We protect thousands of domains — so we hold ourselves to the highest standard. Here's everything you need to know about how we safeguard your data and our infrastructure.
Security Score
Monitored
SecurityMonitor.io is continuously monitored by our own platform — the same 170+ security checks we run for our customers. We practice what we preach: if we ask you to secure your domain, ours should be secured first.
The measures we take to keep your data safe and our infrastructure hardened.
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Database backups are encrypted with separate keys.
All servers and databases run in EU data centres. No data ever leaves the European Union.
Customer data is logically isolated with row-level security policies enforced at the database level.
We collect only the data strictly necessary to deliver the service. No tracking, no profiling, no data selling.
Team access is governed by role-based permissions. All administrative actions are logged in an immutable audit trail.
We maintain a documented incident response plan. Critical vulnerabilities are patched within 24 hours.
We follow industry-standard compliance frameworks and are transparent about our controls.
GDPR compliant
Full data subject rights, DPA available on request
No cookies without consent
Cookie banner with granular consent management
Data Processing Agreement
Available for all paid plans on request
Right to deletion
Account and all associated data fully deletable
Regular penetration testing
Annual third-party security assessments
SOC 2 aligned controls
Following SOC 2 Type II framework practices
Third-party services that process data on our behalf. We carefully vet each provider for security and GDPR compliance.
Infrastructure & payments
Lovable
lovable.dev
Application hosting & deployment
Supabase
supabase.com
Database, authentication & backend
Stripe
stripe.com
Payment processing & subscriptions
Cloudflare
cloudflare.com
CDN, DDoS protection & bot mitigation
Analytics & marketing
Loaded only after you grant the relevant cookie category. Default state is denied for all EU visitors via Google Consent Mode v2. Manage your choice in Cookie preferences.
Google Tag Manager
tagmanager.google.com
Tag orchestration (loads only after consent)
Google Analytics 4
analytics.google.com
Aggregated, IP-anonymised product analytics (consent-based)
Google Search Console
search.google.com
Organic search performance & indexing diagnostics
Google Ads
ads.google.com
Conversion measurement & retargeting (consent-based)
Security intelligence sources
Google Safe Browsing
Malware & phishing URL checks
VirusTotal
Multi-engine malware & reputation scanning
Have I Been Pwned
Breach data lookups (domain-level)
Shodan
Open port & vulnerability discovery
crt.sh
Certificate Transparency log lookups
URLhaus
Malware URL database checks
Spamhaus
IP & domain blacklist reputation
Firecrawl
Public-paste & open-web OSINT crawling for leak detection
Last updated: March 2026. We notify customers at least 30 days before adding new subprocessors. Contact privacy@securitymonitor.io for questions or to request our Data Processing Agreement.
If you believe you've found a security vulnerability in our platform, we encourage you to report it responsibly. We take all reports seriously and aim to respond within 48 hours.
Report a vulnerability
security@securitymonitor.ioResponse time
Acknowledgement within 48h. Critical issues resolved within 7 days.
Safe harbor
No legal action against researchers who follow responsible disclosure.
We use strictly necessary cookies to run the site, and — only with your consent — analytics and marketing cookies (Google Analytics, Google Tag Manager) to improve the product. You can change your choice anytime via "Cookie preferences" in the footer. Privacy Policy · Sub-processors