Security & Data Protection
This is a trust page, not a legal warranty. It explains how we approach security in delivery and operations. Certifications appear only when we can show evidence.
Last updated 14 July 2026
Security-first approach
Access, change, and recovery are designed into delivery, not bolted on after launch. We favour least privilege, clear ownership, and boring, repeatable controls.
Encryption
Data in transit is protected with modern TLS where systems are under our control. Sensitive data at rest is encrypted according to the hosting and product architecture in scope.
Backups
Backup design follows the workload: what must be recoverable, to what point, and who verifies restores. A status light is not treated as proof.
Infrastructure
Environments are segmented with deliberate network and identity boundaries. Patching and monitoring expectations are defined per engagement.
Responsible disclosure
If you believe you have found a vulnerability in an UptimeSphere system or product, report it privately so we can investigate and remediate before public detail.
Business continuity
Continuity planning covers people, access paths, and recovery steps for critical services, sized to the engagement, not to a generic checklist.
Reporting vulnerabilities
Please email security@uptimesphere.com with enough detail to reproduce the issue. Do not include customer personal data in the initial report unless necessary.
- We acknowledge reports when received during business hours.
- We prioritise issues that affect confidentiality, integrity, or availability of production systems.
- Please allow time for investigation before public disclosure.
Security-first approach
We design for least privilege, clear ownership, monitored change, and recovery that can be practiced. Controls are matched to the risk of the workload, not copied from a generic checklist for show.
Encryption and backups
- TLS for data in transit on systems under our control.
- Encryption at rest according to platform and engagement design.
- Backup scope and restore verification defined for critical data.
Infrastructure
Environments use intentional network and identity boundaries. Patching and monitoring cadence is agreed per engagement and reviewed as systems change.
Reporting vulnerabilities
Email security@uptimesphere.com with steps to reproduce. Avoid including unnecessary personal data. We acknowledge reports during business hours and prioritise issues that affect production confidentiality, integrity, or availability.
Business continuity
Continuity covers access paths, escalation contacts, and recovery steps for services we operate. Depth scales with the criticality of the engagement.
Certifications and attestations
We do not list certifications we have not earned, when formal attestations are obtained, they will appear in our compliance registry with dates and scope.