Security
Reporting a vulnerability
Join our support server and message a staff member privately, or open a private ticket, with the steps to reproduce it. Please don't post details in a public channel. We reply within three working days and keep you updated until it is fixed. Please give us a reasonable time to fix it before you publish anything, and do not access other people's data, run denial-of-service tests, or send spam while testing.
Our security.txt points to the same place.
Your account
- You sign in with Discord or GitHub, so we never have a password to lose.
- You can add two-factor authentication with a code from your phone.
- You can see everywhere you're signed in, and sign out of any of them.
- Keys, tokens, and saved headers are stored in a form nobody can read back.
The checks we run
- We never check private or internal network addresses, so Statusbeat can't be used to reach anything that isn't public.
- We only read a small part of each page, and we don't keep it.
- Our checks always say who they are. See our checks.
Everything else
- You can only ever see and change projects you belong to.
- HTTPS everywhere, plus modern browser protections against common attacks.
- Every change to a project is recorded in its audit log.