Security
a11ops is built with security at its core. Learn about our security model, compliance certifications, and best practices for keeping your alert data safe.
Security Overview
End-to-End Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Your alerts are always protected.
Compliance
SOC 2 Type II certified, GDPR compliant, and HIPAA ready. Regular third-party security audits ensure compliance.
Access Control
Role-based access control (RBAC) with granular permissions. Support for SSO and multi-factor authentication.
Audit Logging
Comprehensive audit logs for all actions. Track who accessed what data and when for complete accountability.
API Key Management
API Key Best Practices
- Never commit keys to version control
Use environment variables or secret management systems
- Use different keys for different environments
Separate development, staging, and production keys
- Rotate keys regularly
Implement a key rotation policy (recommended: every 90 days)
- Limit key permissions
Use the principle of least privilege
Secure Key Storage
✓ Recommended
- Environment variables
- AWS Secrets Manager / Parameter Store
- HashiCorp Vault
- Kubernetes Secrets
- Azure Key Vault
✗ Never Use
- Hardcoded in source code
- Configuration files in repository
- Client-side code
- Public documentation
Key Rotation Process
- Generate a new API key in your workspace settings
- Update your applications with the new key
- Verify all services are using the new key
- Revoke the old key after confirming no usage
- Document the rotation in your security log
Data Protection
Encryption Standards
Data Retention
Alert data is retained based on your subscription plan:
- Free plan: 1 day
- Starter plan: 7 days
- Team plan: 30 days
- Enterprise: Customizable (up to 365 days)
- Data is permanently deleted after retention period
- Export your data anytime via API or dashboard
Data Isolation
Your data is completely isolated from other customers:
- Workspace-level isolation at the database level
- Separate encryption keys per workspace
- Network isolation between customers
- No shared resources or data commingling
Infrastructure Security
Network Security
- WAF protection against common attacks
- DDoS mitigation at all layers
- Private network isolation
- Regular penetration testing
Infrastructure
- Hosted on AWS with SOC compliance
- Multi-region deployment
- Automated security patching
- Container scanning for vulnerabilities
Monitoring
- 24/7 security monitoring
- Anomaly detection systems
- Real-time threat intelligence
- Automated incident response
Access Control
- Zero-trust architecture
- Principle of least privilege
- Multi-factor authentication required
- Regular access reviews
Compliance & Certifications
Current Certifications
SOC 2 Type II
Annual audit of security controls
GDPR Compliant
Full compliance with EU data protection
CCPA Compliant
California privacy law compliance
ISO 27001 (In Progress)
Information security management
Data Privacy Rights
We respect your data privacy rights:
- Right to access your data
- Right to rectification
- Right to erasure (right to be forgotten)
- Right to data portability
- Right to restrict processing
To exercise these rights, contact [email protected]
Security Features
Authentication Options
Single Sign-On (SSO)
Support for SAML 2.0 and OpenID Connect
Multi-Factor Authentication
TOTP-based 2FA for all accounts
IP Allowlisting
Restrict access to specific IP ranges
Audit Capabilities
Track all activities in your workspace:
- User login/logout events
- API key creation/deletion
- Workspace configuration changes
- Team member modifications
- Alert acknowledgments and resolutions
- Export audit logs via API
Security Incident Response
In the unlikely event of a security incident:
- Immediate Response
Incident response team activated within 15 minutes
- Customer Notification
Affected customers notified within 72 hours
- Remediation
Swift action to contain and resolve the issue
- Post-Incident Report
Detailed report with timeline and improvements
Security Contact: [email protected]
Report Vulnerabilities: [email protected] (PGP key available)
Shared Responsibility Model
a11ops Responsibilities
- Infrastructure security
- Platform security updates
- Data encryption
- Network security
- Physical security
- Compliance certifications
Your Responsibilities
- API key security
- User access management
- Strong password policies
- Secure integration configurations
- Alert data classification
- Compliance with your policies
Security Resources
Download our security documentation and compliance reports.