a reasonable window before publishing. We do not pay a bounty yet and will not pretend otherwise — but we do say thank you in public, and we will never argue that a real finding was out of scope.

Download the DPA Where checks come from

FAQ

The questions that come up in reviews

Does customer data leave the EU?
Not in normal operation — the application, database and EU checkers are in Germany. Two things are worth naming precisely: some subprocessors are US companies with EU-hosted or EU-safeguarded processing (email delivery, payments, error monitoring, cold archive), each listed with its legal basis in the privacy policy; and alert channels you configure — Slack, PagerDuty, Telegram — receive alert data under their own terms, wherever they run.
Can you sign our DPA instead of yours?
Usually yes. Ours is written to be signable as-is and is a download rather than a negotiation, but if your legal team needs their own paper, send it to us and we will read it rather than reflexively refuse.
What does up4 store that is sensitive?
Monitor configuration (hostnames, headers, expected content), check results and incident history, plus any credentials you deliberately give a monitor or alert channel. Those credentials are encrypted at the application layer with AES-256-GCM. We do not store your customers’ data, because we never see it: a check reads a status code and a response time, not a page of user records.
What happens if an up4 employee wants to look at my account?
Operator access is a separate authenticated plane with mandatory 2FA, and its actions are written to an audit trail that the operator cannot edit. The company is small enough that the honest answer is “a named person, whose actions are logged” rather than “a role-based access matrix”.
How do you handle a breach?
We notify affected customers without undue delay and within the GDPR’s 72-hour window where it applies, with what we know, what we do not yet know, and what we are doing. We would rather send an incomplete notice on day one than a polished one on day five.
Is the status page hosted with everything else?
No, deliberately: status.upfour.io runs off our own infrastructure. A status page that goes down with the thing it reports on is decoration.

Trust, but <em>verify.</em>

€3 credit · no card · signed DPA as a download