Security
How we protect accounts and data, and how to report a vulnerability.
Reporting a vulnerability
If you find a security issue, email security@ip-fd.net with a description and steps to reproduce. We confirm reports within three working days and keep you updated until the issue is fixed. Please give us reasonable time to fix a problem before you publish it, and do not access other users' data, run denial of service tests or use automated scanners against production.
Our security.txt follows RFC 9116.
How we protect your account
- Passwords are hashed with bcrypt. We never store them in readable form.
- Session tokens and API keys are stored as keyed hashes, so a database leak does not expose them.
- Two-factor authentication with any TOTP app is available for every account.
- All traffic uses HTTPS with HSTS. Cookies are HttpOnly, Secure and SameSite.
- Every form is protected against cross-site request forgery, and pages use a strict Content Security Policy.
- Server-side requests to addresses you enter (monitors, webhooks, SSL and HTTP checks) can never reach private networks.
- Passwords you store for HTTP monitors are encrypted with AES-256-GCM.
Your sessions
You can see where you are signed in and sign out other devices on the account security page.