Security overview

Practical safeguards around monitoring and alert delivery

This overview explains the safeguards built into SiteAlert and how monitoring, alerts and shared status information are handled.

Validated monitoring targets

SiteAlert validates destinations before checking them and blocks internal or private network addresses. Monitor URLs cannot contain embedded credentials.

Confirmed incidents

One failed monitoring round is recorded first. A second consecutive failed round is required before a downtime incident opens, while planned maintenance suppresses expected uptime and performance alerts.

Isolated background work

Monitoring, SSL checks, alerts, webhooks and realtime updates use named queues so different workloads can be processed separately.

Signed webhooks

Webhook deliveries include an HMAC-SHA256 signature, timestamp, event name, delivery ID and idempotency key. Delivery targets are validated again before each request.

Retries and duplicate protection

Incident and alert records help prevent duplicate sends. Retryable webhook failures can make four attempts with increasing delays, while terminal results remain visible in delivery history.

Controlled status-page sharing

Public status pages are opt-in and show selected monitoring, incident and public maintenance information. Account contacts, private maintenance and webhook settings stay private.

Data retention

  • Check and closed-incident history follows the effective plan retention period.
  • Performance aggregates are cleaned after approximately 31 days.
  • Webhook delivery history defaults to 30 days.
  • Deleting an account stops its monitoring and removes active service data, subject to the retention described in the Privacy Policy.
Read the full retention and privacy details →

How delivery status is reported

SiteAlert reports the delivery stage it can verify rather than treating every queued alert as delivered.

  • Email status records when an alert has been queued; inbox placement is controlled by the receiving mail systems.
  • WhatsApp status records when Twilio accepts the request; final delivery remains with Twilio and WhatsApp.
  • A delivered webhook means the destination returned a successful HTTP response to SiteAlert.

Report a security concern

Send a concise description, affected URL or feature, reproduction steps and potential impact to support@usesitealert.com. Do not include credentials, tokens, customer data or destructive proof.