Security & trust

Built for teams
that can’t guess.

Security is ongoing work. Here’s how Statuslab approaches transport, access, and data handling for monitoring and status pages — and what expands as enterprise features ship.

Transport and access

Dashboard and API traffic should run over HTTPS in production. Authentication protects operator access to configuration, incidents, and subscriber data.

Data handling

Monitoring data and status page configuration are stored for service delivery and troubleshooting. Retention and regional placement follow your deployment and contract.

Operational security

Use strong passwords, limit project access, and review audit trails as those controls become available on your plan. Least privilege stays the default habit.

Responsible disclosure

Found a vulnerability? Contact us through the disclosure process your account team shares during onboarding. A dedicated public address ships before broad production launch.

Baseline

Practical defaults,
growing with you.

We publish what we practice today — not a wall of badges we haven’t earned. Enterprise procurement, DPAs, and deeper controls are available as you need them.

More in the FAQ and on pricing.

  • HTTPS for production dashboard and API traffic
  • Authenticated access to configuration and incident data
  • DPAs and custom retention available for enterprise needs
  • Expanding controls as certifications and SSO ship

Trust the page
your customers see.

Start monitoring with the same access controls and transport defaults your team expects — free to begin.