The answers procurement asks for, in public.
Monitoring sits inside your perimeter: it knows your hostnames, your response times and often a credential or two. That earns you a straight answer about how it is run — including the parts we do not have, which are at the bottom of this page rather than left out of it.
Where it runs
German infrastructure, EU only
Application, database and checkers run on Hetzner in Germany. Customer data does not leave the EU in normal operation.
A closed network
The servers talk to each other over a private network. Only port 443 is reachable from the internet — the database, the message bus and the metrics endpoints are not exposed at all.
Published probes
Our checkers come from fixed, published egress addresses and identify themselves in the user agent, so you can allowlist us by IP instead of by trust.
Who gets in
Revocable, opaque sessions
Browser sessions are random opaque tokens in a host-only, HttpOnly cookie. Only their hash is stored server-side, so a database copy does not yield a usable session. You can list your active sessions and revoke any of them — or all the others at once.
Two-factor authentication
TOTP with backup codes, per user. A company can make it mandatory for everyone in the organization from the security settings.
Scoped API keys
Public API access uses pls_ Bearer keys with explicit scopes, created and revoked by you. Test keys (pls_test_) run against a sandbox organization so an integration can be built without touching production.
Separate operator plane
Platform operators authenticate on their own domain with their own session and mandatory 2FA. Customer-facing routes cannot reach operator functions, and operator actions are written to a separate audit trail.
What happens to your data
Encrypted secrets
Credentials you give us for alert channels — Twilio tokens, webhook secrets, API keys — are encrypted with AES-256-GCM before they are stored, not merely hashed or hidden in the interface.
Signed outbound webhooks
Every webhook delivery carries an HMAC-SHA256 signature over the payload so your receiver can reject anything that did not come from us. Verification snippets are in the docs.
Retention you can predict
Individual check results live at most 7 days in the primary database, then as aggregated rollups and a compressed archive for your plan’s window — 30 days on pay as you go, 90 on Team, 365 on Agency.
Deletion that deletes
You can export everything at any time, and deleting your account removes the account and its data rather than flagging it hidden.
What you can prove to your own auditor
A signed DPA
The data processing agreement (AVV) is a download, not a sales call, and it names every subprocessor.
A subprocessor list
Published in the privacy policy, with the legal basis for each transfer outside the EU/EEA.
An organization audit log
Security-relevant changes — sessions revoked, keys rotated, settings changed, status-page access tokens issued — are recorded and readable by the company’s admins.
Access-controlled status pages
A status page can be restricted to an IP allowlist or an access link, so internal or client-only pages are not simply unlisted URLs.
What we do not have.
A security page that only lists strengths is a marketing page. These are the gaps a careful reader would find anyway.
| Not available | The honest version |
|---|---|
| SOC 2 / ISO 27001 | We do not hold either. We are a small company and we are not going to imply an audit we have not had. If a report is a hard requirement for your procurement, we are the wrong vendor today — tell us anyway, because it tells us when to start. |
| SAML single sign-on | Built as far as the settings screen and no further; it is honestly labelled as unavailable in the product. TOTP and mandatory 2FA are the current controls. |
| A bug-bounty programme | No paid bounty yet. Reports are read by the person who can fix them, usually the same day — see below. |
Found a hole? We would rather hear it from you.
Use the contact form with the security topic — it lands with priority — or write to hello@upfour.io with “security” in the subject. Include what you did, what happened, and what you expected; a proof of concept helps but is not required.
We aim to acknowledge within one business day and to tell you honestly whether we can fix it quickly or not. Please give us a reasonable window before publishing. We do not pay a bounty yet and will not pretend otherwise — but we do say thank you in public, and we will never argue that a real finding was out of scope.
The questions that come up in reviews
Does customer data leave the EU?
Can you sign our DPA instead of yours?
What does up4 store that is sensitive?
What happens if an up4 employee wants to look at my account?
How do you handle a breach?
Is the status page hosted with everything else?
Trust, but <em>verify.</em>
€3 credit · no card · signed DPA as a download