Security & Compliance
How we protect your data and meet your compliance requirements.
Last updated: August 17, 2026
1. Security Practices
Security is fundamental to a monitoring platform — our customers trust us with the availability of their critical infrastructure. We apply industry-standard security practices across every layer:
- Encryption in transit: All connections use TLS 1.2 or higher. No exceptions.
- Encryption at rest: All stored data is encrypted using AES-256.
- Authentication: Passwords are hashed using bcrypt. OAuth (Google, GitHub) supported. Session tokens use HTTP-only, Secure, SameSite cookies.
- API key security: API keys are stored as SHA-256 hashes and shown only once at creation. Worker keys use 48 random hex bytes with SHA-256 hashing.
- Row-level security: Database-level tenant isolation ensures that application bugs cannot leak data between accounts.
- SSRF prevention: Cloud monitoring checks block requests to private/reserved IP ranges, loopback, link-local, and cloud metadata endpoints.
- HTTP security headers: Strict CSP, HSTS with preload, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy on all responses.
- Rate limiting: Authentication endpoints (5 req/min), API endpoints (10 req/sec), and public tools (5 req/min) are rate-limited per IP.
- Error tracking: Runtime errors are captured and monitored via Sentry for rapid incident response.
- Dependency management: Regular security patches and dependency updates with continuous integration checks.
2. Infrastructure
- Monitoring checks execute from 5 global regions (US East, US West, EU East, EU Central, Asia-Pacific) with consensus-based alerting to eliminate false positives.
- Application servers run in cluster mode with automatic restart and zero-downtime deployments.
- All inter-service communication uses encrypted tunnels — no services are exposed to the public internet.
- Infrastructure is hosted in EU-based datacenters compliant with EU data residency requirements.
3. Sub-Processors
We share data only with the following third-party service providers, strictly to deliver our service. Each sub-processor has been evaluated for security and compliance:
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Authentication | Email, OAuth tokens | US/EU |
| Paddle | Billing & payments | Name, email, payment info | UK/EU |
| Resend | Email delivery | Recipient email | US |
| Vonage | SMS alerts | Phone number (opt-in only) | US/EU |
| Cloudflare | CDN & security | Request metadata | Global |
Google Analytics is used on the marketing website (monitorion.com) only, not within the application.
4. Data Processing Agreement (DPA)
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller") and the data processor identified below ("Processor") for the provision of the Monitorion monitoring service.
Data Processor
Monitorion · Czech Republic (EU) · [email protected]
Scope
The Processor processes personal data (account information, monitoring configuration, check results, alert settings) solely to provide the monitoring service as described in the Terms of Service.
Data Retention
Monitoring data retention varies by subscription plan (see Pricing). Account data is retained until account deletion.
Security & Sub-Processors
Industry-standard encryption, access controls, and tenant isolation. Sub-processors listed in Section 3 above. Changes notified via updates to this page.
Data Subject Rights & Breach Notification
We assist in responding to data subject requests within 30 days. In the event of a data breach, affected parties are notified within 72 hours per GDPR Article 33. Contact: [email protected]
International Transfers
Primary data storage is in the EU. Where data is transferred outside the EU/EEA, Standard Contractual Clauses (SCCs) are in place.
5. GDPR Compliance
Monitorion is operated from the Czech Republic (EU member state). We comply with the General Data Protection Regulation (GDPR):
- Lawful basis: We process data based on contractual necessity (providing the monitoring service) and legitimate interest (improving the service, preventing abuse).
- Data minimization: We collect only the data necessary to provide the service.
- Right to erasure: Users can delete their account and all associated data via Settings → Delete Account. This permanently removes all monitors, checks, incidents, projects, and personal data.
- Data portability: Check history can be exported as CSV from the monitor detail page.
- EU data residency: Primary data storage is in EU-based infrastructure.
- Cookie consent: We use a cookie consent banner. Analytics cookies (marketing site only) require opt-in.
6. Incident Response
In the event of a security incident:
- Automated error tracking alerts the engineering team immediately on anomalies.
- Affected customers are notified within 72 hours of a confirmed data breach, per GDPR Article 33.
- Post-incident analysis is conducted and documented, with preventive measures implemented.
- Platform availability is published on our status page.
7. Contact
For security inquiries, DPA requests, or to report a vulnerability:
See also: Privacy Policy · Terms of Service