Security
Facts, not marketing. What data goes where, who touches it, and what protections are actually in place.
Data storage
Account and monitoring data is stored in the EU (Helsinki). Monitoring workers run from EU and Canadian locations. Workers receive only the public URLs to check and a pseudonymous identifier, never names, emails, credentials, or monitoring history. Workers store no user data.
Worker isolation
Monitoring workers run in separate geographic locations and are not part of the application server. Workers receive only the public URLs to check and a pseudonymous identifier, never names, emails, credentials, or monitoring history, and store no user data. If a worker is compromised, it exposes nothing but URLs and a meaningless ID.
GDPR compliance
We are GDPR-compliant: data processed on documented legal bases, subject rights honored within one month, and EU storage for account and monitoring data. Full details in our Privacy Policy. Complaints may be lodged with the Lithuanian State Data Protection Inspectorate (VDAI): vdai.lrv.lt.
Subprocessors
The complete list, with regions. The same list appears on the Enterprise page.
| Subprocessor | Purpose | Region | Note |
|---|---|---|---|
| Hetzner | Hosting, database, Redis | EU: Helsinki, Finland | |
| OVH | Hosting & monitoring worker | EU: Gravelines, France | |
| Monitoring worker (Montreal) | Monitoring execution from Canada | Canada: Montreal | Monitoring worker: receives public URLs and a pseudonymous ID; stores no user data |
| Brevo | Transactional email | EU: France | |
| Stripe | Payment processing | United States (PCI-DSS certified processor) | We never store card data |
| Optional OAuth sign-in | EU/US | Authentication only: no monitoring data shared | |
| Plausible Analytics | Privacy-friendly analytics | Self-hosted: EU (Helsinki) | Not a third-party subprocessor |
Payment security
- All payments processed by Stripe, a PCI-DSS certified processor
- We never see or store card numbers; card data goes directly to Stripe
- No card data is stored on our servers, database, or backups
Account security
- Passwords hashed with bcrypt; never stored in plain text
- Optional Google OAuth sign-in; Google receives only a redirect for authentication
- Self-hosted proof-of-work CAPTCHA on login, registration, and password reset; no third-party CAPTCHA services, no cookies
- No session tokens in URLs; credentials required for all user data access
Network & infrastructure
- Self-hosted infrastructure operated by GIJA HUB MB; no third-party serverless platforms
- HTTP is forced to HTTPS (301 redirect) at the edge; TLS terminates with Let's Encrypt certificates
- Modern security headers on every page: Content-Security-Policy, X-Frame-Options (DENY), X-Content-Type-Options, Referrer-Policy, Permissions-Policy
- Only ports 22, 80, and 443 exposed externally; firewall rules on all servers
Monitoring transparency
We monitor ourselves in public. Our live status is available on a public Uptime Kuma status page: kuma.gijahub.com/status/notiduck (second opinion, independent of our own monitoring).
Certifications
Not currently SOC 2 or ISO 27001 certified; the security facts above are the complete picture.
Need the full legal detail? Read the Privacy Policy and Terms of Service.