How we protect your data and our platform
Data we process
StatusDNS works with public data: DNS records, WHOIS/RDAP registration details, TLS certificates and DNSBL answers. You do not need to give us credentials to your DNS provider or mail system. Account data is limited to what is required to run your subscription and notify you.
Infrastructure
- All traffic encrypted in transit (TLS 1.2+, HSTS). Passwords hashed with Argon2id. API keys stored as SHA-256 hashes and shown only once.
- Independent recursive resolvers under our control — we do not route your lookups through third-party DNS providers.
- Least-privilege service accounts, isolated per environment; secrets never in source control.
- Daily encrypted backups with tested restores; 30-day retention.
- Audit log of every administrative action in the platform.
Application security
- CSRF protection on every state-changing request, strict Content Security headers, rate limiting on authentication and lookups.
- All shell interactions (ping, traceroute) use strict input validation and argument escaping; no user input reaches a shell unescaped.
- Dependency-free core reduces supply-chain exposure; changes are reviewed before deployment.
Responsible disclosure
If you believe you have found a vulnerability, email security@statusdns.com. We acknowledge within 2 business days, keep you informed, and credit researchers who wish to be named. Please avoid automated scanning against production and do not access data that is not yours.
Compliance
We are GDPR compliant and act as a data processor for customer account data. A Data Processing Agreement is available on request for Professional and Enterprise customers. SOC 2 Type II readiness is in progress.