Trust

Security: your monitoring data stays yours

Encryption everywhere, SSRF-safe probing, organization isolation, and evidence integrity - the controls behind an evidence platform.

Encryption

All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Card details are handled by our payment provider; RELIASTRA never stores full card numbers.

Safe probing

Before any check request leaves, the target is resolved and validated against an SSRF policy that rejects private, loopback, link-local and metadata addresses. Blocked targets are recorded as configuration problems - never as vendor outages - and no request is sent.

Isolation

Organizations are strictly isolated: dependencies, incidents, evidence and credentials are scoped per organization and enforced server-side. Public Track pages show aggregated posture for vendors made public only - never customer endpoints, headers or credentials.

Evidence integrity

Generated reports are checksummed and bound to the producing organization. Public verification confirms existence and integrity without disclosing private configuration. Audit-log entries cover security-relevant actions.

Sessions and access

Short-lived access tokens with rotation, HttpOnly admin session cookies, and rate limiting on authentication and public endpoints. The admin control plane is a separate security domain with its own credentials.

What to do next

Read the Privacy Policy, review Terms, or contact us with security questions at support@reliastra.com.

Know when your dependencies fail. Prove what happened.

Monitor the external APIs your product relies on, correlate their failures with your incidents, and generate verifiable evidence when a vendor causes downtime.