Privacy Policy
Privacy Policy
Effective date: April 7, 2026 · Last updated: April 7, 2026
Overview
Seismograph is a managed SRE platform that monitors your infrastructure endpoints, SaaS dependencies, and deployment activity. This policy explains what data we collect, how we use it, and how we protect it.
We collect only what is necessary to provide the service. We do not sell your data. We do not share your data with third parties except as required to operate the service.
What We Collect
Infrastructure Monitoring Data
When you onboard with Seismograph, you provide:
- ✓Endpoint URLs you want monitored
- ✓Expected response codes and performance thresholds
- ✓SaaS vendor dependencies your endpoints rely on
- ✓GitHub repository webhook configurations
We collect the following through active monitoring:
- ✓HTTP response codes and latency (TTFB) for your declared endpoints
- ✓DNS resolution times for declared dependencies
- ✓Deployment metadata from GitHub webhook events (commit SHA, branch, author name, commit message, repository name, timestamp)
Account Data
- ✓Your name and email address
- ✓Your company name
- ✓Communication history with [email protected]
Website Data
When you visit seismograph.ai:
- ✓Standard web server logs (IP address, browser type, pages visited, timestamps)
- ✓No tracking pixels, no advertising cookies, no third-party analytics
What We Do Not Collect
- ✓We do not collect the contents of your API requests or responses
- ✓We do not collect authentication tokens, passwords, or session data from your endpoints
- ✓We do not collect user data from your application or your customers
- ✓We do not store full API keys — only references to secrets stored in AWS Secrets Manager
- ✓We do not use cookies for tracking or advertising
How We Use Your Data
We use collected data exclusively to:
- ✓Monitor your declared endpoints and report their health status
- ✓Detect degradation and generate alerts
- ✓Correlate your endpoint failures against global infrastructure signals
- ✓Identify deploy-related incidents via GitHub webhook data
- ✓Deliver hourly health snapshots and incident alerts to your designated Slack channel
- ✓Improve detection accuracy over time using aggregated baseline data
Data Retention
| Data type | Retention period |
|---|---|
| Probe results (TTFB, status codes) | 30 days |
| Alert records | 7 days |
| Baseline statistics | 30 days rolling |
| Deploy records (GitHub webhook) | 7 days |
| Global infrastructure snapshots | 1 hour |
| Account data | Duration of engagement + 90 days |
Data is automatically deleted after the retention period via AWS DynamoDB TTL.
Data Storage and Security
All data is stored on AWS infrastructure in the us-east-1 region (Northern Virginia).
- ✓Encryption in transit: TLS 1.2 or higher for all data transmission
- ✓Encryption at rest: AWS KMS encryption for all DynamoDB tables
- ✓Access control: Client dashboards protected by Cloudflare Access with per-client policies
- ✓Secrets management: API keys and credentials stored in AWS Secrets Manager — never in code or logs
- ✓Data isolation: Each client's data is logically isolated. Client A cannot access Client B's data.
Cross-Client Signal Aggregation
- ✓When multiple clients declare the same vendor dependency and experience simultaneous endpoint failures, Seismograph infers a vendor-wide incident with higher confidence
- ✓This aggregation uses only anonymized signal data (degradation counts, timestamps, vendor names) — never client identity, endpoint URLs, or any client-specific information
- ✓No client can see another client's data, endpoints, or alerts
Third-Party Services
Seismograph uses the following third-party services to operate:
| Service | Purpose | Data shared |
|---|---|---|
| AWS (Lambda, DynamoDB, API Gateway, Secrets Manager) | Infrastructure | All monitoring data stored here |
| Cloudflare | CDN, Access control, Email routing | Web traffic, access authentication |
| AI API provider | AI-powered incident diagnosis | Alert context (anonymized signal data, no client PII) |
| Infrastructure intelligence provider | Global infrastructure signals | No client data — read-only public API |
| GitHub | Webhook delivery | Deploy metadata you send via webhook |
| Slack | Alert delivery | Alert content you configure |
We do not use advertising networks, data brokers, or analytics platforms.
Your Rights
You have the right to:
- ✓Access your data — request a copy of all data Seismograph holds about you
- ✓Correction — request correction of inaccurate data
- ✓Deletion — request deletion of your data at any time
- ✓Portability — receive your data in a structured, machine-readable format
- ✓Objection — object to specific uses of your data
To exercise any of these rights, email [email protected]. We respond within 5 business days.
Data Deletion
When your engagement with Seismograph ends:
- ✓All monitoring data is deleted within 30 days
- ✓Account data is deleted within 90 days
- ✓Baseline statistics are deleted within 30 days
- ✓GitHub webhook configurations should be removed from your repositories
To request immediate deletion of all data, email [email protected] with subject line "Data Deletion Request."
GDPR
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- ✓Legal basis for processing: Contractual necessity (to provide the monitoring service you have engaged us for)
- ✓Data controller: Seismograph ([email protected])
- ✓Data transfers: Data is stored in AWS us-east-1 (United States). We rely on standard contractual clauses for any EEA data transfers
- ✓Supervisory authority: You have the right to lodge a complaint with your local data protection authority
Changes to This Policy
We will notify you of material changes to this policy via email to your registered address at least 14 days before changes take effect. The current version is always available at seismograph.ai/privacy.
Contact
For privacy questions or requests:
Email: [email protected]
Response time: Within 5 business days
Seismograph is a product of Seismograph AI. © 2026 Seismograph. All rights reserved.