Security

We do not list certificates we do not hold. We list controls you can check.

Controls

Access control and sessions

Accounts belong to people, not shared mailboxes. Roles separate ownership, billing, and member access per organization. Sessions are server-side and revocable. Two-person review applies to production changes.

Data retention

Availability history is retained per plan: 7 days (Free), 30 days (Pulse), 90 days (Sentinel), 1 year (Command), 2 years (Enterprise). Retention windows are the same windows your availability record draws from; there is no separate marketing math.

Data export and exit

Your records are yours. Availability evidence is exportable on request today; self-service export is the stated next step. If you leave, we do not hold your data hostage: request a final export, then we delete. Ask us at hello@perstat.io and you will get a concrete answer, not a runaround.

SSO status, honestly

Sign-in today is email-based with our own identity service. Enterprise SSO (SAML) is not available yet. If SSO is a hard requirement for your policy, tell us; that conversation shapes the roadmap.

Certifications, honestly

Perstat does not currently hold ISO 27001 or SOC 2. We would rather tell you that than imply otherwise with borrowed badge walls. The founder holds CISSP, CCSP, and ISSAP personally, and the controls above are written so you can verify them in conversation with us.

Data protection

GDPR applies to everything we do. A data processing agreement (DPA) you can sign, a current subprocessor list, and our technical and organizational measures are available on request today and will be published on this page as downloads. Until then, request them by email: hello@perstat.io.

Responsible disclosure

Found a vulnerability? Write to security@perstat.io. We answer, we fix, and we credit you if you want to be credited.