How we handle your data today, described plainly
We're a small team without a formal certification yet — this page says what's actually true, not what would sound best
We aim for high availability, but we don't publish a specific uptime number or financial guarantee until we can actually stand behind one.
All traffic to Seiri runs over TLS, and data is encrypted at rest with our cloud provider's standard encryption.
Logical multi-tenant isolation between customer accounts, with role-based access controls within an organization.
We're a small team. We haven't completed a formal third-party certification, and we won't claim one until it's real.
Your data security is our highest priority
Data is automatically purged based on your plan limits and retention settings. No manual intervention required.
Request complete data deletion at any time. We'll permanently remove all your data within 30 days.
Built on enterprise-grade cloud infrastructure
Hosted on established cloud infrastructure providers — we don't run our own datacenters, and we don't publish a specific uptime SLA on top of theirs.
Our hosting provider's baseline network protections apply to all traffic; we haven't layered on a separate dedicated DDoS product.
We run from one region today. Additional regions are on the roadmap, driven by where customers actually are.
Filters malicious traffic before it reaches our servers
Prevents abuse with intelligent rate limiting per API key
Private networks with no direct internet access
Strict firewall rules controlling all network traffic
Where we actually are today
We haven't completed a SOC 2, ISO 27001, or similar third-party audit. If you need one for a vendor-security review, tell us — it's useful signal for prioritizing it, but we won't claim it before it exists.
We aim to handle personal data consistent with GDPR principles (data minimization, the right to deletion, and clear retention). We haven't made specific representations around CCPA, PIPEDA, or HIPAA, and shouldn't be treated as compliant with those until we say so explicitly.
Proactive monitoring and incident response
Security work is done by the engineers who build the product, not a separate full-time security team — for now, that's the honest size of the company.
If you find a security issue, email hello@seiri.app — we don't have a paid bug bounty program yet, but we read every report and will credit you if you'd like.
Common questions about our security practices
Logical multi-tenant separation, with each monitor accessed through its own unguessable ping URL and role-based access controls within your organization.
We'd investigate and contain it as fast as we're able to as a small team, and notify affected customers in line with GDPR's 72-hour requirement where it applies. We don't have a published, tested incident-response SLA beyond that yet.
Not yet — we haven't completed a SOC 2 or similar third-party audit, so there's no report to share. If a vendor-security review needs one, email hello@seiri.app and tell us; it helps us prioritize.
Access is limited to the people who need it to operate the service, and we don't have a large team with broad standing access. We don't currently run a formal monthly access audit process — if that's a hard requirement for you, ask us where we stand before you rely on it.
We host from a single region today and don't offer a choice of data residency. Additional regions are on the roadmap if customer demand and data-protection requirements call for it.
Our security team is here to help with any questions about our practices, compliance, or how we protect your data.