Security

If ServerPal sits in the path of knowing whether your infrastructure is healthy, it should be clear how the thing itself is run.

How the product is built

Encrypted in transit

TLS on every connection: the console, the public API, the status pages, and every sample the agent sends. Certificates for customer status-page domains are issued and renewed automatically.

Roles scoped per project

Owner, admin, editor and viewer. A role is granted on one project rather than across an account, so somebody added to one project gains no visibility into another.

Two-factor authentication

Authenticator-app 2FA on every account including free, with sessions listed and revocable.

Audit log

Account and project actions are recorded — who did what, and when — so an unexpected configuration change is traceable.

Separate admin application

The internal admin console is a separate application on its own hostname, gated server-side before any of its code is served. It is not a hidden route inside the customer product.

Outbound-only agent

The agent reports out on an interval. It needs no inbound firewall rule and opens no listening port on your servers.

What we store

ServerPal keeps what it needs to draw your charts and decide whether to alert, and nothing about the contents of your application.

  • Check results: timing, status code and outcome. Not response bodies.
  • Server metrics: resource numbers and OS health flags from the agent. Not process lists, files or logs.
  • Both are kept for your plan's retention window and then aged out.
  • Deleting a project deletes its servers, checks and history with it.

Our own availability

Plenty of monitoring companies print an uptime percentage with nothing standing behind it. Instead, here is what is architecturally true:

  • Checks keep running and alerting during a console outage — alerting does not depend on anyone loading the dashboard.
  • Status page delivery is separated from the console, so your customers' page survives our bad day.
  • When an incident affects customers we say so in writing rather than waiting to be asked.

Reporting a vulnerability

If you have found a security problem we would much rather hear it from you first. Open a support ticket from the console or write to security@serverpal.net describing what you found and how to reproduce it. We will confirm receipt, tell you what we found, and let you know when it is fixed. Nobody reporting in good faith gets threatened for it.

ServerPal holds no third-party security certification at this time. Where a page like this would normally list compliance badges, we would rather say plainly that we do not have them yet than imply otherwise.

Start monitoring in about a minute.

Twenty checks and one server, free and with no card. Upgrade only when you outgrow it.