PYLONMON

Security & trust

The monitoring service you trust to watch your systems has to be worth trusting itself. This page is how PylonMon is built and operated, in enough detail for a security review — every item is a live property of the service, not a roadmap slide. Need it as a document? Request the security packet.

Architecture

PylonMon is one static Go binary, run as an active-active pair behind a load balancer, backed by a managed PostgreSQL service, with an independent prober in a second region. Nothing in the path is shared with any other product, and nothing runs inside your network unless you install the open-source agent.

            YOUR INFRASTRUCTURE
     endpoints · hosts · cron jobs · logs
          │ (outbound only)  │ (we poll)
          ▼                  ▼
   pylon-beacon ──────▶  PylonMon app nodes  ◀──── second-region prober
   (open source, MIT)     us-west, active-active     us-east, stateless
                          behind a load balancer     confirms outages
                                  │
                                  ▼
                          managed PostgreSQL
                          state · rollups · logs (separate database)
                                  │
                                  ▼
                          alert delivery
     email · SMS · voice · Slack · Teams · Discord · webhooks · PagerDuty · push

Where data lives

Accounts & access

Operations

Backups & continuity

Incident response

Subprocessors

The third parties that handle customer data on our behalf, what they see, and where. We keep this list current; if you need notice of changes, ask under the security packet below and we will add you to it.

ProviderPurposeData it handlesRegion
Akamai Cloud (Linode)Hosting: application nodes, load balancer, managed PostgreSQLAll service dataUS West (Fremont), US East (Newark, prober only)
StripeBillingBilling contact, card details (never seen by PylonMon)United States
ResendTransactional email (alerts, sign-in codes, reports)Recipient address, message contentUnited States
TwilioSMS and voice alerts; email fallback lanePhone number or address, alert textUnited States
GoogleOptional sign-in (OIDC)Email address at sign-inUnited States
Your chosen channelsSlack, Teams, Discord, PagerDuty, Telegram, ntfy, webhooks — only if you add themAlert text sent to the endpoint you configuredYours

Vulnerability disclosure

If you find a security issue in pylonmon.com, the API, or pylon-beacon, tell us at security@pylonmon.com — reports land in front of an engineer. We also publish /.well-known/security.txt.

Compliance

PylonMon is not SOC 2 audited yet, and we will not claim otherwise. The controls a SOC 2 review looks for — access scoping, MFA, audited changes, backups, encryption in transit, incident handling, vendor inventory — are the ones described on this page, and we will walk your security review through them directly. A SOC 2 Type I engagement starts when a customer needs it as a condition of contract.

Request the security packet

Email security@pylonmon.com with the subject "Security packet" and we will send, within two business days: this page as a dated PDF, our answers to the common security questionnaires (SIG Lite / CAIQ style), the architecture diagram, the subprocessor list, our data processing agreement, and our incident-response and backup summaries. An engineer joins a video call on request.

Start monitoring free →