Security & Data Retention
At CriticalBuzzer, security is built into the product from day one. Whether you're monitoring infrastructure, business metrics, application events, or custom JSON payloads, we treat your data with the same level of care that we expect for our own systems.
Our goal is simple:
Your monitoring data belongs to you. We protect it, minimize unnecessary access, and never use it for purposes you haven't authorized.
Security
Security is designed into every layer of CriticalBuzzer.
Our platform follows several core principles:
- Secure by default
- Tenant isolation
- Least-privilege access
- Encryption of sensitive data
- Auditable access to AI integrations
- Continuous monitoring and logging
Every customer workspace is logically isolated, ensuring your monitoring data remains separate from every other organization.
How We Secure Your Data
CriticalBuzzer protects customer data through multiple layers of security.
Authentication
- Secure account authentication
- Strong password hashing
- Optional two-factor authentication (planned)
- Session management and secure authentication tokens
API Security
Every monitor receives a unique endpoint protected by a long, randomly generated secret.
Only requests containing the correct endpoint secret are accepted.
Unauthorized requests are rejected before entering the processing pipeline.
Tenant Isolation
Every event, alert, project, and integration is scoped to your organization.
Our architecture is designed to prevent cross-organization data access.
Audit Logging
Important administrative and AI-related actions are logged to provide accountability and traceability.
Encryption
We protect your information both in transit and at rest.
Encryption in Transit
All communication with CriticalBuzzer uses HTTPS with TLS encryption.
This includes:
- Dashboard access
- API requests
- Webhook ingestion
- MCP communication
- Notification configuration
Encryption at Rest
Sensitive configuration data such as integration credentials is encrypted before storage.
Secrets are never stored in plain text.
Password hashes are stored using modern one-way hashing algorithms.
Infrastructure
CriticalBuzzer is built using a security-first architecture.
Key infrastructure principles include:
- Multi-tenant isolation
- Environment-based secret management
- Queue-based event processing
- Stateless workers
- Rate limiting on public endpoints
- Secure configuration management
- Principle of least privilege
Large payloads may be stored separately from application metadata to improve both security and performance.
Data Retention
We collect only the information required to provide our monitoring service.
Event Data
Monitoring events are retained to:
- Display event history
- Detect anomalies
- Generate AI summaries
- Help investigate incidents
Customers may configure shorter retention periods as these options become available.
Account Data
Account information is retained while your account remains active.
If you permanently delete your account, associated customer data will be scheduled for deletion in accordance with our internal retention policies, unless we are legally required to retain specific records.
Backups
Encrypted backups are retained for disaster recovery purposes and are automatically rotated.
Privacy
Your monitoring data is your data.
We do not:
- Sell customer data
- Share monitoring payloads with advertisers
- Use your data for marketing
- Train public AI models using your monitoring data
Only authorized systems and services required to operate CriticalBuzzer can process your data.
AI Usage
CriticalBuzzer uses AI carefully and only where it provides meaningful value.
AI is primarily used to:
- Generate alert summaries
- Explain anomalies
- Interpret natural-language alert rules
- Provide contextual insights
We intentionally avoid sending unnecessary information to AI providers.
Whenever possible:
- Deterministic logic is used instead of AI.
- Only the minimum information required for the requested analysis is shared.
- AI usage is minimized to reduce both cost and data exposure.
Compliance
Security is an ongoing process.
CriticalBuzzer is designed around widely accepted security best practices, including:
- Encryption in transit
- Encryption of sensitive configuration
- Access control
- Audit logging
- Secure authentication
- Tenant isolation
- Principle of least privilege
As CriticalBuzzer grows, we intend to continue expanding our security and compliance program based on customer needs and industry standards.
Responsible Disclosure
We appreciate responsible security research.
If you discover a potential security issue, vulnerability, or privacy concern, please report it privately so we can investigate and resolve it promptly.
Please include:
- A description of the issue
- Steps to reproduce (if applicable)
- Potential impact
- Screenshots or logs where appropriate
We ask that you avoid publicly disclosing vulnerabilities until we have had an opportunity to investigate and remediate them.
Contact Our Security Team
For security-related questions or responsible disclosure reports, please contact:
Email: support@criticalbuzzer.com
We take every report seriously and aim to acknowledge security reports as quickly as possible.
Last updated: August 2026