Infrastructure Security

The managed OpsPing cloud runs as a single Node.js service on one AWS EC2 instance in us-east-2 (Ohio), backed by a single DynamoDB table. Email is delivered via AWS SES. We deliberately keep the infrastructure small — fewer moving parts, fewer places for things to go wrong. Private single-tenant deployments run the same application on infrastructure you or we manage.

Data Encryption

Network Security

Access Control

Application Security

Authentication

Input Validation & Output Encoding

Dependency Management

Zero Standing Access

OpsPing staff hold no standing access to your data. The system is built so that we can't read your alerts unless you explicitly let us — and when you do, everything we do is recorded in your own audit log.

Tenant Isolation

Support Access by Invitation

Break-Glass Accountability

Compliance & Certifications

SOC 2

We plan to pursue SOC 2 Type II certification after beta. No independent audit has been conducted yet and no report is available. See our SOC 2 page for current status and what we can share in the meantime.

GDPR

OpsPing is GDPR compliant. All customer data is stored in AWS us-east-2 (Ohio, USA). We offer a Data Processing Agreement (DPA) for customers who need one. See our Privacy Policy for details on data handling, retention, and deletion.

Data Retention

Vulnerability Disclosure

If you discover a security vulnerability in OpsPing, please report it to security@ops-ping.com. We investigate all reports and respond within 48 hours. We don't run a public bug bounty yet, but we credit researchers in our changelog (with permission).

Do not attempt to access, modify, or delete other users' data when testing. Use your own account and test alerts only.

Questions?

Contact security@ops-ping.com for security questions, DPA requests, or penetration testing coordination. We're happy to provide additional documentation for your security review.

Enterprise Security Questionnaire

Evaluating OpsPing for your organization? This section answers the questions we most commonly receive in vendor security assessments. Because OpsPing is in beta, several answers describe work in progress — we disclose limitations plainly so your team can make an informed risk decision.

Product Overview

OpsPing is a SaaS on-call paging and alerting product for DevOps and operations teams, consisting of a React Native (Expo) mobile application and an AWS-hosted backend. Alerts are delivered via push notifications (relayed through Expo's push service), email (Amazon SES), and optional SMS/voice (Twilio).

Data Handling

Disclosed beta limitation: channel PII (phone numbers and email addresses) is not encrypted at the application layer — it is stored in plaintext in DynamoDB, protected at rest only by DynamoDB's server-side encryption with AWS-managed keys. Application-layer encryption for channel PII is planned for a future release.

Subprocessors

We share personal data only with the subprocessors needed to operate the Service — AWS (hosting, database, and email via Amazon SES), Expo (push notification relay), and Twilio (optional SMS/voice). See the full subprocessor list for purposes, data processed, locations, and SOC 2 status. Customers are notified at least 30 days in advance of subprocessor changes, with a 14-day objection window (see our DPA).

Security Measures

Compliance Status

Incident Response

Business Continuity & Disaster Recovery

Security questions not covered here: security@ops-ping.com. This questionnaire reflects the current state of the beta product and will be updated as controls mature.