Security

Security at Site Monitor

Last updated: August 28, 2026

Site Monitor is a small service with a small attack surface, and we would rather tell you plainly what we do than dress it up. Most of our infrastructure controls are inherited from providers who are audited far more thoroughly than we could be on our own; the controls we own ourselves are listed below with no claims we cannot back up.

Inherited infrastructure controls

  • Hosting — Vercel. The application and its scheduled checks run on Vercel, which holds SOC 2 Type 2 and ISO 27001 certifications.
  • Database — Upstash. Account data, site configuration and check history are stored in Upstash Redis. All connections use TLS and data is encrypted at rest.
  • Email — Resend. Alerts and reports that are not sent through your own SMTP go through Resend, which holds a SOC 2 Type II report.
  • Payments — Stripe. Card details are entered on Stripe-hosted pages and never touch our servers. Stripe is a PCI DSS Level 1 service provider.

We do not hold a SOC 2 report or ISO certification of our own. If your procurement process requires one from the vendor directly, we are not the right fit yet, and we would rather say so up front.

Encryption

  • All traffic between your browser and the Service, and between the Service and its providers, is encrypted in transit with TLS (TLS 1.3 where the client supports it).
  • Data is encrypted at rest by our hosting and database providers.
  • Credentials you give us for your own SMTP server are stored in the database and used only to send your alerts and reports.

Account security

  • Passwords are hashed with bcrypt and never stored or logged in plain text.
  • Two-factor authentication (TOTP, compatible with any authenticator app) is available to every user, with one-time backup codes.
  • Breached-password screening: new passwords are checked against known breach lists using a privacy-preserving lookup, and rejected if they appear.
  • Rate limiting on sign-in, sign-up, password reset and two-factor endpoints slows down credential stuffing and brute force.
  • Sessions use a signed, HTTP-only cookie. Signing out invalidates it.
  • Tenant isolation: every site, result and setting belongs to an account, and every request is checked against the signed-in user's account.

What we collect, and what we don't

  • We fetch only the public pages you ask us to monitor, the way a browser would, and keep the status code, response time and any error. We do not store page content.
  • We never log in to the sites we monitor, never submit forms, and never see booking, patient or customer records. No protected health information (PHI) passes through the Service, so no Business Associate Agreement is needed.
  • Check history expires automatically after your plan's retention period, or sooner if you choose.
  • Details of what we store and for how long are in the Privacy Policy; processor terms are in the DPA.

Availability, honestly

Checks run from a single cloud region on a schedule, with a second confirmation before an outage alert is sent. We do not run a global probe network and we do not offer a contractual uptime SLA today. Alerts are retried automatically if a delivery provider fails, and the app shows you when an alert could not be delivered. We publish incidents that affect customers by email.

Responsible disclosure

If you find a security problem, please tell us at security@concepcion.work. We read every report, aim to acknowledge within two business days, and will keep you informed while we fix it. Our security.txt is at https://uptime.concepcion.work/.well-known/security.txt.

We ask that you:

  • give us a reasonable time to fix the issue before making it public;
  • test only against accounts you own, and avoid accessing, changing or deleting other people's data;
  • do not run denial-of-service, spam or social-engineering attacks against the Service, our providers, or the websites our customers monitor.

Research conducted in line with these rules is welcome and we will not pursue legal action over it. We do not currently run a paid bug bounty program, but we will credit you here if you would like.

Contact

Security: security@concepcion.work · Everything else: support@concepcion.work · Concepcion.Work