MARKETING · SECURITY

Security & compliance

How HowlOps protects your monitoring data: encryption everywhere, EU-only residency, audited access, and a transparent responsible-disclosure flow.

01 · COMPLIANCE POSTURE

What we ship today, what’s next

We’d rather be honest about what’s certified, what’s mid-audit, and what’s still on the roadmap than overpromise. Status is updated when an item ships or when an audit milestone closes.

ITEMDETAILSTATUS
GDPR complianceEU-only data residency, signed DPA available on request
Live
SAML SSOPremium tier; SP-initiated and IdP-initiated flows
Live
Audit logsTenant-scoped, 90d on Standard, 1y on Premium
Live
MFA enforcementTOTP + WebAuthn passkeys for all account tiers
Live
SOC 2 Type IIAudit in progress — controls + evidence collection underway
In progress
Annual third-party pentestScheduled with external testing partner
Planned
Bug bounty programmePublic bounty on HackerOne or Intigriti
Planned
02 · TECHNICAL CONTROLS

How the platform stays locked down

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Encrypted database backups. Secrets isolated in HashiCorp Vault.

Identity & access

TOTP + WebAuthn MFA, SAML SSO on Premium, role-based access control, scoped API tokens, session revocation.

EU-only data residency

Primary in Frankfurt, replica in Paris. No transfer outside EU without Standard Contractual Clauses.

03 · RESPONSIBLE DISCLOSURE

Found a vulnerability? Here’s the playbook.

Email [email protected]. We won’t pursue legal action against researchers who follow the steps below.

1

Send a detailed report to the security email address below

2

We acknowledge receipt within 24 hours

3

We assess severity and begin remediation

4

We keep you informed of progress throughout

5

We publicly acknowledge your contribution (if desired)

Legal & procurement

Signed DPA available on request. Full subprocessor list published below.