On this page
Reviewed: 4 September 2026.
Forward this summary to your reviewers
- Control plane. The EU control plane is operated by the German Datargo GmbH.
- Access. Perstat uses 6 organization roles, scoped API keys, and verified phone numbers. REST and MCP are separate access paths.
- Plan windows. Windows of 7, 30, 90, 365, or 730 days limit public history of resolved incidents and status-page uptime. They also control pruning of raw probe checks, with a 2-day technical buffer.
- Retention. Raw host-agent curves are pruned after the plan window, at most 90 days, plus a 2-day buffer. Status-page uptime is capped at the plan window, at most 365 days. The conflicting 13-month wording in the Terms still requires legal reconciliation.
- MFA and SSO. The backend supports TOTP, recovery codes, and MFA challenges. Enrollment and management UI is not available, so customers cannot self-activate MFA today. SAML SSO is not available.
- Export and documents. Manual CSV plus manifest export is available on request. Public versions of the DPA, the subprocessor list, and the technical and organizational measures are in preparation.
Check the current procurement boundaries
| Review question | Current answer |
|---|---|
| MFA / 2FA | Backend support only, customers cannot self-activate today |
| SAML SSO | Not available today |
| Encryption in transit | TLS |
| Backups | Encrypted before upload |
| Live server disks | Not encrypted at the OS layer |
| Tenant separation | Enforced in application queries |
| Row-level security | Team-chat tables only, with FORCE |
| Backup recovery | 2 EU repositories with freshness monitoring |
| Restore exercise | No documented restore exercise today |
| Account deletion | Documented and implemented, via iOS app or API |
- MFA. TOTP, recovery codes, and challenge handling exist in the backend. Enrollment and management UI is not available.
- Row-level security. Team-chat tables additionally use PostgreSQL row-level security with
FORCE. Other tenant tables do not use RLS. - Account deletion. Preview the impact, confirm it, then delete the signed-in account through the iOS app or API.
These are present-state disclosures, not certifications. Confirm the applicable state and documents through the contact page before relying on them contractually.
Datargo GmbH operates the EU control plane
The Perstat control plane runs in the EU. It is operated by Datargo GmbH, a German company.
Of the 6 probe regions, 5 are outside the EU. Those probes measure and report. They hold no customer account data.
That verified boundary concerns customer account data. It is not a blanket claim that every configured target, header, response detail, or diagnostic value is incapable of containing personal data. Procurement reviews should assess the configured data flow.
The audit trail records author and time
Relevant configuration, membership, key, and curation actions are recorded with their author and time.
Discarding a false alarm requires a reason. Perstat shows the effect on uptime before the discard happens. The discard can be reversed.
The history keeps 3 strands side by side:
- the raw timeline
- the curated outage record
- the configuration log
We do not call the store tamper-proof. We do not claim an exhaustive audit of every mutation. The narrower property is what matters here: curation interventions are attributable, reasoned, and reversible.
Roles divide duties, one-time codes verify phone numbers
Six organization roles divide duties:
- Owner
- Admin
- Responder
- Developer
- Viewer
- BillingAdmin
SMS and phone calls are sent only to numbers confirmed with a one-time code.
REST reads, MCP writes
Organization API keys carry scopes. A key can be narrowed to selected projects or monitors.
API keys read 7 REST endpoints today. REST write scopes are not evaluated. Writing is a separate MCP path.
The MCP endpoint accepts scoped organization API keys. For OAuth-capable clients, it publishes an OAuth Authorization Code flow with PKCE. A browser session cookie is not accepted as MCP authentication.
Every MCP write is attributed to the human identity behind the credential: the API-key creator or the OAuth subject. The server checks that identity’s current membership and role again on every write.
Read the API documentation and the MCP documentation.
A blocklist checks targets, agents omit full paths
By default, probe, redirect, and webhook targets are checked against the same SSRF blocklist. An explicit operator environment override can allow private webhook targets. The source code marks this override for development and local end-to-end tests.
The inventory transmitted by the host agent contains no full paths, command lines, usernames, or environment-variable values. When process monitoring is explicitly enabled, the agent transmits only process and executable basenames.
History windows depend on plan and object
Each plan sets a window. The window limits public history of resolved monitor incidents and status-page uptime, and it controls pruning of raw external probe checks.
| Plan | Plan window (days) |
|---|---|
| Free | 7 |
| Pulse | 30 |
| Sentinel | 90 |
| Command | 365 |
| Enterprise | 730 |
| Data or view | Current implementation |
|---|---|
| Public history of resolved monitor incidents | Read access limited to the plan window |
| Raw external probe checks | Physically pruned after plan window plus 2 days |
| Raw host-agent measurement curves | Plan window, at most 90 days, plus 2 days |
| Status-page uptime history | Plan window, at most 365 days |
| Other records | Object-specific lifecycle |
- Public history. The plan window limits read access. It does not automatically delete the incident record.
- Raw probe checks. The 2 days are a technical buffer on top of the applicable plan window.
- Other records. The plan window alone does not define their deletion. Some currently have no automatic expiry.
The current Terms also state a 13-month standard for measurement and event data. That wording does not match this implementation, and legal reconciliation is still open.
Treat the tables as the current technical state, not a replacement for binding terms. Review the fuller object-level explanation and request the applicable retention terms before procurement or deployment.
Request an export or exit
Evidence is exportable on request today, as CSV with a manifest. The export covers:
- monitors
- measurements
- state changes
- monitor-linked incidents
- the maintenance and exclusion windows the availability figures depend on
Manually created incidents without a monitor are not included in the current export. Self-service export is not offered today.
Use the contact page for a current export or exit request.
Sign in with email and password or Apple
Sign-in today supports email and password as well as Sign in with Apple on the web and iOS.
Enterprise SSO (SAML) is not available.
We monitor ourselves
Perstat runs on Perstat. Our status page, status.perstat.io, is produced by the same measurement pipeline we sell. It is the product, pointed at itself.
The founder holds personal qualifications
The founder holds CISSP, CCSP, and ISSAP personally. These are personal qualifications, not certifications of Perstat or Datargo GmbH.
Ask about procurement documents
Public versions of the data processing agreement (DPA), the subprocessor list, and the technical and organizational measures are in preparation.
Ask for their current status or a specific security review through the contact page.
Report a vulnerability
Report security vulnerabilities to security@perstat.io. This address is reserved for responsible disclosure.
Use the contact page for procurement and product-security questions.