8 days until Shopify stops accepting app script tags. Is your store running one? Check your store free
Get started free

Security

How StatusBird protects monitoring data

What we collect is small by design: which services you monitor, where to send alerts, and the results of our own checks. This page says how that data is protected, stated plainly so it can be pasted into a vendor questionnaire. Last reviewed September 22, 2026.

What we hold

Encryption

Access

Integrity of the record

Monitoring history is written once and never edited by the application. Every day at 00:20 UTC we compute a SHA-256 digest over every reading of the previous day, chained to the day before, and publish it at /api/public/v1/integrity.json. Anyone holding a copy of the raw data can recompute a day and compare; a deleted or altered reading changes every digest from that day forward. CRM deliveries and incident acknowledgements are in the same chain, so the record of which incident became which ticket, and who acknowledged it, is tamper evident too. Sealed reports carry their own hash and a verification page.

Availability and abuse

Retention and deletion

Dependencies and vulnerability handling

Dependencies are pinned and audited against the Python advisory database; known-vulnerable versions are upgraded promptly. Report a vulnerability to security@statusbird.io; we acknowledge within two business days and do not pursue good-faith researchers.

Compliance

StatusBird LLC is not itself SOC 2 or ISO 27001 certified. Our hosting providers are (Render: SOC 2 Type II; Google Cloud: SOC 2, ISO 27001), and the controls above are documented so a customer's own review can proceed without a certification. Our written policy set (information security, access control, change management, incident response, business continuity, vendor management, data retention and risk register) and a control matrix mapping each SOC 2 Trust Services Criterion and ISO 27001 Annex A theme to the control that meets it and its evidence are available on request. If your procurement requires a signed questionnaire or a data processing agreement, email security@statusbird.io.