Security & compliance
How HowlOps protects your monitoring data: encryption everywhere, EU-only residency, audited access, and a transparent responsible-disclosure flow.
What we ship today
Security is a priority and we do the maximum that matters in practice: encryption in transit and at rest, tenant-scoped audit logs, EU-only data residency, and regular review. We don’t hold formal certifications today. If you need a specific compliance document for your procurement process, reach out and we’ll work with you.
| ITEM | DETAIL | STATUS |
|---|---|---|
| GDPR compliance | EU-only data residency, signed DPA available on request | Live |
| SAML SSO | Any paid plan (talk to us); SP- and IdP-initiated flows, DNS-verified email domains with domain-scoped provisioning | Live |
| Audit logs | 365-day retention for every account, covering authentication and security events (login, MFA, OAuth, SAML, sessions, password) | Live |
| MFA available | TOTP authenticator apps + backup codes available on every account tier, opt-in | Live |
How the platform stays locked down
Encryption everywhere
TLS 1.3 in transit. Sensitive fields such as MFA secrets and notification-channel credentials are encrypted with AES-256-GCM. Secrets encrypted at rest with SOPS/age and managed as Kubernetes Secrets.
Identity & access
TOTP MFA with backup codes, SAML SSO on any paid plan with DNS-verified email domains (just-in-time provisioning is scoped to your verified domain, so one org can never be joined by another org’s users), role-based access control, scoped API tokens, session revocation.
EU data residency
Your account data, monitoring history, and backups are stored only in EU datacenters, in Germany and Finland. To check your services from where your users actually are, some uptime probes also run from other regions such as the US and Asia. Those probes only perform the check and store nothing outside the EU.
Found a vulnerability? Here’s the playbook.
Email [email protected]. We won’t pursue legal action against researchers who follow the steps below.
Send a detailed report to the security email address below
We acknowledge receipt within 24 hours
We assess severity and begin remediation
We keep you informed of progress throughout
We publicly acknowledge your contribution (if desired)
Legal & procurement
Signed DPA available on request. Full subprocessor list published below.