Security practices

Security & Compliance

How we handle your data today, described plainly

We're a small team without a formal certification yet — this page says what's actually true, not what would sound best

No formal uptime SLA yet

We aim for high availability, but we don't publish a specific uptime number or financial guarantee until we can actually stand behind one.

Encryption in transit and at rest

All traffic to Seiri runs over TLS, and data is encrypted at rest with our cloud provider's standard encryption.

Least-privilege access

Logical multi-tenant isolation between customer accounts, with role-based access controls within an organization.

Where we stand on compliance

We're a small team. We haven't completed a formal third-party certification, and we won't claim one until it's real.

GDPR-aligned data practices
No SOC 2 / ISO 27001 yet

Data Protection & Privacy

Your data security is our highest priority

Encryption Standards

  • Encryption at rest using our cloud provider's standard disk/database encryption
  • TLS for all data in transit
  • Unique ping URLs per monitor, so guessing one doesn't expose another customer's data

Data Isolation

  • Multi-tenant architecture with complete data separation
  • Unique monitoring URLs prevent cross-tenant access
  • Role-based access controls within organizations
  • Network-level segregation in our infrastructure

Data Retention & Deletion

Automated Retention

Data is automatically purged based on your plan limits and retention settings. No manual intervention required.

Right to Deletion

Request complete data deletion at any time. We'll permanently remove all your data within 30 days.

Infrastructure Security

Built on enterprise-grade cloud infrastructure

Cloud infrastructure

Hosted on established cloud infrastructure providers — we don't run our own datacenters, and we don't publish a specific uptime SLA on top of theirs.

Standard network protections

Our hosting provider's baseline network protections apply to all traffic; we haven't layered on a separate dedicated DDoS product.

Single-region hosting

We run from one region today. Additional regions are on the roadmap, driven by where customers actually are.

Network Security Layers

1

Web Application Firewall

Filters malicious traffic before it reaches our servers

2

Rate Limiting

Prevents abuse with intelligent rate limiting per API key

3

VPC Isolation

Private networks with no direct internet access

4

Security Groups

Strict firewall rules controlling all network traffic

Compliance & Certifications

Where we actually are today

We haven't completed a SOC 2, ISO 27001, or similar third-party audit. If you need one for a vendor-security review, tell us — it's useful signal for prioritizing it, but we won't claim it before it exists.

We aim to handle personal data consistent with GDPR principles (data minimization, the right to deletion, and clear retention). We haven't made specific representations around CCPA, PIPEDA, or HIPAA, and shouldn't be treated as compliant with those until we say so explicitly.

Security Operations

Proactive monitoring and incident response

Incident Response

  • Small team, direct line — a security report reaches the people who built the product, not a queue
  • Customer notification in line with GDPR's 72-hour breach notification requirement, if it ever applies

Ongoing practices

  • Dependency and vulnerability scanning on our codebase and dependencies
  • No formal penetration testing program yet — we haven't engaged a third-party firm, and won't claim we have

Team & disclosure

Small team, not a dedicated security org

Security work is done by the engineers who build the product, not a separate full-time security team — for now, that's the honest size of the company.

Responsible disclosure welcome

If you find a security issue, email hello@seiri.app — we don't have a paid bug bounty program yet, but we read every report and will credit you if you'd like.

Security FAQ

Common questions about our security practices

How do you ensure data isolation between customers?

Logical multi-tenant separation, with each monitor accessed through its own unguessable ping URL and role-based access controls within your organization.

What happens if there's a security breach?

We'd investigate and contain it as fast as we're able to as a small team, and notify affected customers in line with GDPR's 72-hour requirement where it applies. We don't have a published, tested incident-response SLA beyond that yet.

Can I get a copy of your security audit reports?

Not yet — we haven't completed a SOC 2 or similar third-party audit, so there's no report to share. If a vendor-security review needs one, email hello@seiri.app and tell us; it helps us prioritize.

How do you handle employee access to customer data?

Access is limited to the people who need it to operate the service, and we don't have a large team with broad standing access. We don't currently run a formal monthly access audit process — if that's a hard requirement for you, ask us where we stand before you rely on it.

What data residency options do you offer?

We host from a single region today and don't offer a choice of data residency. Additional regions are on the roadmap if customer demand and data-protection requirements call for it.

Questions About Our Security?

Our security team is here to help with any questions about our practices, compliance, or how we protect your data.

We read every security inquiry and reply as quickly as we can