Security at UpMonix

How we protect your data and how to report security vulnerabilities responsibly.

Encryption in transit

Public website and dashboard traffic is served over HTTPS. Outbound monitoring checks use TLS where supported by the target endpoint.

Encryption at rest

Database credentials and sensitive notification channel configuration are stored in environment configuration. Channel secrets in the database are encrypted at the application level where the communication platform is enabled.

Password security

Account passwords are hashed using PHP password_hash() with the default algorithm (bcrypt/argon2 as configured by the server). Plain-text passwords are not stored.

Account access controls

Customer accounts support role-based access (owner, admin, viewer). Optional two-factor authentication is available for login. Platform administration is restricted to super-admin users.

Production access

Production server access is limited to authorised operators. Customer data is isolated by customer_id on all tenant queries.

Audit logging

Significant account and configuration changes are recorded in the platform audit log, viewable by administrators.

Backups

Database backups are the responsibility of the hosting operator. Configure and verify your backup policy for production deployments.

Data location

Configure and verify your production data residency. Do not assume EU-only processing unless confirmed for your deployment.

Data retention

Check and incident data retention follows your subscription plan limits. See pricing for details.

Incident response

Security issues affecting the platform are handled through our internal incident process. Report vulnerabilities via our responsible disclosure programme.

Vulnerability reporting

Email security@upmonix.com or read our responsible disclosure policy.

Security contact

security@upmonix.com

UpMonix Business continuity monitoring — know before your customers do.