← Trustpack

A real sample security pack

Public-source specimen: Healthchecks.io. An independent demonstration generated from public Healthchecks.io documentation. Healthchecks.io did not provide or endorse this sample.

This is the exact artifact produced by the production generation engine, validator gate, and customer rendering. The public-source prompt mode uses third-person language and an independent provenance line instead of claiming the specimen supplied an attestation. Nothing here is staged or hand-edited.

Method: Public-source review of the hosted service and its open-source repository; each cited page was fetched successfully before the production generation pipeline ran. No private access or vendor questionnaire responses were used.

Scope: Healthchecks.io hosted-service controls documented on the cited pages as of 2026-08-28. Unpublished controls are labelled “not evidenced,” not treated as absent.

Sources reviewed on 2026-08-28:

Healthchecks.io — Security & Trust

Based on public information about Healthchecks.io reviewed on 2026-08-28. Independent Trustpack demonstration; not provided or endorsed by Healthchecks.io, and not an audit or certification.


Overview

Healthchecks.io is an open-source hosted service that monitors cron jobs and scheduled tasks. The service is operated by a one-person team. Its security posture reflects that scale: controls are specific and documented where they exist, and this page identifies areas where public evidence was not found.


Infrastructure & Hosting

Healthchecks.io runs on Hetzner bare-metal servers located in Germany. Customer data does not leave Germany at rest except for encrypted off-site backups (see Data Protection). Hetzner states ISO 27001 certification for its own infrastructure; no equivalent certification was evidenced for Healthchecks.io itself. Inter-server traffic is protected with WireGuard. Client-to-server traffic uses HTTPS.

A PostgreSQL hot standby is documented, and database failover is performed manually. No separate disaster-recovery runbook was evidenced in the reviewed public sources. Service availability is tracked at the public status page: https://status.healthchecks.io/


Data Protection

Data categories stored: account email address and optional password, billing and contact information, notification-service credentials, support messages, browser and server logs, IP address, device and referral data, time zone, and customer-supplied check data.

Encryption in transit: HTTPS for client-to-server traffic; WireGuard between servers.

Encryption at rest: Primary database data is not encrypted at rest. Off-site database backups are GPG-encrypted; subprocessors do not hold the encryption key. Encrypted backups are stored on Amazon Web Services.

Backups: Daily GPG-encrypted PostgreSQL backups are stored off-site. Deleted information may remain recoverable in those backups for up to 2 months.

Data deletion and retention: Customers can close their account at any time. Inactive accounts are closed after 1 year, preceded by a 30-day notice. Deleted information may remain in database backups for up to 2 months.

Data export: Customers may request access and portability under the privacy policy. Project and check data are also accessible through the documented API.

GDPR: The privacy policy supports access, correction, deletion, processing restriction, objection, and portability requests. Affected customers are notified without undue delay following a breach; supervisory authority notification occurs within 72 hours where required. A published Data Breach Policy covers reporting, containment, investigation, customer notification, remediation review, and a public incident report.


Access & Authentication

Customers sign in with an email address and an optional password. The open-source codebase also documents WebAuthn two-factor authentication for customer accounts. The public FAQ identifies a one-person operations team with access to production systems. No more granular production-access policy was evidenced in the reviewed public sources.


Monitoring & Vulnerability Management

The privacy policy states that regular vulnerability monitoring is performed. The public repository security policy directs vulnerability reports to contact@healthchecks.io. The BSD-licensed source code and full change history are publicly available at https://github.com/healthchecks/healthchecks. Browser, device, server, IP-address, referral, access-time, and operating-system logs are documented in the privacy policy; a retention period for those logs was not evidenced.


Subprocessors

NamePurpose
HetznerHosting and primary data storage
Amazon Web ServicesEncrypted off-site database backups
TwilioSMS and WhatsApp notification delivery
BraintreePayment processing
FastmailEmail hosting

Current Posture & Public-Evidence Gaps

Documented in the cited public record:

  • Hetzner bare-metal hosting in Germany with Hetzner's stated ISO 27001 certification
  • HTTPS and WireGuard encryption in transit
  • Daily GPG-encrypted off-site backups with 2-month recoverable retention window
  • PostgreSQL hot standby with documented manual failover
  • Customer WebAuthn two-factor authentication
  • Published Data Breach Policy with 72-hour supervisory notification commitment
  • GDPR data-subject request support
  • Public source code at GitHub

Not evidenced in the reviewed public record:

  • Healthchecks.io security certification (SOC 2, ISO 27001, or equivalent)
  • Staff two-factor authentication enforcement
  • Customer SSO
  • Staff endpoint security controls
  • Third-party penetration test
  • Log retention period
  • Cyber-liability insurance

Contact

Security questions, vulnerability disclosures, and data-subject requests should be directed to contact@healthchecks.io.

Build my security pack — $49 →Browse the answer guides