Security
How we protect your data
Seismograph is built using managed AWS services, with Cloudflare supporting edge delivery. Here is what we do to keep your data safe.
Data Security
- ✓All data encrypted in transit (TLS 1.2+)
- ✓Application data stored in AWS is encrypted at rest using AWS encryption services, including AWS KMS
- ✓Data isolated per client
- ✓Automatic data expiry on probe results and alerts
Access Control
- ✓Client dashboards protected by passwordless email authentication
- ✓Client-level authorization controls isolate access to each customer's data
- ✓Endpoint authentication credentials and Slack OAuth tokens securely stored and encrypted in AWS Secrets Manager
- ✓Credential access limited to application components that require it for customer-configured monitoring or integrations
Infrastructure
- ✓Serverless architecture on AWS
- ✓No persistent servers
- ✓Automated scaling, no manual intervention
Webhook Security
- ✓GitHub webhook payloads verified via signature
- ✓No webhook secrets stored in code
Responsible Disclosure
If you discover a security vulnerability, please report it to us privately.
Email hello@seismograph.ai with a description of the issue. We will acknowledge your report promptly and work with you to investigate it.