Skip to main content
For Security & Compliance

Monitoring that pulls its weight in the audit binder.

Continuous SSL/TLS and availability checks with an in-app audit log, encrypted-at-rest integration credentials, and clean evidence exports your audit team can hand straight to the assessor.

SOC 2
Type II program
ISO 27001
Programme
AES-256-GCM
Credentials at rest
365 d +
Audit log on Enterprise
By role

What you get with AlertifyPro

Continuous SSL/TLS monitoring

Every HTTPS check opportunistically harvests certificate details. Expiry alerts, chain visibility and a dedicated SSL certificates view across the workspace.

Audit log with per-event detail

Every configuration change, permission grant, and incident action is recorded with actor, target, and diff. Expandable rows in the dashboard for forensic review.

Owner / admin / member RBAC

Role assignment with per-resource permissions. Custom RBAC roles available on Enterprise. Every API call carries tenant scope as a row-level filter.

Compliance evidence on request

SOC 2 Type II report, ISO 27001 certificate, DPA and pen-test summaries available through the security contact. We sign your paper, not the other way around.

Cert-tampering and downgrade alerts

Alert on cert change, expiry windows and unexpected TLS downgrades — paged separately from availability so security and SRE don't compete for the same channel.

Self-hosted for residency control

If your security model requires data stays in-house, run the same four backend services as Docker images in your own environment.

SAML 2.0 / OIDC SSO + SCIM 2.0

Per-org SAML (crewjam/saml) or OIDC discovery against Okta, Azure AD, Google Workspace, OneLogin and JumpCloud. SCIM 2.0 user lifecycle provisioning on Enterprise. TOTP MFA + org-wide enforce-MFA on Pro+.

Tenant isolation & per-region residencyRoadmap

Pin a workspace to EU, US or APAC regional infrastructure. Tenant isolation reviewed and documented for customer security questionnaires.

Hash-chained immutable audit logRoadmap

Append-only audit log with hash-chaining for tamper evidence. Configurable retention up to 7 years on Enterprise — built for SOX, PCI and ISO long-tail evidence.

Customer-managed keys via KMS (BYOK)Roadmap

Bring your own encryption key through AWS KMS, GCP KMS or Azure Key Vault. Rotate on your schedule; revoke to render data unreadable.

Built for the controls your auditor asks about

Whether you're prepping for SOC 2 Type II, renewing ISO 27001 or fielding a customer security questionnaire, AlertifyPro produces the evidence in the format auditors expect.

  • CC7.2 monitoring evidence — coverage + alerts mapped
  • A.12.4.1 event logging — audit log export with full detail
  • Continuous SSL/TLS monitoring across every HTTPS surface
  • Per-tenant scoping recorded on every API call
  • DPA published; BAA available for healthcare customers
  • SAML 2.0 / OIDC SSO + SCIM 2.0 user lifecycle
  • Hash-chained tamper-evident audit log, 7-year retentionRoadmap
  • Customer-managed encryption keys via AWS / GCP / Azure KMSRoadmap

Audit export · last 24h

23:59:01user.login[email protected] · ok
23:14:30monitor.updatedcheckout-api · diff recorded
22:01:08role.assignedapprover: [email protected]
21:48:22integration.createdpagerduty · creds encrypted

Outcomes our customers see

Cleaner audits
Evidence on hand
Audit log export and SSL cert history pulled straight from the dashboard.
Zero plaintext
Integration creds at rest
AES-256-GCM encryption for every stored credential.
0 cert surprises
Continuous TLS check
Median across customers who add SSL monitors to every HTTPS surface.
The audit-log export and the SSL cert history saved us about three weeks of manual evidence gathering. The credentials-at-rest model passed our security review on the first pass.
Dana R.Head of Security & Compliance, SaaS

Frequently asked

Ready to see it on your stack?

Spin up your first monitor in under a minute. Free forever for the first 5 services.