Security

a11ops is built with security at its core. Learn about our security model, compliance certifications, and best practices for keeping your alert data safe.

Security Overview

End-to-End Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Your alerts are always protected.

Compliance

SOC 2 Type II certified, GDPR compliant, and HIPAA ready. Regular third-party security audits ensure compliance.

Access Control

Role-based access control (RBAC) with granular permissions. Support for SSO and multi-factor authentication.

Audit Logging

Comprehensive audit logs for all actions. Track who accessed what data and when for complete accountability.

API Key Management

API Key Best Practices

  • Never commit keys to version control

    Use environment variables or secret management systems

  • Use different keys for different environments

    Separate development, staging, and production keys

  • Rotate keys regularly

    Implement a key rotation policy (recommended: every 90 days)

  • Limit key permissions

    Use the principle of least privilege

Secure Key Storage

✓ Recommended

  • Environment variables
  • AWS Secrets Manager / Parameter Store
  • HashiCorp Vault
  • Kubernetes Secrets
  • Azure Key Vault

✗ Never Use

  • Hardcoded in source code
  • Configuration files in repository
  • Client-side code
  • Public documentation

Key Rotation Process

  1. Generate a new API key in your workspace settings
  2. Update your applications with the new key
  3. Verify all services are using the new key
  4. Revoke the old key after confirming no usage
  5. Document the rotation in your security log

Data Protection

Encryption Standards

In TransitTLS 1.3 (minimum TLS 1.2)
At RestAES-256-GCM encryption
Key ManagementAWS KMS with automatic rotation
BackupsEncrypted with separate keys

Data Retention

Alert data is retained based on your subscription plan:

  • Free plan: 1 day
  • Starter plan: 7 days
  • Team plan: 30 days
  • Enterprise: Customizable (up to 365 days)
  • Data is permanently deleted after retention period
  • Export your data anytime via API or dashboard

Data Isolation

Your data is completely isolated from other customers:

  • Workspace-level isolation at the database level
  • Separate encryption keys per workspace
  • Network isolation between customers
  • No shared resources or data commingling

Infrastructure Security

Network Security

  • WAF protection against common attacks
  • DDoS mitigation at all layers
  • Private network isolation
  • Regular penetration testing

Infrastructure

  • Hosted on AWS with SOC compliance
  • Multi-region deployment
  • Automated security patching
  • Container scanning for vulnerabilities

Monitoring

  • 24/7 security monitoring
  • Anomaly detection systems
  • Real-time threat intelligence
  • Automated incident response

Access Control

  • Zero-trust architecture
  • Principle of least privilege
  • Multi-factor authentication required
  • Regular access reviews

Compliance & Certifications

Current Certifications

SOC 2 Type II

Annual audit of security controls

GDPR Compliant

Full compliance with EU data protection

CCPA Compliant

California privacy law compliance

ISO 27001 (In Progress)

Information security management

Data Privacy Rights

We respect your data privacy rights:

  • Right to access your data
  • Right to rectification
  • Right to erasure (right to be forgotten)
  • Right to data portability
  • Right to restrict processing

To exercise these rights, contact [email protected]

Security Features

Authentication Options

Single Sign-On (SSO)

Support for SAML 2.0 and OpenID Connect

Multi-Factor Authentication

TOTP-based 2FA for all accounts

IP Allowlisting

Restrict access to specific IP ranges

Audit Capabilities

Track all activities in your workspace:

  • User login/logout events
  • API key creation/deletion
  • Workspace configuration changes
  • Team member modifications
  • Alert acknowledgments and resolutions
  • Export audit logs via API

Security Incident Response

In the unlikely event of a security incident:

  1. Immediate Response

    Incident response team activated within 15 minutes

  2. Customer Notification

    Affected customers notified within 72 hours

  3. Remediation

    Swift action to contain and resolve the issue

  4. Post-Incident Report

    Detailed report with timeline and improvements

Security Contact: [email protected]

Report Vulnerabilities: [email protected] (PGP key available)

Shared Responsibility Model

a11ops Responsibilities

  • Infrastructure security
  • Platform security updates
  • Data encryption
  • Network security
  • Physical security
  • Compliance certifications

Your Responsibilities

  • API key security
  • User access management
  • Strong password policies
  • Secure integration configurations
  • Alert data classification
  • Compliance with your policies

Security Resources

Download our security documentation and compliance reports.