Security

EyeballMonitor is designed as a private system with real nodes, controlled evidence delivery and traceability.

Private execution

Nodes are not part of a shared cloud probe pool. They can be governed by policy and audited.

Secure delivery

Evidence uploads can be signed, restricted and governed by retention policies.

NDA-ready onboarding

Enterprise onboarding can include an NDA, dedicated retention rules and environment isolation.

Website security

  • TLS encryption and HSTS
  • Content Security Policy and protective HTTP headers
  • CSRF protection for forms
  • Honeypot anti-spam
  • IP-based rate limiting
  • Internal storage, cache, log and configuration paths are not publicly accessible

Responsible vulnerability disclosure

If you discover a potential vulnerability, send a description, affected URL, reproduction steps and expected impact to [email protected]. Do not include real customer data or take actions that compromise availability or confidentiality.

We will acknowledge receipt and perform a technical assessment. Please do not publish the information before a reasonable period has been provided for investigation and remediation.

Machine-readable information: /.well-known/security.txt