How your data is protected
ErrorDetector is a small service run by [YOUR LEGAL NAME / ADDRESS]. This page lists the controls that are actually in place, in the order they matter to a customer. Nothing here is aspirational; each line names a mechanism in the product.
Encryption
- In transit: the site, the API, alert deliveries and the checks we send are made over TLS; the site sends HSTS.
- At rest: integration secrets (webhook URLs, chat tokens, API credentials on monitors, webhook signing secrets) are encrypted with a key that lives only in the server environment. Passwords are salted hashes; API keys are stored as SHA-256 hashes and compared in constant time.
- Card data never reaches our servers: checkout and card updates happen on Stripe.
Account security
- Minimum password length of 10 characters; disposable e-mail domains are refused at signup.
- Optional two-factor authentication (TOTP) with eight single-use backup codes; disabling it needs the password and a code.
- Sessions carry an epoch that changes on password reset, e-mail change and 2FA changes, and "Sign out everywhere" ends every session at once. Sessions expire after 30 days at most.
- Team roles (admin, editor, viewer) are enforced on every state-changing route; viewers cannot change anything.
Application controls
- Content-Security-Policy with per-request nonces; no inline event handlers; vendor scripts are self-hosted with integrity hashes.
- CSRF tokens on every form and rate limits on login, signup, password reset, the API, test sends and the contact form.
- Every URL you give us is checked against private, loopback and cloud-metadata address ranges before a request is made, and again at each redirect hop, from a client that pins the validated address.
- Stripe webhooks are verified with Stripe's signature and every event is applied at most once.
- Outgoing generic webhooks are signed (HMAC-SHA256 in
X-ErrorDetector-Signature) so your endpoint can verify them. - Custom status-page domains are served only after a DNS TXT ownership check.
Operations
- Hosting and data storage in the European Union; one monitoring origin in the European Union.
- Daily consistent database snapshots, kept for 14 days, with off-site copies where configured.
- An audit log records sign-ins, changes to monitors, alerts, team and billing, and data exports.
- Dependencies are scanned for known vulnerabilities before every deploy; a deploy that fails the scan does not ship.
Your data
- Download everything as JSON from Settings, any time.
- Delete your account from Settings; it cancels the subscription first and removes your data.
- Sub-processors and retention periods are listed in the Privacy Policy; a DPA is available on request.
Reporting a vulnerability
If you find a security problem, tell us before anyone else: use the contact form with the subject "Security" or email support@errordetector.eu. We confirm receipt within two working days, keep you informed while we fix it, and do not take action against good-faith research that stays within your own accounts and data.