Security at SutramX
Last Updated: October 3, 2026
SutramX monitors websites, APIs, and network services that our customers configure. That means we hold monitor configuration and, sometimes, credentials used to reach authenticated endpoints. This page describes the measures we currently have in place to protect them. It is a description of our practices, not a certification.
1. Encryption
- In transit: traffic between your browser or API client and SutramX is encrypted with TLS 1.2 or newer.
- Secrets at rest: credentials you attach to monitors (request header values such as tokens, cookies and API keys, request bodies, passwords, and credential query parameters such as
?api_key=), browser check secrets, integration secrets, and two-factor authentication seeds are encrypted with AES-256-GCM before they are stored. Monitor credentials are decrypted only to run a check and to show them to the people who can edit the monitor; viewers and read-only API keys see them masked. Integration secrets are decrypted only to deliver an alert. - Passwords are stored as salted hashes, never in plain text.
2. Two-factor authentication
Every user can turn on optional TOTP-based two-factor authentication (RFC 6238) using an authenticator app. Staff access to SutramX administrative tools is protected by two-factor authentication.
3. Probe network and SSRF defences
Server-side request forgery (SSRF) mitigations
Monitor targets are validated before a check runs. Requests to loopback addresses (127.0.0.1, ::1), cloud metadata endpoints (169.254.169.254), and private network ranges (RFC 1918) are blocked, and the resolved address is checked at connection time so DNS tricks cannot redirect a check into an internal network.
Our checker identifies itself honestly; its user agent and published IP addresses are listed on the bot information page.
4. Data protection
We follow GDPR-aligned practices: we collect only the data needed to run the service, act as a processor for the monitoring data our customers configure, use sub-processors under contract, and honour requests to access, export, correct, or delete personal data. We do not sell customer data. Your account and monitoring data is hosted in Frankfurt, Germany (EU); encrypted backups are stored in the USA, and data exports are delivered through Cloudflare R2. SutramX does not currently hold a third-party security or compliance certification (such as SOC 2 or ISO 27001). See the Privacy Policy for details, including retention periods, our Data Processing Addendum for the terms on which we process customer data, and our sub-processor list.
5. Vulnerability disclosure
If you discover a security vulnerability in SutramX, please report it privately to security@sutramx.com with enough detail to reproduce it, and give us a reasonable window to fix it before public disclosure. We will acknowledge your report and keep you updated. We do not currently run a paid bug bounty programme. A PGP key is available on request.