Credential encryption
Integration credentials are encrypted with AES-256-GCM using a derived application key, unique initialization vectors, and authentication tags.
Write-only secrets · Versioned ciphertext
A transparent view of how Uptime protects accounts, separates workspaces, handles sensitive credentials, records administrative activity, and approaches the controls still being built.
Credential vault
AES-256-GCM · authenticated ciphertext
Workspace boundary
Membership and permission checks
Access model
Owner · Admin · Member · Viewer
Audit evidence
Actor · target · request · outcome
This page distinguishes implemented controls from work in progress. No third-party certification is claimed without evidence.
Implemented controls
These are implementation-backed controls—not aspirations or compliance shorthand. Scope is stated precisely so your team can evaluate what each control protects.
Integration credentials are encrypted with AES-256-GCM using a derived application key, unique initialization vectors, and authentication tags.
Write-only secrets · Versioned ciphertext
Organization-scoped requests require an authenticated session, active membership, and permission for the requested action.
Membership + permission + scoped query
Owner, administrator, member, and viewer roles separate management privileges from read-only access across workspace resources.
Four workspace roles
Platform changes can retain actor, action, target, request, network, and before/after context while redacting sensitive field names.
Sensitive values redacted
Production authentication uses secure cookies, trusted origins, account-disable checks, and session revocation after password resets.
Secure production cookies
Public status responses use customer-facing component data and derived identifiers without exposing monitor targets or organization records.
Targets remain private
Tenant isolation
A workspace identifier alone is not authorization. Protected API routes establish the user session, verify organization membership, evaluate the role’s permission, and constrain the database operation to that organization.
Public status-page routes use a separate response shape designed to expose customer-facing health information without returning monitor targets or organization metadata.
Session
Authenticated user
Membership
Organization match
Permission
Action allowed
Scoped query
Tenant constrained
Authorized request
Unauthorized, disabled, or insufficiently privileged accounts are rejected before the protected operation proceeds.
Data handling
Uptime stores the account, workspace, telemetry, and delivery data needed to operate the service. Sensitive credentials follow a narrower storage and retrieval path.
Retention policy status
A universal deletion schedule is not yet published. Formal retention and deletion commitments are in progress.
Data class
Account and membership
Operational purpose
Authentication, organization access, invitations, and support
Current handling
Accessed through authenticated, role-aware operations
Data class
Monitoring telemetry
Operational purpose
Availability history, incident evidence, charts, and reports
Current handling
Organization-scoped; historical observations survive region retirement
Data class
Integration credentials
Operational purpose
Deliver notifications to configured destinations
Current handling
Application-encrypted and never returned in full after storage
Data class
Public status content
Operational purpose
Communicate component health, maintenance, and incidents
Current handling
Explicitly selected content with internal targets removed
Retiring a probe region does not erase the monitoring observations already associated with customer history.
Probe credentials and status-subscriber verification tokens are compared using stored hashes rather than plaintext token records.
Status-page owners choose a visible 30, 60, or 90-day history; that display setting does not imply deletion of source telemetry.
Control maturity
Security programs become less useful when roadmap items are presented as finished controls. This register shows the distinction plainly and will evolve with the platform.
Organization-scoped authorization
Membership and role permissions are evaluated before workspace data access.
Encrypted integration vault
AES-256-GCM protects stored provider credentials at the application layer.
Platform audit records
Administrative changes retain traceable context with sensitive-key redaction.
Published retention schedule
Documented deletion windows and customer-facing retention commitments.
Formal incident-response policy
Published severity, escalation, notification, and post-incident commitments.
Self-service session management
User-visible active sessions with individual and global revocation controls.
Multi-factor authentication
Additional account verification beyond the primary password flow.
Enterprise identity
SAML-based SSO and automated identity lifecycle management.
Independent compliance program
Evidence collection and third-party assessment before any certification claim.
Incident handling
Current operational tooling provides service heartbeats, platform audit evidence, account controls, and notification-delivery context. A formal external incident-response and notification policy is still being documented.
Step 1
Route the report to the security category and establish affected scope.
Step 2
Use request identifiers, audit context, sessions, and service health to investigate.
Step 3
Revoke access, disable affected accounts or credentials, and correct the vulnerable path.
Step 4
Notify affected parties as appropriate and retain remediation follow-through.
If you believe you found a security issue, send a private report with enough detail for the team to reproduce and assess it.
Please include
Testing boundaries
Do not access another customer’s data, include real user records, perform destructive tests, or degrade service availability. A public bug-bounty program and response-time SLA are not currently offered.
Need a deeper review?
Tell us about your architecture, procurement, or data-handling requirements and we will answer with the current platform scope.