Trust & Security
Current controls, compliance status, subprocessors, and contact information.
Readiness work is in progress. We have not yet begun an observation period or received a SOC 2 report. Ask security@servicealert.ai for the current program status.
Data subject requests are handled through privacy@servicealert.ai. A DPA with Standard Contractual Clauses is available on request.
California residents can request data export or deletion via privacy@servicealert.ai.
Standard DPA with SCCs signed on request for Business and Enterprise customers. Email legal@servicealert.ai.
Infrastructure and availability
- ServiceAlert runs on Microsoft Azure infrastructure in the United States.
- Production data is backed up for disaster recovery under the schedule in our Data Retention Policy.
- Public traffic is encrypted in transit. Public endpoints use rate limits and other abuse controls.
- Credentials and service secrets are kept outside the application source code and restricted to authorized processes.
Authentication & access
- Auth0 handles customer authentication. Enterprise plans support SAML or OIDC single sign-on.
- API keys are stored in non-reversible form, scoped to an organisation, and can be revoked.
- Role and tenant checks restrict access to monitors, incidents, and other account data.
- Audit records capture material account changes. Retention depends on the purchased plan.
Data handling
- We store account information, configured monitors, incident records, alert preferences, and the results needed to operate those features. We do not sell customer data.
- ServiceAlert does not proxy application traffic. It checks the public or network targets a customer configures.
- The current retention and deletion schedule is maintained in the Data Retention Policy.
- Operational logs are limited and rotated. Sensitive request content is not intended to be retained in standard web logs.
Vulnerability disclosure
Report a suspected vulnerability to security@servicealert.ai. Please avoid accessing customer data, degrading the service, or publishing details before we have had a reasonable opportunity to investigate.
PGP key and security.txt available at /.well-known/security.txt.
Incident transparency
Current operational information is published at status.servicealert.ai. Material product changes are listed in the public changelog. Required incident notices are sent to affected customers under the applicable agreement and law.
Subprocessors
- Microsoft Azure, infrastructure hosting (eastus2)
- Auth0 / Okta, authentication
- Stripe, billing
- Postmark, transactional email
- Twilio, SMS alerts
- Cloudflare, DNS and DDoS protection
Purpose and data categories are documented in the DPA available on request. Material changes are notified to customers as required by the applicable agreement.
Questions
For security questionnaires, architecture questions, the current SOC 2 readiness status, or the availability of additional review materials, email security@servicealert.ai.
Last updated: 16 August 2026