More

Data, retention & security

What SutramX stores, how long results and logs are kept, how credentials are protected, where it is hosted, checker IPs, and exporting or deleting data.

This page explains what SutramX stores about your account and monitors, how long it's kept, and how it's protected. It also covers how to export or delete your data. For the legal versions, see the Privacy Policy and the Security page.

What data SutramX stores#

TypeExamples
Account dataName, email address, hashed password, workspace and team membership, time zone, notification preferences, two-factor settings.
Billing dataPlan, billing country, subscription status, invoice history and the billing details you enter. Card and UPI details stay with the payment provider. SutramX never stores full card numbers.
Monitor configurationTarget URLs, hosts and ports, request settings, custom headers and credentials (encrypted), check intervals, and alert destinations such as email addresses, chat webhooks and integration keys.
Monitoring resultsCheck outcomes, status codes, response timings, response snippets, certificate details and incident history.
Status page subscribersEmail addresses visitors submit to a status page, kept only after they confirm.
LogsSign-in events and sessions, IP addresses, user agents, API usage, audit events and alert delivery records.
CommunicationsMessages you send to support.

For your own account data, SutramX is the data controller. For data you put into the service (for example, alert recipients' email addresses or content in monitored responses), SutramX acts as a processor on your behalf. SutramX doesn't sell personal data and doesn't use monitoring data for advertising.

Data retention#

Most retention periods are the same on every plan. The exception is aggregated daily uptime history, whose window depends on your plan. Upgrading lengthens the window from then on (history that was already removed doesn't come back). If a paid plan ends or you downgrade, the longer window still applies for 30 days; after that, history older than your new plan's window is removed.

DataHow long it's kept
Raw check results (each individual check from each region)90 days
Aggregated daily uptime historyDepends on your plan: 90 days on Free, 12 months on Starter, 24 months on Growth and Pro. After a downgrade or a paid plan ends, the longer window is kept for 30 days, then older history is removed
IncidentsAs long as your account is active
Incident event timelines (the step-by-step events within an incident)About 13 months after the incident is resolved
Alert delivery logs90 days
Data exports you requestDeleted 7 days after they're created
Account dataAs long as your account is active
Billing recordsLonger where tax or accounting law requires it

Because daily rollups are kept, uptime history and reports for older periods stay available after the raw checks are removed, for as long as your plan keeps uptime history. Downgrading or cancelling a plan doesn't delete monitors, settings or incidents: anything over your new limits is paused, not removed. Only daily uptime history older than the new plan's window is removed, 30 days after the change (see Upgrade, downgrade & cancel).

Where your data is stored#

WhatWhere
Application, API, database and monitoring workers (primary hosting and processing)Frankfurt, Germany (EU), on Amazon Web Services (eu-central-1)
Encrypted database backupsUSA, on Amazon Web Services (us-east-1, N. Virginia)
Operational logs (kept 14 days)USA, on Amazon Web Services (us-east-1, N. Virginia)
Data exports you requestStored temporarily with Cloudflare R2, deleted after 7 days. Download links expire after 1 hour.
ChecksRun from SutramX's checker locations, listed below

How your data is protected#

These are the measures described on the Security page and used in the product:

  • Encryption in transit: traffic between your browser or API client and SutramX uses TLS 1.2 or newer.
  • Secrets encrypted at rest: credentials you attach to monitors (request header values, tokens, API keys, request bodies and credential query parameters such as ?api_key=), browser check secrets, integration secrets and two-factor seeds are encrypted with AES-256-GCM before they're stored. Monitor credentials are decrypted only to run a check and to show them to the people who can edit the monitor; viewers and read-only API keys see them masked. Integration secrets are decrypted only to deliver an alert.
  • Passwords are stored as salted hashes, never in plain text.
  • SutramX API keys are stored as hashes. After you create a key, only its prefix is shown again.
  • Two-factor authentication: every user can turn on two-factor authentication with an authenticator app (TOTP) or email codes. See Sign-in & security.
  • SSRF protection: monitor targets are checked before each run. Requests to loopback addresses, cloud metadata endpoints and private network ranges are blocked. The resolved address is checked again at connection time, so DNS tricks can't send a check into an internal network.
  • Malicious-site screening: target URLs can be screened against Google Web Risk for known malicious sites. Google receives the scheme, host and path only, never the query string or credentials.
  • Data exports leave out secrets: passwords, tokens, API keys, webhook URLs and other credentials are never included in an export. Header values are masked.

Reporting a vulnerability#

Please report security issues privately to security@sutramx.com, with enough detail to reproduce them. Allow a reasonable time for a fix before you disclose anything publicly. There's no paid bug bounty.

Probe IP addresses and user agent#

Every check request carries the SutramX-Monitor user agent. The IP addresses of SutramX's checkers are published at:

  • https://sutramx.com/bot: the user agent, the IP addresses by node, and allowlisting steps for Cloudflare, Vercel, AWS WAF, nginx and Apache.
  • https://sutramx.com/bot/ips.txt: a plain-text list for scripts.

IP addresses can change when locations are added or moved, so re-check the list or fetch ips.txt automatically. If your firewall supports it, allowlisting by the SutramX-Monitor user agent keeps working when an IP address changes. The current regions are:

RegionCodeCountryContinent
FRA1 (Frankfurt, Germany)fra1GermanyEurope
AZ (Arizona, USA)usa-az-probe——
IN (Mumbai)in-mumbaiIndiaAsia

See Troubleshooting if a firewall or bot protection is blocking checks.

Sub-processors#

SutramX shares data with these providers only as needed to run the service:

ProviderPurposeLocation
Amazon Web Services (AWS)Hosting of the application, API, database, monitoring workers, the website and the Frankfurt checker; outgoing email (Amazon SES) for transactional, alert and newsletter emails, with its delivery reports; encrypted database backups; operational logs (kept 14 days)Germany (eu-central-1, Frankfurt); backups and operational logs in the USA (us-east-1, N. Virginia)
HostingerHosting of the Arizona and Mumbai checkers; outgoing email (SMTP) for transactional and alert emailsCheckers in the USA (Arizona) and India (Mumbai); email per provider
CloudflareDNS, network security and content delivery for our websites and APIGlobal edge network
Cloudflare R2Temporary storage of data exports you requestGlobal (Cloudflare R2)
Dodo PaymentsUSD payments (merchant of record)Per provider
RazorpayINR payments, including UPI AutopayIndia
Google Web RiskScreening monitor target URLs for known malicious sites; receives only the scheme, host and path, never the query string or credentialsUnited States
Globalping (jsDelivr)Last-mile checks on plans that include them. Receives only the host name, port and path, never headers, credentials or bodiesGlobal (probe network)
Google Analytics (Google)Visitor analytics for the sutramx.com website, only if you accept analytics cookiesUnited States
PostHogProduct analytics for the website and the dashboard, only if you accept analytics cookies. Everything you type is hidden in session recordingsUnited States
TwilioSMS and voice call alerts, and WhatsApp alerts sent through TwilioUnited States
Meta (WhatsApp Business Platform)WhatsApp alerts sent through the WhatsApp Cloud APIGlobal
TelegramTelegram alerts sent through the SutramX Telegram botGlobal
OpenAI (OpenAI API)Drafting AI incident summaries, postmortems and status page updates from redacted incident facts (no alert recipients, names, request headers or bodies, or full monitored URLs): on request, and automatically for incidents open more than 5 minutes on plans that include AI incident summaries. OpenAI doesn't use API data to train its models.United States
SentryError diagnostics for the API, scrubbed of credentials and request bodiesUnited States
Expo (Expo push notification service)Delivering push alerts to the SutramX mobile appUnited States
Browser push services (Google, Mozilla, Apple, Microsoft)Delivering encrypted browser push alerts you turn onPer browser vendor

The authoritative, dated list is at sutramx.com/subprocessors.

When you connect your own integrations (such as Slack, Discord, Microsoft Teams, PagerDuty or Opsgenie), alert content is sent to those services on your instruction, under their terms. Because data is hosted in Germany, backed up and logged in the USA and processed by the providers and checker locations above, it may be processed outside your country of residence.

Exporting your data#

The workspace owner can download a full JSON copy of a workspace.

  1. Go to Account → Settings (the Account settings page) and scroll to Danger zone.
  2. Under Export data, select Export data.
  3. When the export is ready, the download starts automatically.

The export includes your monitors, incidents, status pages and settings. It also includes up to the 50,000 most recent raw check results from the retention window. Daily uptime rollups cover your older history. Credentials and secrets are left out.

Deleting your data#

The workspace owner can delete a workspace from Account settings → Danger zone. If you don't own any other workspace, your SutramX account is deleted too.

  1. Select Delete workspace… (or Delete account…).
  2. Confirm it's you with your password. If your account has no password, enter a code from your authenticator app or an emailed code, and type DELETE.
  3. Confirm the deletion.

What happens next:

  • Monitoring stops, and you're signed out everywhere.
  • The workspace and its monitors, incidents, status pages, API keys and integrations are scheduled for deletion. If this deletes your account, your login, profile and connected sign-ins go too.
  • Nothing is erased for 30 days. During that time, sign in and select Cancel deletion to get everything back.
  • After 30 days, the data is permanently purged and any paid subscription is cancelled. Records SutramX must keep by law (such as billing records) are kept.

Deleting some of your data#

You can delete parts of your SutramX data without deleting your account. These deletions take effect immediately and can't be undone. Deleted data can remain in encrypted database backups until they expire, within about 40 days.

DataHow to delete itWhat is deleted
Incident notesIn the SutramX Monitoring app, open the incident and select Delete under the note. In the dashboard, open the incident and delete the noteThe note text and who wrote it. Notes shown on a status page disappear from it
A signed-in phone or browserIn the app, open Settings → Signed-in devices and select Sign out (or Sign out all other devices). In the dashboard, use Account settings → SessionsThe session and, for a phone, its push notification token, so the phone stops getting alerts
MonitorsIn the dashboard, open the monitor and delete itThe monitor with its check results, incidents and notes
Status pages, alert channels and API keysIn the dashboard, delete them from their pagesThe item and its settings

To have any other personal data deleted, email support@sutramx.com from your account's email address and say what to delete. We reply within 30 days. Records SutramX must keep by law (such as billing records) are kept.

Your privacy rights#

Depending on where you live, including under the EU/UK GDPR and India's DPDP Act, 2023, you may have the right to access, correct, delete or export your personal data. You may also have the right to object to or restrict processing. You can export and delete data yourself as described above. For anything else, email support@sutramx.com. If SutramX processes your data on behalf of one of its customers (for example, you're an alert recipient), contact that customer first.

Last updated . Something unclear or missing on this page? Tell us at support@sutramx.com.