Data, retention & security
What SutramX stores, how long results and logs are kept, how credentials are protected, where it is hosted, checker IPs, and exporting or deleting data.
This page explains what SutramX stores about your account and monitors, how long it's kept, and how it's protected. It also covers how to export or delete your data. For the legal versions, see the Privacy Policy and the Security page.
What data SutramX stores#
| Type | Examples |
|---|---|
| Account data | Name, email address, hashed password, workspace and team membership, time zone, notification preferences, two-factor settings. |
| Billing data | Plan, billing country, subscription status, invoice history and the billing details you enter. Card and UPI details stay with the payment provider. SutramX never stores full card numbers. |
| Monitor configuration | Target URLs, hosts and ports, request settings, custom headers and credentials (encrypted), check intervals, and alert destinations such as email addresses, chat webhooks and integration keys. |
| Monitoring results | Check outcomes, status codes, response timings, response snippets, certificate details and incident history. |
| Status page subscribers | Email addresses visitors submit to a status page, kept only after they confirm. |
| Logs | Sign-in events and sessions, IP addresses, user agents, API usage, audit events and alert delivery records. |
| Communications | Messages you send to support. |
For your own account data, SutramX is the data controller. For data you put into the service (for example, alert recipients' email addresses or content in monitored responses), SutramX acts as a processor on your behalf. SutramX doesn't sell personal data and doesn't use monitoring data for advertising.
Data retention#
Most retention periods are the same on every plan. The exception is aggregated daily uptime history, whose window depends on your plan. Upgrading lengthens the window from then on (history that was already removed doesn't come back). If a paid plan ends or you downgrade, the longer window still applies for 30 days; after that, history older than your new plan's window is removed.
| Data | How long it's kept |
|---|---|
| Raw check results (each individual check from each region) | 90 days |
| Aggregated daily uptime history | Depends on your plan: 90 days on Free, 12 months on Starter, 24 months on Growth and Pro. After a downgrade or a paid plan ends, the longer window is kept for 30 days, then older history is removed |
| Incidents | As long as your account is active |
| Incident event timelines (the step-by-step events within an incident) | About 13 months after the incident is resolved |
| Alert delivery logs | 90 days |
| Data exports you request | Deleted 7 days after they're created |
| Account data | As long as your account is active |
| Billing records | Longer where tax or accounting law requires it |
Because daily rollups are kept, uptime history and reports for older periods stay available after the raw checks are removed, for as long as your plan keeps uptime history. Downgrading or cancelling a plan doesn't delete monitors, settings or incidents: anything over your new limits is paused, not removed. Only daily uptime history older than the new plan's window is removed, 30 days after the change (see Upgrade, downgrade & cancel).
Where your data is stored#
| What | Where |
|---|---|
| Application, API, database and monitoring workers (primary hosting and processing) | Frankfurt, Germany (EU), on Amazon Web Services (eu-central-1) |
| Encrypted database backups | USA, on Amazon Web Services (us-east-1, N. Virginia) |
| Operational logs (kept 14 days) | USA, on Amazon Web Services (us-east-1, N. Virginia) |
| Data exports you request | Stored temporarily with Cloudflare R2, deleted after 7 days. Download links expire after 1 hour. |
| Checks | Run from SutramX's checker locations, listed below |
How your data is protected#
These are the measures described on the Security page and used in the product:
- Encryption in transit: traffic between your browser or API client and SutramX uses TLS 1.2 or newer.
- Secrets encrypted at rest: credentials you attach to monitors (request header values, tokens, API keys, request bodies and credential query parameters such as
?api_key=), browser check secrets, integration secrets and two-factor seeds are encrypted with AES-256-GCM before they're stored. Monitor credentials are decrypted only to run a check and to show them to the people who can edit the monitor; viewers and read-only API keys see them masked. Integration secrets are decrypted only to deliver an alert. - Passwords are stored as salted hashes, never in plain text.
- SutramX API keys are stored as hashes. After you create a key, only its prefix is shown again.
- Two-factor authentication: every user can turn on two-factor authentication with an authenticator app (TOTP) or email codes. See Sign-in & security.
- SSRF protection: monitor targets are checked before each run. Requests to loopback addresses, cloud metadata endpoints and private network ranges are blocked. The resolved address is checked again at connection time, so DNS tricks can't send a check into an internal network.
- Malicious-site screening: target URLs can be screened against Google Web Risk for known malicious sites. Google receives the scheme, host and path only, never the query string or credentials.
- Data exports leave out secrets: passwords, tokens, API keys, webhook URLs and other credentials are never included in an export. Header values are masked.
Reporting a vulnerability#
Please report security issues privately to security@sutramx.com, with enough detail to reproduce them. Allow a reasonable time for a fix before you disclose anything publicly. There's no paid bug bounty.
Probe IP addresses and user agent#
Every check request carries the SutramX-Monitor user agent. The IP addresses of SutramX's checkers are published at:
- https://sutramx.com/bot: the user agent, the IP addresses by node, and allowlisting steps for Cloudflare, Vercel, AWS WAF, nginx and Apache.
- https://sutramx.com/bot/ips.txt: a plain-text list for scripts.
IP addresses can change when locations are added or moved, so re-check the list or fetch ips.txt automatically. If your firewall supports it, allowlisting by the SutramX-Monitor user agent keeps working when an IP address changes. The current regions are:
| Region | Code | Country | Continent |
|---|---|---|---|
| FRA1 (Frankfurt, Germany) | fra1 | Germany | Europe |
| AZ (Arizona, USA) | usa-az-probe | — | — |
| IN (Mumbai) | in-mumbai | India | Asia |
See Troubleshooting if a firewall or bot protection is blocking checks.
Sub-processors#
SutramX shares data with these providers only as needed to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting of the application, API, database, monitoring workers, the website and the Frankfurt checker; outgoing email (Amazon SES) for transactional, alert and newsletter emails, with its delivery reports; encrypted database backups; operational logs (kept 14 days) | Germany (eu-central-1, Frankfurt); backups and operational logs in the USA (us-east-1, N. Virginia) |
| Hostinger | Hosting of the Arizona and Mumbai checkers; outgoing email (SMTP) for transactional and alert emails | Checkers in the USA (Arizona) and India (Mumbai); email per provider |
| Cloudflare | DNS, network security and content delivery for our websites and API | Global edge network |
| Cloudflare R2 | Temporary storage of data exports you request | Global (Cloudflare R2) |
| Dodo Payments | USD payments (merchant of record) | Per provider |
| Razorpay | INR payments, including UPI Autopay | India |
| Google Web Risk | Screening monitor target URLs for known malicious sites; receives only the scheme, host and path, never the query string or credentials | United States |
| Globalping (jsDelivr) | Last-mile checks on plans that include them. Receives only the host name, port and path, never headers, credentials or bodies | Global (probe network) |
| Google Analytics (Google) | Visitor analytics for the sutramx.com website, only if you accept analytics cookies | United States |
| PostHog | Product analytics for the website and the dashboard, only if you accept analytics cookies. Everything you type is hidden in session recordings | United States |
| Twilio | SMS and voice call alerts, and WhatsApp alerts sent through Twilio | United States |
| Meta (WhatsApp Business Platform) | WhatsApp alerts sent through the WhatsApp Cloud API | Global |
| Telegram | Telegram alerts sent through the SutramX Telegram bot | Global |
| OpenAI (OpenAI API) | Drafting AI incident summaries, postmortems and status page updates from redacted incident facts (no alert recipients, names, request headers or bodies, or full monitored URLs): on request, and automatically for incidents open more than 5 minutes on plans that include AI incident summaries. OpenAI doesn't use API data to train its models. | United States |
| Sentry | Error diagnostics for the API, scrubbed of credentials and request bodies | United States |
| Expo (Expo push notification service) | Delivering push alerts to the SutramX mobile app | United States |
| Browser push services (Google, Mozilla, Apple, Microsoft) | Delivering encrypted browser push alerts you turn on | Per browser vendor |
The authoritative, dated list is at sutramx.com/subprocessors.
When you connect your own integrations (such as Slack, Discord, Microsoft Teams, PagerDuty or Opsgenie), alert content is sent to those services on your instruction, under their terms. Because data is hosted in Germany, backed up and logged in the USA and processed by the providers and checker locations above, it may be processed outside your country of residence.
Exporting your data#
The workspace owner can download a full JSON copy of a workspace.
- Go to Account → Settings (the Account settings page) and scroll to Danger zone.
- Under Export data, select Export data.
- When the export is ready, the download starts automatically.
The export includes your monitors, incidents, status pages and settings. It also includes up to the 50,000 most recent raw check results from the retention window. Daily uptime rollups cover your older history. Credentials and secrets are left out.
Deleting your data#
The workspace owner can delete a workspace from Account settings → Danger zone. If you don't own any other workspace, your SutramX account is deleted too.
- Select Delete workspace… (or Delete account…).
- Confirm it's you with your password. If your account has no password, enter a code from your authenticator app or an emailed code, and type
DELETE. - Confirm the deletion.
What happens next:
- Monitoring stops, and you're signed out everywhere.
- The workspace and its monitors, incidents, status pages, API keys and integrations are scheduled for deletion. If this deletes your account, your login, profile and connected sign-ins go too.
- Nothing is erased for 30 days. During that time, sign in and select Cancel deletion to get everything back.
- After 30 days, the data is permanently purged and any paid subscription is cancelled. Records SutramX must keep by law (such as billing records) are kept.
Deleting some of your data#
You can delete parts of your SutramX data without deleting your account. These deletions take effect immediately and can't be undone. Deleted data can remain in encrypted database backups until they expire, within about 40 days.
| Data | How to delete it | What is deleted |
|---|---|---|
| Incident notes | In the SutramX Monitoring app, open the incident and select Delete under the note. In the dashboard, open the incident and delete the note | The note text and who wrote it. Notes shown on a status page disappear from it |
| A signed-in phone or browser | In the app, open Settings → Signed-in devices and select Sign out (or Sign out all other devices). In the dashboard, use Account settings → Sessions | The session and, for a phone, its push notification token, so the phone stops getting alerts |
| Monitors | In the dashboard, open the monitor and delete it | The monitor with its check results, incidents and notes |
| Status pages, alert channels and API keys | In the dashboard, delete them from their pages | The item and its settings |
To have any other personal data deleted, email support@sutramx.com from your account's email address and say what to delete. We reply within 30 days. Records SutramX must keep by law (such as billing records) are kept.
Your privacy rights#
Depending on where you live, including under the EU/UK GDPR and India's DPDP Act, 2023, you may have the right to access, correct, delete or export your personal data. You may also have the right to object to or restrict processing. You can export and delete data yourself as described above. For anything else, email support@sutramx.com. If SutramX processes your data on behalf of one of its customers (for example, you're an alert recipient), contact that customer first.
Related
Last updated . Something unclear or missing on this page? Tell us at support@sutramx.com.