Security
deployhealth looks at your code's configuration and at your clients' servers, so here is exactly what it stores, what it does, and how to reach us. The code is public, so you can check every claim below.
What we store
- Variable names and file:line, never values. For each deploy: the commit sha, branch and time, and for each finding the variable name, the file and line that reads it, and the env file involved, plus the names each env file defines. The scanner runs in your CI and reads env files only for their names; the ingest API accepts only names, paths and line numbers.
- Findings per deploy (missing, unused, out of sync), so you can see what changed.
- Endpoint URLs you add, with their names and settings, and for each check its time, status code, latency and a short error reason. Raw checks are deleted after 30 days; daily totals are kept for monthly reports.
- Alerts (when they opened and resolved, and the message) and your alert webhook URL. Webhook URLs contain secrets, so logs show only their host.
- Ingest tokens only as a SHA-256 hash. The token itself is shown once, when it's created.
- Your account: your GitHub id, login, name, public email and avatar URL, from GitHub sign-in. Sign-in asks GitHub for your profile only, not for access to your repositories. Clients, deploy notes and contact emails are what you type in.
How checks run
- One request per check (GET or HEAD) with a 10-second budget, following at most 5 redirects.
- SSRF-guarded. A URL must be public http(s): no credentials, no private, loopback, link-local or otherwise reserved addresses. That's checked when you save it, and again at connect time for every redirect hop, which also defeats DNS rebinding. Alert webhooks go through the same guard.
- Response bodies are never read or stored: only the status code and timing.
- A hostname is checked at most once every 10 seconds, however many accounts monitor it, and an account can monitor at most 500 endpoints (100 per project). deployhealth can't be used to flood a server.
How share links work
A monthly report's share link isn't stored anywhere: the link itself carries the client, the month and an expiry date 90 days out, signed with HMAC-SHA256 using a key only the server has. Anyone with the link can read that one report until it expires, and nothing else; changing any part of it breaks the signature. Links can't be revoked one by one: rotating the key revokes all of them at once. Shared pages are rate-limited per IP address and ask search engines not to index them.
Report a vulnerability
Please report security issues to a private security advisory on GitHub, not in a public issue. Include what you found and how to reproduce it. Testing against your own account and your own endpoints is welcome; please don't access other people's data or degrade the service.
Machine-readable: /.well-known/security.txt.
Our commitment
If a security incident affects your data, we will email every affected user within 72 hours of confirming it, at the email address on their GitHub account, saying what happened, which data was involved, and what we are doing about it.