Security
An overview of how we protect your account and the monitoring configuration you give us — high level by design, since some detail about our infrastructure is deliberately not public.
Encryption in transit
All traffic to our dashboard and API is served over TLS. Health checks we run on your behalf follow whatever scheme (HTTP or HTTPS) the endpoint you configured uses.
Sensitive check data
When you configure a check, header or body values you mark as sensitive — API keys, auth tokens, and similar — are encrypted before they're stored, and only decrypted at the moment a check runs. They're never returned back to the dashboard in plaintext once saved.
Account security
Passwords are hashed, never stored in plaintext. Sessions are protected against common web attacks, and we apply rate limiting to authentication endpoints to slow down credential-guessing attempts.
Infrastructure
The Service runs on cloud infrastructure with isolated environments per component. We don't publish exact infrastructure topology or IP ranges — the regions our checks run from are listed on our bot info page.
Reporting a vulnerability
If you believe you've found a security vulnerability in HeimPulse, please report it to security@heimpulse.com before disclosing it publicly. We'll acknowledge reports promptly and keep you updated as we investigate and fix the issue.
HeimPulse