All systems operationalReal-time DNS, email and infrastructure monitoring
SupportAPIContactSign in
Trust & security

How we protect your data and our platform

Data we process

StatusDNS works with public data: DNS records, WHOIS/RDAP registration details, TLS certificates and DNSBL answers. You do not need to give us credentials to your DNS provider or mail system. Account data is limited to what is required to run your subscription and notify you.

Infrastructure

  • All traffic encrypted in transit (TLS 1.2+, HSTS). Passwords hashed with Argon2id. API keys stored as SHA-256 hashes and shown only once.
  • Independent recursive resolvers under our control — we do not route your lookups through third-party DNS providers.
  • Least-privilege service accounts, isolated per environment; secrets never in source control.
  • Daily encrypted backups with tested restores; 30-day retention.
  • Audit log of every administrative action in the platform.

Application security

  • CSRF protection on every state-changing request, strict Content Security headers, rate limiting on authentication and lookups.
  • All shell interactions (ping, traceroute) use strict input validation and argument escaping; no user input reaches a shell unescaped.
  • Dependency-free core reduces supply-chain exposure; changes are reviewed before deployment.

Responsible disclosure

If you believe you have found a vulnerability, email security@statusdns.com. We acknowledge within 2 business days, keep you informed, and credit researchers who wish to be named. Please avoid automated scanning against production and do not access data that is not yours.

Compliance

We are GDPR compliant and act as a data processor for customer account data. A Data Processing Agreement is available on request for Professional and Enterprise customers. SOC 2 Type II readiness is in progress.