What UPKira refuses to call.
A monitor target is an address you control, and it is also an address our workers will fetch. The guards below are how that fetch is constrained.
Which controls are in the product?
| Area | Behavior |
|---|---|
| Probe targets | Every outbound request to a URL you supply passes an SSRF guard, including redirects. Link-local, loopback, private, and cloud metadata addresses are refused. |
| Private-target switch | A test-only flag can allow private addresses. It is refused when the process is running in production. |
| Monitor secrets | Authorization headers and notification secrets are encrypted with AES-256-GCM before they are stored. Logs and error text are redacted. |
| Heartbeat tokens | The token in the ping URL is stored only as a SHA-256 hash. Rotating it revokes the previous hash. |
| Webhooks | Generic webhook deliveries are HMAC-signed. The signing secret is stored encrypted, not in the channel's plain config. |
| Accounts | Passwords are stored as scrypt hashes. A session cookie is set only after the email address is verified, and that cookie is HttpOnly. Verification links are signed and expire after one hour. Password reset links expire after one hour, work once, and sign out other sessions. Those links are not written to logs. Sign-up, sign-in, and reset attempts are rate limited in memory inside each web process. The limit is not tied to a client address until a trusted proxy is configured, and it is not shared across processes. |
| Workspace roles | Roles are owner, admin, member, and viewer, with owner above admin above member above viewer. An owner cannot be invited. Workspace routes enforce that order. Someone outside the workspace gets the same response as a missing record. |
| Retention | A probe may read at most 64 KiB of a decompressed response to evaluate a match. The stored row is the outcome, status, timing, and a short redacted error. The body is not stored. |
This page describes controls that exist in the codebase. It is not a certification, a penetration-test report, or a promise about a hosted environment that is not running yet. Report a vulnerability to hello@upkira.com.