Security and privacy, built in

A monitoring service holds the keys to your infrastructure — URLs, credentials and alert contacts. Here is how Uptime Tracker protects them.

[ 001 ]

Account protection

  • Passwordless sign-in with single-use, 15-minute email links or codes
  • TOTP two-factor authentication with single-use recovery codes on every plan
  • Rate-limited sign-in and lockout after repeated wrong codes
  • Session list with remote sign-out
  • Secure, HttpOnly, SameSite cookies and CSRF defences
[ 002 ]

Tenant isolation

  • PostgreSQL row-level security enforces workspace boundaries in the database itself
  • Every API request is authorised against the signed-in member or scoped token
  • Guests see only the project they were invited to
  • Public status pages expose an allow-listed projection, never internal monitor records
[ 003 ]

Secrets and data

  • Credentials you store (API keys, webhook signing secrets, bot tokens) are encrypted before storage and never displayed again
  • Monitor headers that reference secrets are dropped on cross-origin redirects
  • Exports exclude secrets and heartbeat tokens and neutralise spreadsheet formulas
  • Heartbeat URLs are kept out of access logs
[ 004 ]

Infrastructure

  • Application and primary database in Estonia (EU); traffic through Cloudflare with TLS
  • HSTS and strict security headers on every response
  • Continuous WAL archiving and encrypted, versioned off-site backups in AWS (us-east-1)
  • Automated restore drills that verify recovery within target
[ 005 ]

Safe monitoring

  • Monitors cannot target private, loopback or internal network addresses (SSRF protection)
  • Plan-based check intervals and a clear, identifiable monitoring User-Agent
  • SMTP and IMAP checks never authenticate or send mail
  • Outbound webhooks are signed with HMAC-SHA256 and a timestamp to prevent replay
[ 006 ]

Accountability

  • Append-only audit log of workspace changes with request IDs (Team)
  • Payments handled by Stripe; card details never touch our servers
  • No advertising trackers and no sale of personal data
  • Clear data deletion: cancellation is not deletion, and workspace deletion is a confirmed, separate step
Responsible disclosure

Found an issue? Tell us.

Email [email protected]. Test only against your own account, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before sharing details. Our security.txt lists the same contact.

FAQ

Frequently asked questions

Where is my data stored?

The Uptime Tracker application and primary PostgreSQL database run on a server in Estonia (European Union). Encrypted backups are stored in Amazon Web Services us-east-1 (United States), and traffic passes through Cloudflare. See the privacy policy for the full list of service providers.

Do you support two-factor authentication?

Yes. Any user on any plan can enable TOTP two-factor authentication with an authenticator app. Recovery codes are provided, and disabling 2FA or regenerating codes requires a fresh second factor.

How do I report a security vulnerability?

Email [email protected] with a description, steps to reproduce and the impact you observed. Please do not access other customers’ data or degrade the service while testing. We will acknowledge your report and keep you updated.

Uptime Tracker

Start monitoring in under five minutes

Start on the free plan — commercial use allowed. No credit card, no password, just your email address.

  • Free forever plan
  • No credit card
  • Cancel anytime