๐Ÿ”ฅ Pro plan free โ€” limited timeYour APIs are failing right now and you don't know it.5 min setup ยท No credit card ยท No config files
Start catching failures โ†’
FeaturesPricingDocsBlogLog inStart free โ€” no card

Security by design

Your monitoring data is sensitive. Here is what we protect, how we protect it, and what we never collect in the first place.

How Nurbak Watch protects your data

We monitor your APIs from outside (synthetic checks across 4 regions) and from inside (instrumentation.ts). At every step, traffic is encrypted in transit, data is encrypted at rest, and the footprint is minimized to the smallest possible surface.

1

TLS 1.3 in transit

Every health check, metric upload, and alert delivery runs over TLS 1.3 with HSTS enforced. Plain HTTP is rejected.

2

AES-256 at rest

Response codes, latency samples, error rates, and account data are encrypted at rest with AES-256. Backups live in a separate encryption domain.

3

Encrypted credentials

API keys and bearer tokens used to monitor authenticated endpoints are wrapped with envelope encryption. Tokens are never stored or logged in plaintext.

Encryption standards

TLS 1.3

All traffic between your servers, our probes, our dashboard, and alert channels uses TLS 1.3. HSTS is enforced for nurbak.com and watch.nurbak.com.

AES-256-GCM

Persistent monitoring data and customer credentials are encrypted at rest with AES-256-GCM and authenticated tags.

KMS envelope encryption

Customer API keys used for authenticated checks are wrapped with KMS-managed data keys, so a database compromise alone does not expose tokens.

What we don't collect

The safest data is the data we never have. Nurbak Watch is built to know as little about your business as possible.

No response bodies

We capture status codes, headers you opt in to, and timing data (DNS, TLS, TTFB, total). The body of your API response is never read or stored.

No PII from your users

Nurbak monitors your routes, not your users. We never collect identifiers, IPs, or behavior data about people calling your APIs.

No third-party trackers

No Facebook Pixel, no ad networks, no session replay. We use first-party privacy-friendly analytics only.

Infrastructure & operations

Multi-region, EU-default

Probes run from 4 global regions. Customer data is stored in the EU by default; Team customers can pin storage to EU, US, or both.

Short retention

Detailed metrics are retained 30 days on Free, 90 days on Pro. Aggregates are kept longer; raw probe data is deleted on schedule.

No third-party tracking

No advertising trackers, no session replay tools. Operational logs are scrubbed of secrets and rotated within 14 days.

Security FAQ

Can Nurbak read my API responses?

We only inspect status codes, response headers you explicitly opt into, and timing data (DNS, TLS, TTFB, total). We do not capture or store response bodies, so the actual content your API returns to users is never visible to Nurbak.

Where is my monitoring data stored?

By default, monitoring data is stored in the EU. Team plan customers can pin storage to EU, US, or both. All data is encrypted at rest with AES-256, and backups live in a separate encryption domain.

Is Nurbak Watch GDPR-compliant?

Yes. Nurbak Watch acts as a Data Processor for the operational data you send us. We minimize data by design โ€” no end-user identifiers, no request bodies, no PII. A Data Processing Agreement is available on request.

How do you protect API keys I give you for authenticated monitoring?

Authentication tokens used to call your protected endpoints are encrypted with envelope encryption (AES-256-GCM with KMS-managed keys). They are decrypted only at probe execution time and never logged. You can rotate or revoke them from the dashboard at any time.

What happens if your servers are breached?

Encrypted-at-rest databases would expose only ciphertext. KMS keys are not stored alongside the data. We monitor for anomalies, rotate credentials on a fixed schedule, and would notify customers within 72 hours of any confirmed compromise โ€” sooner where regulation requires.

Start free โ€” no card

Health checks, latency tracking, multi-region monitoring, and instant alerts. Everything you need to keep your APIs healthy in production.

Start free โ€” no card