Security
How Uptimehub keeps your data safe
Uptimehub runs read-only external checks against the URLs and endpoints you add. We never install an agent, never touch your servers, and never need credentials to your systems. We store only the results and timings of your checks, and we encrypt everything in transit and at rest.
In short
Yes. Uptimehub only makes the same kind of request a visitor's browser would: it sends a check to the public URL or endpoint you tell it to watch and records whether the response was healthy and how long it took. It runs from our own probe infrastructure across six regions, never installs software on your servers, never needs a login or API key to your systems, and cannot change anything on your side. We store only check results and timings, encrypt data in transit and at rest, and you can pause or delete any monitor at any time.
Security posture
Read-only from the outside, by design
Every choice below is made so you can monitor your sites and services without giving anyone access to your servers, databases, or credentials.
Read-only external checks
Uptimehub only sends requests to the public URLs and endpoints you add, the same way a browser or an API client would. It reads the response status, headers, timing, and keyword you configured. It cannot write, change, or delete anything on your side.
No agent on your servers
There is nothing to install. We do not run software inside your infrastructure, so there is no agent to patch and no new process with access to your machines.
No access to your systems
We never ask for a login, SSH key, database password, or API key to your servers. Monitoring only needs the public address of the thing you want watched.
We store only results and timings
We keep the outcome of each check: up or down, status code, response time, region, and the timestamp. We do not copy or store the contents of your application data or your users records.
Encryption in transit and at rest
All traffic between you, our probes, and our systems is encrypted with TLS, and stored check data is encrypted at rest. Account credentials are stored hashed and are never exposed in logs.
Our own probe infrastructure
Checks run from probes we operate across six global regions. Alerts to Slack, email, SMS, and webhooks are sent from our systems, and enterprise customers can request a security review and custom terms.
Scope
What we check, and what we never do
What we check
- The public URLs, APIs, and endpoints you add to a monitor
- Response status codes, headers, and a keyword or content match you configure
- Response time and availability from each of six global regions
- SSL certificate expiry and domain reachability, so we can warn you early
What we never do
- Install an agent or run software on your servers
- Ask for a login, SSH key, database password, or API key to your systems
- Read, copy, or store the contents of your application or user data
- Write, change, or delete anything on your infrastructure
Uptimehub watches your services from the outside, the way your customers reach them. Every alert points a human on your team at something to look into on your own systems.
Security questions
The questions teams ask first
Every minute on Starter and every 30 seconds on Pro and above, from 6 global regions. Faster intervals and multi-region checks are the default, not an upsell locked behind the top tier, so you catch outages quickly wherever your users are.
In seconds, the moment a check confirms your service is down. Alerts route to Slack, email, SMS, webhook, Discord, Microsoft Teams, Telegram or a PagerDuty-style on-call flow. You pick the channels per monitor and per escalation step.
Yes. Every monitor is checked from 6 global regions with automatic retry verification. A regional network blip that would fool a single-location checker gets confirmed across regions first, so you do not get false "you are down" alerts at 3am.
Yes. Every plan includes a branded public status page with your logo, colors and a custom domain. Your monitors auto-power it, it shows 90-day uptime history, and agencies can run a separate white-label page per client. The status page is included, not a separate paid module.
More on regions, alerts, and status pages on the full FAQ.
Monitoring you can trust to stay out of the way
Start watching your sites, APIs and services from six regions. We check from the outside, store only results and timings, and never touch your servers.