Security at a11ops

Security is fundamental to our mission. We implement comprehensive security measures to protect your critical alert infrastructure and ensure reliable delivery when it matters most.

Security Overview

SOC 2 Type II

Independently audited for security, availability, and confidentiality

ISO 27001

Certified information security management system

GDPR Compliant

Full compliance with EU data protection regulations

HIPAA Ready

Available BAA for healthcare customers

Infrastructure Security

Cloud Infrastructure

  • Hosted on AWS with enterprise-grade security
  • Multi-region deployment with automatic failover
  • Network isolation using VPCs and security groups
  • DDoS protection through AWS Shield
  • Regular security patches and updates

Data Centers

  • SOC 2 certified facilities
  • 24/7 physical security monitoring
  • Biometric access controls
  • Redundant power and cooling systems
  • Geographic distribution for disaster recovery

Data Security

Encryption

  • In Transit: TLS 1.3 for all communications
  • At Rest: AES-256 encryption for stored data
  • Key Management: AWS KMS with automatic key rotation
  • Certificate Pinning: Available for mobile SDKs

Data Isolation

  • Logical separation of customer data
  • Row-level security in databases
  • Separate encryption keys per workspace
  • No shared resources between customers

Data Retention & Deletion

  • Configurable retention policies per plan
  • Automated data expiration
  • Secure deletion with crypto-shredding
  • 30-day grace period for account recovery
  • Complete removal from all backups within 90 days

Application Security

Authentication & Access Control

  • Multi-factor authentication (MFA) support
  • SSO integration (SAML 2.0, OAuth 2.0)
  • API key rotation and scoping
  • Role-based access control (RBAC)
  • Session management with automatic timeout

Security Testing

  • Annual third-party penetration testing
  • Continuous vulnerability scanning
  • Static and dynamic code analysis
  • Dependency scanning for known vulnerabilities
  • Bug bounty program for responsible disclosure

Secure Development

  • Security training for all developers
  • Code reviews with security focus
  • OWASP Top 10 compliance
  • Secure coding guidelines
  • Automated security checks in CI/CD

Operational Security

Access Management

  • Principle of least privilege for all access
  • Regular access reviews and audits
  • Background checks for all employees
  • Security awareness training
  • Immediate access revocation upon termination

Monitoring & Logging

  • 24/7 security monitoring
  • Centralized log aggregation
  • Real-time threat detection
  • Automated incident response
  • Audit logs retained for 1 year minimum

Compliance & Certifications

Current Certifications

  • SOC 2 Type II
  • ISO 27001:2013
  • ISO 27017:2015 (Cloud Security)
  • ISO 27018:2019 (Privacy)

Regulatory Compliance

  • GDPR (EU)
  • CCPA (California)
  • PIPEDA (Canada)
  • HIPAA ready (with BAA)

Compliance reports and certifications are available upon request for Enterprise customers.

Incident Response

Security Incident Management

We maintain a comprehensive incident response plan that includes:

  • 24/7 incident response team
  • Defined escalation procedures
  • Customer notification within 72 hours
  • Post-incident analysis and reporting
  • Regular drills and plan updates

Report security concerns to [email protected]

Data Privacy & Residency

Data Location

  • Choose your data residency region
  • Data never leaves your selected region
  • Available regions: US, EU, UK, Canada, Australia
  • Metadata may be replicated globally for performance

Privacy Controls

  • Data minimization principles
  • Purpose limitation for data use
  • User consent management
  • Right to erasure (GDPR)
  • Data portability options

Security Best Practices for Customers

Help us keep your account secure by following these best practices:

  • Enable multi-factor authentication (MFA)
  • Use strong, unique passwords
  • Rotate API keys regularly
  • Limit API key scopes to necessary permissions
  • Monitor your account for unusual activity
  • Keep your contact information up to date
  • Train your team on security awareness

Security Resources

Have Security Questions?

Our security team is here to help with any concerns or questions.

Contact Security Team