Trust & Security
Security, privacy, infrastructure, and data protection at StatusPage.me — a two-minute overview, with links to the full detail.
Start Free TrialLast updated: September 4, 2026
Security at a glance
Infrastructure & data residency
| Persistent application data | Hosted in Germany (EU) — currently Munich, migrating to Nuremberg. |
| Monitoring / probe network | Uptime checks run from an 11-location global network spanning North & South America, Europe, Africa, and Asia-Pacific — this is intentionally global, not EU-only, so accurate multi-region uptime data can be produced. |
| Subprocessors | A dated, public catalog lists every provider, its purpose, and its location. See Subprocessors. |
Because monitoring runs globally, transient check traffic can originate outside the EU even though persistent customer data does not leave Germany. See Security for the full breakdown.
Authentication & access
| Password protection | Argon2id hashing; HaveIBeenPwned breach checking at signup/change. |
| Two-factor authentication | TOTP and WebAuthn passkeys/security keys, for both user and admin accounts. |
| Session security | Secure, HttpOnly session cookies; a password change or admin-forced ban invalidates every active session for that account immediately. |
| Role-based access | Team members hold Owner, Admin, Editor, or Viewer roles with different permissions on shared resources. |
Full detail: Security → Authentication & Access.
Encryption & credential protection
We're precise about which of these apply where — hashing, encryption, and "never returned to the client" are different properties, and we don't collapse them into one umbrella claim.
| In transit | TLS with HSTS everywhere, including custom domains (auto-HTTPS via Let's Encrypt). |
| Hashed (irreversible) | Passwords (Argon2id), API keys (SHA-256), and access-log IP addresses (SHA-256). |
| Encrypted (recoverable) | OAuth access/refresh tokens and select integration secrets, with AES-256-GCM. This is a scoped set of fields, not a blanket "database encrypted at rest" claim. |
| Never returned to the client | Existing monitor request credentials (custom headers, query parameters, body, and auth fields) are omitted from monitor read responses and never re-rendered into the edit form as plaintext. |
Full detail: Security → Encryption.
Application security
| CSRF | Session-bound tokens on state-changing requests across the dashboard and admin panel. |
| SSRF | Outbound requests from user-supplied monitor/webhook targets block private, loopback, link-local, and cloud-metadata IP ranges, with redirect re-validation. |
| Rate limiting | Per-IP limits on authentication, the public API, and public status-page rendering, with escalating temporary blocks. |
| Uploads | Avatar/logo SVG uploads are validated and sanitized before storage. |
Full detail: Security → Application Security.
Privacy & data protection
| Analytics | Self-hosted, cookie-free Plausible Community Edition — no third-party ad/analytics trackers. |
| Cookies | Essential first-party cookies only (session + CSRF). |
| IP addresses | Hashed with SHA-256 before storage; raw IPs are not stored. |
| Sale of personal data | We do not sell personal data. (Policy commitment — see Privacy Policy.) |
| Your rights | GDPR/CCPA access, correction, portability, and deletion rights — see Privacy Policy for the full list and how to exercise them. |
Full detail: Privacy Policy · Privacy-Friendly Overview.
Retention & deletion
Closing your account immediately flags it as closed, and your data is scheduled for removal from active systems under our retention policy — targeting 60 days for account data and 90 days for hashed access logs.
For the full policy, or to confirm your data has been removed, see our Privacy Policy or contact privacy@statuspage.me.
Backups & recovery
Automated daily database backups run with weekly/monthly rotation, alongside timestamped application backups on every deployment. See Security → Backups & Recovery for our documented restore procedure.
Subprocessors
We maintain a public, dated list of the service providers and subprocessors we use, what they do, and where they're located — including hosting, our global monitoring network, and optional integrations you configure yourself.
View all subprocessorsIncident response
We monitor our own infrastructure with the same multi-region checks we offer customers, and publish incidents on our own public status page. We don't currently offer a formal incident-response SLA or a 24/7 SOC — see status.statuspage.me for live status and history.
Vulnerability reporting
Found a security issue? Email security@statuspage.me with details and reproduction steps. We don't run a paid bug-bounty program, but verified reporters can be credited in our public acknowledgements list.
See Security → Report a vulnerability and our Responsible Disclosure policy.
Compliance & transparency
We follow SOC 2-aligned practices but have not completed a formal SOC 2, ISO 27001, or PCI DSS audit, and don't claim one. We'd rather tell you plainly what we have and haven't done than imply a certification we don't hold.
Full disclosure list: Security → What we don't have (yet).