Security

FlatLyne sees your job names, schedules and the pings your jobs send. This page says how we protect that, and what we don't do yet.

Encryption in transit

The dashboard, the API and every ping URL are served over HTTPS.

Credentials

Every secret FlatLyne issues is a long random value generated on our servers. Secrets you only see once, such as API keys, are stored as one-way hashes, so nobody at FlatLyne can read them back. Ping URLs, which the dashboard shows you again, are stored encrypted.

Each credential does one job. A ping URL can only ping its own check. An API key works inside one project and can't do owner actions such as deleting it.

If a credential leaks

Replace it from the dashboard. On Pro and Business, regenerate a check's ping URL and the old one stops working immediately, or create a new ping key, switch your job over, then revoke the old one. On Free, upgrade, or delete the check and create a new one.

Sign-in and sessions

You sign in with Google, so FlatLyne never stores a password. Sessions live in cookies that page scripts can't read and that are only sent over HTTPS. Signing out ends the session on our side, not only in your browser.

Access between accounts

Every request is checked against project membership. A project you don't belong to looks exactly like one that doesn't exist, and an invalid ping URL looks the same whether it never existed, expired or was revoked.

What your jobs send us

Each ping records its time, source IP, user agent and a capped excerpt of the request body. We keep a limited history of recent pings per check. Don't put passwords, tokens or personal data in check names or ping bodies.

You can delete your account from account settings at any time. See the privacy policy for what we store and why.

Outgoing alerts

Webhook alerts are never delivered to private or internal network addresses, so a webhook can't be pointed at our own infrastructure.

Payments

Payments are processed by Dodo Payments, our merchant of record. Card details go to Dodo and never reach FlatLyne's servers.

What we don't have yet

FlatLyne is a small, new service. We have no SOC 2 or ISO 27001 certification, no third-party penetration test and no bug bounty. We'll update this page when that changes.

Report a vulnerability

Email [email protected] with steps to reproduce. Please give us time to fix it before you disclose it, and only test against accounts and data that are yours.