Trust & Security

Security, privacy, infrastructure, and data protection at StatusPage.me — a two-minute overview, with links to the full detail.

Start Free Trial

Last updated: September 4, 2026

Security at a glance

Persistent application data is hosted in Germany (EU).
TLS with HSTS everywhere, including auto-HTTPS for custom domains.
Passwords are hashed with Argon2id; passkeys (WebAuthn) and TOTP 2FA are supported.
Monitor credentials aren't returned by read APIs or shown back in the edit form.
Daily database backups, retained on a rolling schedule.
Self-hosted, cookie-free analytics (Plausible) — no ad trackers.
We do not sell personal data.
Public vulnerability reporting channel, with a researcher acknowledgements list.

Infrastructure & data residency

Persistent application dataHosted in Germany (EU) — currently Munich, migrating to Nuremberg.
Monitoring / probe networkUptime checks run from an 11-location global network spanning North & South America, Europe, Africa, and Asia-Pacific — this is intentionally global, not EU-only, so accurate multi-region uptime data can be produced.
SubprocessorsA dated, public catalog lists every provider, its purpose, and its location. See Subprocessors.

Because monitoring runs globally, transient check traffic can originate outside the EU even though persistent customer data does not leave Germany. See Security for the full breakdown.

Authentication & access

Password protectionArgon2id hashing; HaveIBeenPwned breach checking at signup/change.
Two-factor authenticationTOTP and WebAuthn passkeys/security keys, for both user and admin accounts.
Session securitySecure, HttpOnly session cookies; a password change or admin-forced ban invalidates every active session for that account immediately.
Role-based accessTeam members hold Owner, Admin, Editor, or Viewer roles with different permissions on shared resources.

Full detail: Security → Authentication & Access.

Encryption & credential protection

We're precise about which of these apply where — hashing, encryption, and "never returned to the client" are different properties, and we don't collapse them into one umbrella claim.

In transitTLS with HSTS everywhere, including custom domains (auto-HTTPS via Let's Encrypt).
Hashed (irreversible)Passwords (Argon2id), API keys (SHA-256), and access-log IP addresses (SHA-256).
Encrypted (recoverable)OAuth access/refresh tokens and select integration secrets, with AES-256-GCM. This is a scoped set of fields, not a blanket "database encrypted at rest" claim.
Never returned to the clientExisting monitor request credentials (custom headers, query parameters, body, and auth fields) are omitted from monitor read responses and never re-rendered into the edit form as plaintext.

Full detail: Security → Encryption.

Application security

CSRFSession-bound tokens on state-changing requests across the dashboard and admin panel.
SSRFOutbound requests from user-supplied monitor/webhook targets block private, loopback, link-local, and cloud-metadata IP ranges, with redirect re-validation.
Rate limitingPer-IP limits on authentication, the public API, and public status-page rendering, with escalating temporary blocks.
UploadsAvatar/logo SVG uploads are validated and sanitized before storage.

Full detail: Security → Application Security.

Privacy & data protection

AnalyticsSelf-hosted, cookie-free Plausible Community Edition — no third-party ad/analytics trackers.
CookiesEssential first-party cookies only (session + CSRF).
IP addressesHashed with SHA-256 before storage; raw IPs are not stored.
Sale of personal dataWe do not sell personal data. (Policy commitment — see Privacy Policy.)
Your rightsGDPR/CCPA access, correction, portability, and deletion rights — see Privacy Policy for the full list and how to exercise them.

Full detail: Privacy Policy · Privacy-Friendly Overview.

Retention & deletion

Closing your account immediately flags it as closed, and your data is scheduled for removal from active systems under our retention policy — targeting 60 days for account data and 90 days for hashed access logs.

For the full policy, or to confirm your data has been removed, see our Privacy Policy or contact privacy@statuspage.me.

Backups & recovery

Automated daily database backups run with weekly/monthly rotation, alongside timestamped application backups on every deployment. See Security → Backups & Recovery for our documented restore procedure.

Subprocessors

We maintain a public, dated list of the service providers and subprocessors we use, what they do, and where they're located — including hosting, our global monitoring network, and optional integrations you configure yourself.

View all subprocessors

Incident response

We monitor our own infrastructure with the same multi-region checks we offer customers, and publish incidents on our own public status page. We don't currently offer a formal incident-response SLA or a 24/7 SOC — see status.statuspage.me for live status and history.

Vulnerability reporting

Found a security issue? Email security@statuspage.me with details and reproduction steps. We don't run a paid bug-bounty program, but verified reporters can be credited in our public acknowledgements list.

See Security → Report a vulnerability and our Responsible Disclosure policy.

Compliance & transparency

We follow SOC 2-aligned practices but have not completed a formal SOC 2, ISO 27001, or PCI DSS audit, and don't claim one. We'd rather tell you plainly what we have and haven't done than imply a certification we don't hold.

Full disclosure list: Security → What we don't have (yet).