Strict tenant isolation
Every record carries a tenant id and every query is scoped to it. A client account can only ever read its own data.
Security
Every claim on this page is verifiable in the codebase. There are no certifications listed here, because we do not hold any — and a badge nobody audited is worth less than a sentence you can check.
Every record carries a tenant id and every query is scoped to it. A client account can only ever read its own data.
No third-party monitoring API is involved, so your clients’ URLs are never handed to a vendor.
Monitored targets are resolved before they are used, and private, loopback and link-local addresses are refused — when a site is saved, and again before every check.
Passwords are hashed with bcrypt. Reset links are single-use, time-limited and stored only as hashes. Repeated login attempts from one address are rate-limited.
The database is backed up every day, and restoring from those backups is verified rather than assumed.
Every “view as user” session an administrator opens is written to an audit log — who, whom, when and from where.
If your own client needs a specific answer about how their data is held, ask and you will get a straight one.