The answers procurement asks for, in public.
Monitoring sits inside your perimeter: it knows your hostnames, your response times and often a credential or two. That earns you a straight answer about how it is run — including the parts we do not have, which are at the bottom of this page rather than left out of it.
Where it runs
German core infrastructure, global checks
The application and database run on Hetzner in Germany. Checkers run on Hetzner and UpCloud infrastructure, including outside the EU. Your selected regions determine where the configuration needed for a check is processed.
Protected service connections
Core infrastructure communicates over an access-restricted private network. External checkers connect through encrypted WSS with individual credentials and restricted messaging permissions. The database and internal metrics endpoints are not publicly reachable.
Published probes
Our checkers come from fixed, published egress addresses and identify themselves in the user agent, so you can allowlist us by IP instead of by trust.
Who gets in
Revocable, opaque sessions
Browser sessions are random opaque tokens in a host-only, HttpOnly cookie. Only their hash is stored server-side, so a database copy does not yield a usable session. You can list your active sessions and revoke any of them — or all the others at once.
Two-factor authentication
TOTP with backup codes, per user. A company can make it mandatory for everyone in the organization from the security settings.
Scoped API keys
Public API access uses pls_ Bearer keys with explicit scopes, created and revoked by you. Test keys (pls_test_) run against a sandbox organization so an integration can be built without touching production.
Separate operator plane
Platform operators authenticate on their own domain with their own session and mandatory 2FA. Customer-facing routes cannot reach operator functions, and operator actions are written to a separate audit trail.
What happens to your data
Encrypted credentials
HTTP Basic Auth passwords, custom monitor headers and the defined secret fields of alert channels are encrypted with AES-256-GCM before storage. Request bodies are outside the scope of this field encryption.
Signed outbound webhooks
Every webhook delivery carries an HMAC-SHA256 signature over the payload so your receiver can reject anything that did not come from us. Verification snippets are in the docs.
Retention you can predict
Individual check results live at most 7 days in the primary database, then as aggregated rollups and a compressed archive for your plan’s window — 62 days on pay as you go, 90 on Team, 365 on Agency.
Requesting deletion
You can export your monitoring data through Reporting. Request account deletion by email; we verify your identity and confirm the scope, any records that must be retained, and the next steps. A member’s request concerns their own identity; deleting the whole company requires its owner’s explicit request.
What you can prove to your own auditor
Data processing agreement
The current contractual documentation is described under data processing.
Providers and data locations
The privacy policy describes the providers we use, their tasks and international processing, and links to their privacy and transfer terms.
An organization audit log
Security-relevant changes — sessions revoked, keys rotated, settings changed, status-page access tokens issued — are recorded and readable by the company’s admins.
Access-controlled status pages
A status page can be restricted to an IP allowlist or an access link, so internal or client-only pages are not simply unlisted URLs.
What we do not have.
A security page that only lists strengths is a marketing page. These are the gaps a careful reader would find anyway.
| Not available | The honest version |
|---|---|
| SOC 2 / ISO 27001 | We do not hold either. We are a small company and we are not going to imply an audit we have not had. If a report is a hard requirement for your procurement, we are the wrong vendor today — tell us anyway, because it tells us when to start. |
| SAML single sign-on | Built as far as the settings screen and no further; it is honestly labelled as unavailable in the product. TOTP and mandatory 2FA are the current controls. |
| A bug-bounty programme | No paid bounty yet. Reports are read by the person who can fix them, usually the same day — see below. |
Found a hole? We would rather hear it from you.
Use the contact form with the security topic — it lands with priority — or write to hello@upfour.io with “security” in the subject. Include what you did, what happened, and what you expected; a proof of concept helps but is not required.
We aim to acknowledge within one business day and to tell you honestly whether we can fix it quickly or not. Please give us a reasonable window before publishing. We do not pay a bounty yet and will not pretend otherwise — but we do say thank you in public, and we will never argue that a real finding was out of scope.