Security, privacy and keeping the watcher up
A monitor holds keys to other people’s systems and sends requests to the open internet. This page says, in plain words, what OpenPing does about both today. Where something is not built yet it says Planned.
Your secrets
- API keys and tokens you give a monitor are kept in a vault, encrypted. Each organisation has its own data key, and that key is itself encrypted with a master key held outside the database.
- A secret is never shown again after you save it. The API lists secret names, never values.
- A secret is fetched only when a check is about to run. It is never written to logs, results or error messages.
- Wrapping keys with a cloud key-management service, and secrets held only inside your own network by a private probe. Planned
A good citizen on the internet
- Every request carries a clear user agent,
OpenPing/1.0 (+https://openping.ai/bot), and the addresses our probes call from are published as JSON, so you can allow them and anyone else can block them. See our checker. - Our probes never call private addresses: private ranges, link-local addresses and cloud metadata addresses are refused. A probe looks a name up once and connects to that address, so a DNS trick cannot send it somewhere else. Redirects are checked again at every hop.
- The no-account checker is limited by address, and an unclaimed check is deleted after 24 hours.
- A signed header so your server can prove a request came from us, a cap on total checks against one site, and proof of domain ownership for fast checks. Planned
Agent and MCP checks
- Use test accounts only. An agent test should never run as a real customer.
- Answers are stored with personal data removed (emails, phone numbers, card numbers, Aadhaar and PAN formats) and cut to the first 2 KB. You can choose to store results only, with no answer text at all.
- An MCP test call only uses a tool the server marks read-only, or one you have allowed by name. It never calls a tool marked destructive.
- Answers and tool descriptions are treated as data, never as instructions. The AI judge is told that the answer it is grading may try to instruct it, and it runs only after the plain rules have passed.
- Changed tool descriptions are scanned for hidden instructions: text aimed at a model, invisible characters and links that were not there before.
Accounts and data
- Sign in with Google, GitHub or an email link. There are no OpenPing passwords to steal.
- Roles: owner, admin, member, viewer and billing, with an audit log of changes.
- Every row belongs to one organisation, and the database itself enforces that with row-level security, not only the application.
- API keys carry scopes (read, write, incidents, status pages). The key is shown once, when you create it.
- We never store raw IP addresses of visitors; where we need one to spot abuse, we keep a salted hash.
- What a check keeps: timings, the status code, each rule’s result and a short sample of the response with personal data removed. Samples are kept for 7 days and the numbers for 13 months.
- Single sign-on (SAML or OIDC), SCIM, and controls to shorten how long data is kept, export it all or delete it all yourself. Planned Until then, email us and we will do it by hand.
- Data is stored in one region to begin with. EU and India storage. Planned
Compliance
We do not hold a security certification today and will not claim one until an auditor has signed it. A data processing agreement for GDPR and India’s DPDP Act, and a SOC 2 audit, are planned. Planned
Keeping the watcher up
A monitoring product has two jobs other products don’t: never be down, and never raise a false alarm.
- Nothing alerts on one region’s word. Probes only run checks and report back. One service decides what is down, and it needs two of three regions to agree.
- A false-alarm guard. When many unrelated monitors fail from one region at once, that region is set aside and our own on-call is told, not you.
- Probes hold on to results. If a probe cannot reach us, it keeps the results it has and sends them when it can.
- Status pages live elsewhere. Your status page is rendered to static files and served from Cloudflare’s edge, so it stays up when our app is down.
- Email has a fallback. If the first email provider fails, alerts go through a second.
- A separate setup on another cloud that watches OpenPing itself and tests the alert path end to end; probes on two providers; a monthly drill that breaks one part on purpose. Planned
Report a problem
Found a security problem? Email hello@openping.ai with what you found and how to see it. We will answer, and we will not take action against anyone who reports in good faith.