Security & data protection

The answers procurement asks for, in public.

Monitoring sits inside your perimeter: it knows your hostnames, your response times and often a credential or two. That earns you a straight answer about how it is run — including the parts we do not have, which are at the bottom of this page rather than left out of it.

Where it runs

German core infrastructure, global checks

The application and database run on Hetzner in Germany. Checkers run on Hetzner and UpCloud infrastructure, including outside the EU. Your selected regions determine where the configuration needed for a check is processed.

Protected service connections

Core infrastructure communicates over an access-restricted private network. External checkers connect through encrypted WSS with individual credentials and restricted messaging permissions. The database and internal metrics endpoints are not publicly reachable.

Published probes

Our checkers come from fixed, published egress addresses and identify themselves in the user agent, so you can allowlist us by IP instead of by trust.

Who gets in

Revocable, opaque sessions

Browser sessions are random opaque tokens in a host-only, HttpOnly cookie. Only their hash is stored server-side, so a database copy does not yield a usable session. You can list your active sessions and revoke any of them — or all the others at once.

Two-factor authentication

TOTP with backup codes, per user. A company can make it mandatory for everyone in the organization from the security settings.

Scoped API keys

Public API access uses pls_ Bearer keys with explicit scopes, created and revoked by you. Test keys (pls_test_) run against a sandbox organization so an integration can be built without touching production.

Separate operator plane

Platform operators authenticate on their own domain with their own session and mandatory 2FA. Customer-facing routes cannot reach operator functions, and operator actions are written to a separate audit trail.

What happens to your data

Encrypted credentials

HTTP Basic Auth passwords, custom monitor headers and the defined secret fields of alert channels are encrypted with AES-256-GCM before storage. Request bodies are outside the scope of this field encryption.

Signed outbound webhooks

Every webhook delivery carries an HMAC-SHA256 signature over the payload so your receiver can reject anything that did not come from us. Verification snippets are in the docs.

Retention you can predict

Individual check results live at most 7 days in the primary database, then as aggregated rollups and a compressed archive for your plan’s window — 62 days on pay as you go, 90 on Team, 365 on Agency.

Requesting deletion

You can export your monitoring data through Reporting. Request account deletion by email; we verify your identity and confirm the scope, any records that must be retained, and the next steps. A member’s request concerns their own identity; deleting the whole company requires its owner’s explicit request.

What you can prove to your own auditor

Data processing agreement

The current contractual documentation is described under data processing.

Providers and data locations

The privacy policy describes the providers we use, their tasks and international processing, and links to their privacy and transfer terms.

An organization audit log

Security-relevant changes — sessions revoked, keys rotated, settings changed, status-page access tokens issued — are recorded and readable by the company’s admins.

Access-controlled status pages

A status page can be restricted to an IP allowlist or an access link, so internal or client-only pages are not simply unlisted URLs.

The quiet part, out loud

What we do not have.

A security page that only lists strengths is a marketing page. These are the gaps a careful reader would find anyway.

Not availableThe honest version
SOC 2 / ISO 27001We do not hold either. We are a small company and we are not going to imply an audit we have not had. If a report is a hard requirement for your procurement, we are the wrong vendor today — tell us anyway, because it tells us when to start.
SAML single sign-onBuilt as far as the settings screen and no further; it is honestly labelled as unavailable in the product. TOTP and mandatory 2FA are the current controls.
A bug-bounty programmeNo paid bounty yet. Reports are read by the person who can fix them, usually the same day — see below.
Reporting something

Found a hole? We would rather hear it from you.

Use the contact form with the security topic — it lands with priority — or write to hello@upfour.io with “security” in the subject. Include what you did, what happened, and what you expected; a proof of concept helps but is not required.

We aim to acknowledge within one business day and to tell you honestly whether we can fix it quickly or not. Please give us a reasonable window before publishing. We do not pay a bounty yet and will not pretend otherwise — but we do say thank you in public, and we will never argue that a real finding was out of scope.

Data processing Where checks come from

FAQ

The questions that come up in reviews

Does customer data leave the EU?
Yes, depending on selected check regions and services. Global checkers process the configuration needed for a check locally. Email, payments, support and cloud storage can also involve processing outside the EU. Providers are listed in the privacy policy. Alert integrations you configure receive the data needed to deliver the alert.
Can you review our DPA?
Send your contractual requirements through our contact form. We review the terms and the actual processing chain, including agency arrangements.
What data does a check process?
A check processes the target address and any credentials, headers and request body you configure. Keyword and content checks also read a bounded response body, which can contain personal data. Full HTTP response bodies are not stored as regular check results; results and incident history contain status, timing and error diagnostics.
What happens if an up4 employee wants to look at my account?
Operator access is a separate authenticated plane with mandatory 2FA, and its actions are written to an audit trail that the operator cannot edit. The company is small enough that the honest answer is “a named person, whose actions are logged” rather than “a role-based access matrix”.
How do you handle a personal data breach?
As a processor, we notify affected customers without undue delay after becoming aware. As a controller, we assess whether notification to the supervisory authority is required within 72 hours of awareness and whether affected people must be informed. We also document incidents that do not require notification.
Is the status page hosted with everything else?
No, deliberately: status.upfour.io runs off our own infrastructure. A status page that goes down with the thing it reports on is decoration.

Trust, but <em>verify.</em>

€9 starting credit · no card