Skip to content

Trust center

Clear trust signals without inflated claims

ErrorNotifier separates what is implemented today from planned or contract-specific controls, so buyers can evaluate uptime monitoring, privacy, and security honestly.

Availability monitoringAvailable Now
External checks, confirmed incidents, recovery events, and public status pages.
Data minimizationAvailable Now
Payload caps, PII scrubbing, masked secrets, and retention tied to plan entitlements.
Access controlAvailable Now
Organization roles for owners, admins, responders, viewers, and billing users.
Automated test historyAvailable Now
Secret-key CI ingestion records unit-test runs, failures, pass rate, and report URLs.
Enterprise workflowsPlanned
Contract SLAs, SAML, DPA workflows, and private probes require explicit enterprise setup.

Security overview

SSRF checks block private targets and unsafe redirects before monitoring requests run. Webhook deliveries can be verified with HMAC signatures.

Review security

Data minimization

Monitor records store URLs, expected statuses, check metadata, incident history, and bounded telemetry needed to operate the service.

Read privacy notes

PII redaction

Error ingestion is designed to remove tokens, passwords, authorization headers, card-like values, and email addresses before storage.

Encryption

Transport security depends on the deployed HTTPS configuration. Secret-at-rest protection uses WordPress salts and encrypted/masked storage where implemented; formal encryption-at-rest claims need hosting review.

Retention and deletion

Telemetry retention follows plan limits, and account export/delete flows require email-token confirmation before data is returned or removed.

Sub-processors

Business TODO: publish the active hosting, email, payment, and alert-delivery sub-processor list before enterprise procurement.

Incident response

Confirmed incidents, alert attempts, acknowledgements, and recovery events are captured in append-only timelines for post-incident review.

Security contact

Send security questions to security@errornotifier.com. This is a contact channel, not a vulnerability bounty commitment.

Operational posture

Use WP-CLI workers from cron or Task Scheduler for production checks, with WP-Cron kept as a fallback.

Set up workers

Public demo

Review the real product screens with read-only mock data

Open the demo workspace to inspect monitors, incidents, domains, alert channels, status pages, projects, issues, automated test runs, releases, artifacts, audit history, and umbrella reports without creating an account.