Infrastructure Security

The managed OpsPing cloud runs as a single Go service binary on one AWS EC2 instance in us-east-2 (Ohio), backed by a PostgreSQL database (single-table design) with automated daily backups. Email is delivered via AWS SES. We deliberately keep the infrastructure small — fewer moving parts, fewer places for things to go wrong. Private single-tenant deployments run the same application on infrastructure you or we manage.

Data Encryption

Network Security

Access Control

Application Security

Authentication

Input Validation & Output Encoding

Dependency Management

Zero Standing Access

OpsPing staff hold no standing access to your data. The system is built so that we can't read your alerts unless you explicitly let us — and when you do, everything we do is recorded in your own audit log.

Tenant Isolation

Support Access by Invitation

Break-Glass Accountability

Compliance & Certifications

SOC 2

OpsPing is not pursuing SOC 2 certification — no independent audit has been conducted and none is planned. Our practices are mapped to the SOC 2 Trust Services Criteria, in depth, on our SOC 2 page.

GDPR

OpsPing is GDPR compliant. All customer data is stored in AWS us-east-2 (Ohio, USA). We offer a Data Processing Agreement (DPA) for customers who need one. See our Privacy Policy for details on data handling, retention, and deletion.

Data Retention

Vulnerability Disclosure

If you discover a security vulnerability in OpsPing, please report it to [email protected]. We investigate all reports and respond within 48 hours. We don't run a public bug bounty yet, but we credit researchers in our changelog (with permission).

Do not attempt to access, modify, or delete other users' data when testing. Use your own account and test alerts only.

Questions?

Contact [email protected] for security questions, DPA requests, or penetration testing coordination. We're happy to provide additional documentation for your security review.

Enterprise Security Questionnaire

Evaluating OpsPing for your organization? This section answers the questions we most commonly receive in vendor security assessments. Because OpsPing is in beta, several answers describe work in progress — we disclose limitations plainly so your team can make an informed risk decision.

Product Overview

OpsPing is a SaaS on-call paging and alerting product for DevOps and operations teams, consisting of a React Native (Expo) mobile application and an AWS-hosted backend. Alerts are delivered via push notifications (relayed through Expo's push service), email (Amazon SES), and optional SMS/voice (Twilio).

Data Handling

Channel PII encryption: on-call phone numbers and email addresses are encrypted at the application layer (AES-256-GCM) in addition to infrastructure-level protections. MFA secrets receive the same treatment.

Subprocessors

We share personal data only with the subprocessors needed to operate the Service — AWS (hosting, database, and email via Amazon SES), Expo (push notification relay), and Twilio (optional SMS/voice). See the full subprocessor list for purposes, data processed, locations, and SOC 2 status. Customers are notified at least 30 days in advance of subprocessor changes, with a 14-day objection window (see our DPA).

Security Measures

Compliance Status

Incident Response

Business Continuity & Disaster Recovery

Security questions not covered here: [email protected]. This questionnaire reflects the current state of the beta product and will be updated as controls mature.