Security

You're trusting us with your monitoring data. We don't take that lightly. This page explains exactly how we protect it, who has access, and why we think a small, focused team is actually an advantage when it comes to security.

Who's Behind Your Data

Oh Dear is built and maintained by two people you can actually look up:

We've spent years building our reputations through open-source work, conference talks, and writing. Our public personas are directly tied to this product. If we mess up, everyone will know. That's a pretty strong incentive to get security right.

Technical Security

Here's how we actually protect your data:

Encryption

Infrastructure

We rely on providers with proper certifications:

Access Controls

Development Practices

Backups & Recovery

We take backups seriously. Here's our retention schedule:

Backups are stored separately from production infrastructure. We test restores regularly.

Why No SOC 2 (Yet)?

We don't have SOC 2 or ISO 27001 certifications. Here's why:

SOC 2 audits cost $50,000+ and require significant ongoing overhead. For a three-person team, that's a meaningful investment that would directly impact what we can build for you. We'd rather spend that time and money on making the product better.

But here's the thing: a small team isn't a security weakness. It's actually an advantage.

We've never had a reportable security breach. That's not because we're lucky - it's because we're careful, and because there are only three of us to keep track of.

For Security & Compliance Teams

We understand you might need more than this page for your vendor assessment. Here's what we can offer:

If you have specific compliance requirements or questions we haven't addressed here, email us directly. We're happy to get on a call if that helps.

Vulnerability Disclosure

Found a security issue? We want to hear about it.

Please give us reasonable time to fix issues before disclosing them publicly. We'll keep you updated on our progress.

Legal Documentation

For the formal details on how we handle your data:

Privacy Policy

How we collect, use, and protect your personal data

Read Policy

Terms & Conditions

The terms governing your use of Oh Dear

Read Terms

Data Processing Agreement

GDPR-compliant DPA with EU Standard Contractual Clauses

Read DPA

Subprocessors

Complete list of third-party processors and their certifications

View List

Contact Us

Questions about security? We're happy to talk.