Security
Last updated: 2026-09-29
Responsible Disclosure
If you discover a security vulnerability, email security@crontinel.com with details. We will investigate the report and coordinate a fix with you.
We ask that you do not publicly disclose any vulnerability without our explicit permission. Once the issue is resolved, we welcome coordinated disclosure.
Data Security
- Transport: The public API uses HTTPS. Keep your app key private and revoke it if it is exposed.
- Access control: Organization and app permissions limit who can manage monitors and read operational data.
- Recovery: We have not completed a hosted restore drill or verified a recovery window. Backup copies may outlive records removed from the live database.
Infrastructure
Crontinel's application and PostgreSQL database run on Railway. Cloudflare serves the public site and hosts optional AI investigations. See the Privacy Policy for the data we send to service providers.
Compliance
- Data requests: Profile export and deletion controls are available. Account deletion does not immediately remove every retained record. See the Privacy Policy.
- SOC 2: Crontinel has not completed a SOC 2 audit.
Authentication
- API keys: Keys can be scoped to an app and revoked. Treat a copied key as a credential until it is revoked.
- Dashboard 2FA: Two-factor authentication via TOTP is available for all dashboard accounts. We strongly recommend enabling it.
Incident Response
If an incident affects your data, we will assess its impact and notify affected people and authorities when required by applicable law. GDPR Article 33 concerns notice to a supervisory authority; Article 34 covers notice to affected people.
We maintain an internal incident response plan that covers containment, investigation, communication, and remediation steps.
Contact
Security-related questions? security@crontinel.com