← Back to home

Security & Compliance

How we protect your data and meet your compliance requirements.

Last updated: August 17, 2026

1. Security Practices

Security is fundamental to a monitoring platform — our customers trust us with the availability of their critical infrastructure. We apply industry-standard security practices across every layer:

  • Encryption in transit: All connections use TLS 1.2 or higher. No exceptions.
  • Encryption at rest: All stored data is encrypted using AES-256.
  • Authentication: Passwords are hashed using bcrypt. OAuth (Google, GitHub) supported. Session tokens use HTTP-only, Secure, SameSite cookies.
  • API key security: API keys are stored as SHA-256 hashes and shown only once at creation. Worker keys use 48 random hex bytes with SHA-256 hashing.
  • Row-level security: Database-level tenant isolation ensures that application bugs cannot leak data between accounts.
  • SSRF prevention: Cloud monitoring checks block requests to private/reserved IP ranges, loopback, link-local, and cloud metadata endpoints.
  • HTTP security headers: Strict CSP, HSTS with preload, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy on all responses.
  • Rate limiting: Authentication endpoints (5 req/min), API endpoints (10 req/sec), and public tools (5 req/min) are rate-limited per IP.
  • Error tracking: Runtime errors are captured and monitored via Sentry for rapid incident response.
  • Dependency management: Regular security patches and dependency updates with continuous integration checks.

2. Infrastructure

  • Monitoring checks execute from 5 global regions (US East, US West, EU East, EU Central, Asia-Pacific) with consensus-based alerting to eliminate false positives.
  • Application servers run in cluster mode with automatic restart and zero-downtime deployments.
  • All inter-service communication uses encrypted tunnels — no services are exposed to the public internet.
  • Infrastructure is hosted in EU-based datacenters compliant with EU data residency requirements.

3. Sub-Processors

We share data only with the following third-party service providers, strictly to deliver our service. Each sub-processor has been evaluated for security and compliance:

ProviderPurposeData ProcessedLocation
SupabaseAuthenticationEmail, OAuth tokensUS/EU
PaddleBilling & paymentsName, email, payment infoUK/EU
ResendEmail deliveryRecipient emailUS
VonageSMS alertsPhone number (opt-in only)US/EU
CloudflareCDN & securityRequest metadataGlobal

Google Analytics is used on the marketing website (monitorion.com) only, not within the application.

4. Data Processing Agreement (DPA)

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller") and the data processor identified below ("Processor") for the provision of the Monitorion monitoring service.

Data Processor

Monitorion · Czech Republic (EU) · [email protected]

Scope

The Processor processes personal data (account information, monitoring configuration, check results, alert settings) solely to provide the monitoring service as described in the Terms of Service.

Data Retention

Monitoring data retention varies by subscription plan (see Pricing). Account data is retained until account deletion.

Security & Sub-Processors

Industry-standard encryption, access controls, and tenant isolation. Sub-processors listed in Section 3 above. Changes notified via updates to this page.

Data Subject Rights & Breach Notification

We assist in responding to data subject requests within 30 days. In the event of a data breach, affected parties are notified within 72 hours per GDPR Article 33. Contact: [email protected]

International Transfers

Primary data storage is in the EU. Where data is transferred outside the EU/EEA, Standard Contractual Clauses (SCCs) are in place.

5. GDPR Compliance

Monitorion is operated from the Czech Republic (EU member state). We comply with the General Data Protection Regulation (GDPR):

  • Lawful basis: We process data based on contractual necessity (providing the monitoring service) and legitimate interest (improving the service, preventing abuse).
  • Data minimization: We collect only the data necessary to provide the service.
  • Right to erasure: Users can delete their account and all associated data via Settings → Delete Account. This permanently removes all monitors, checks, incidents, projects, and personal data.
  • Data portability: Check history can be exported as CSV from the monitor detail page.
  • EU data residency: Primary data storage is in EU-based infrastructure.
  • Cookie consent: We use a cookie consent banner. Analytics cookies (marketing site only) require opt-in.

6. Incident Response

In the event of a security incident:

  • Automated error tracking alerts the engineering team immediately on anomalies.
  • Affected customers are notified within 72 hours of a confirmed data breach, per GDPR Article 33.
  • Post-incident analysis is conducted and documented, with preventive measures implemented.
  • Platform availability is published on our status page.

7. Contact

For security inquiries, DPA requests, or to report a vulnerability:

Monitorion

Czech Republic (EU)

Email: [email protected]