ErrorDetector ←  Back to site

Trust

Security Overview

Last updated September 9, 2026

On this page

  1. 01 How your data is protected
  2. 02 Encryption
  3. 03 Account security
  4. 04 Application controls
  5. 05 Operations
  6. 06 Your data
  7. 07 Reporting a vulnerability
01

How your data is protected

ErrorDetector is a small service run by [YOUR LEGAL NAME / ADDRESS]. This page lists the controls that are actually in place, in the order they matter to a customer. Nothing here is aspirational; each line names a mechanism in the product.

02

Encryption

  • In transit: the site, the API, alert deliveries and the checks we send are made over TLS; the site sends HSTS.
  • At rest: integration secrets (webhook URLs, chat tokens, API credentials on monitors, webhook signing secrets) are encrypted with a key that lives only in the server environment. Passwords are salted hashes; API keys are stored as SHA-256 hashes and compared in constant time.
  • Card data never reaches our servers: checkout and card updates happen on Stripe.
03

Account security

  • Minimum password length of 10 characters; disposable e-mail domains are refused at signup.
  • Optional two-factor authentication (TOTP) with eight single-use backup codes; disabling it needs the password and a code.
  • Sessions carry an epoch that changes on password reset, e-mail change and 2FA changes, and "Sign out everywhere" ends every session at once. Sessions expire after 30 days at most.
  • Team roles (admin, editor, viewer) are enforced on every state-changing route; viewers cannot change anything.
04

Application controls

  • Content-Security-Policy with per-request nonces; no inline event handlers; vendor scripts are self-hosted with integrity hashes.
  • CSRF tokens on every form and rate limits on login, signup, password reset, the API, test sends and the contact form.
  • Every URL you give us is checked against private, loopback and cloud-metadata address ranges before a request is made, and again at each redirect hop, from a client that pins the validated address.
  • Stripe webhooks are verified with Stripe's signature and every event is applied at most once.
  • Outgoing generic webhooks are signed (HMAC-SHA256 in X-ErrorDetector-Signature) so your endpoint can verify them.
  • Custom status-page domains are served only after a DNS TXT ownership check.
05

Operations

  • Hosting and data storage in the European Union; one monitoring origin in the European Union.
  • Daily consistent database snapshots, kept for 14 days, with off-site copies where configured.
  • An audit log records sign-ins, changes to monitors, alerts, team and billing, and data exports.
  • Dependencies are scanned for known vulnerabilities before every deploy; a deploy that fails the scan does not ship.
06

Your data

  • Download everything as JSON from Settings, any time.
  • Delete your account from Settings; it cancels the subscription first and removes your data.
  • Sub-processors and retention periods are listed in the Privacy Policy; a DPA is available on request.
07

Reporting a vulnerability

If you find a security problem, tell us before anyone else: use the contact form with the subject "Security" or email support@errordetector.eu. We confirm receipt within two working days, keep you informed while we fix it, and do not take action against good-faith research that stays within your own accounts and data.

↑  Back to top

Questions? Email support@errordetector.eu

Privacy Terms Security Contact Home