SEISMO

Security

How we protect your data

Seismograph is built using managed AWS services, with Cloudflare supporting edge delivery. Here is what we do to keep your data safe.

Data Security

  • All data encrypted in transit (TLS 1.2+)
  • Application data stored in AWS is encrypted at rest using AWS encryption services, including AWS KMS
  • Data isolated per client
  • Automatic data expiry on probe results and alerts

Access Control

  • Client dashboards protected by passwordless email authentication
  • Client-level authorization controls isolate access to each customer's data
  • Endpoint authentication credentials and Slack OAuth tokens securely stored and encrypted in AWS Secrets Manager
  • Credential access limited to application components that require it for customer-configured monitoring or integrations

Infrastructure

  • Serverless architecture on AWS
  • No persistent servers
  • Automated scaling, no manual intervention

Webhook Security

  • GitHub webhook payloads verified via signature
  • No webhook secrets stored in code

Responsible Disclosure

If you discover a security vulnerability, please report it to us privately.

Email hello@seismograph.ai with a description of the issue. We will acknowledge your report promptly and work with you to investigate it.