Trust
Security: your monitoring data stays yours
Encryption everywhere, SSRF-safe probing, organization isolation, and evidence integrity - the controls behind an evidence platform.
Encryption
All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Card details are handled by our payment provider; RELIASTRA never stores full card numbers.
Safe probing
Before any check request leaves, the target is resolved and validated against an SSRF policy that rejects private, loopback, link-local and metadata addresses. Blocked targets are recorded as configuration problems - never as vendor outages - and no request is sent.
Isolation
Organizations are strictly isolated: dependencies, incidents, evidence and credentials are scoped per organization and enforced server-side. Public Track pages show aggregated posture for vendors made public only - never customer endpoints, headers or credentials.
Evidence integrity
Generated reports are checksummed and bound to the producing organization. Public verification confirms existence and integrity without disclosing private configuration. Audit-log entries cover security-relevant actions.
Sessions and access
Short-lived access tokens with rotation, HttpOnly admin session cookies, and rate limiting on authentication and public endpoints. The admin control plane is a separate security domain with its own credentials.
What to do next
Read the Privacy Policy, review Terms, or contact us with security questions at support@reliastra.com.
Know when your dependencies fail. Prove what happened.
Monitor the external APIs your product relies on, correlate their failures with your incidents, and generate verifiable evidence when a vendor causes downtime.