Security

Last updated: August 2026

1. Where your data lives

CaneCron is built and operated from Estonia. All data is stored on Hetzner servers in Helsinki, Finland — inside the European Union. Your data never leaves the EU for processing.

2. Encryption

All traffic to and from CaneCron is encrypted in transit with TLS. We monitor our own certificates using CaneCron itself — the same SSL expiry monitoring that is available to every customer.

3. Account security

Passwords are hashed with bcrypt and never stored in plain text. Two-factor authentication (TOTP) is available on every account, free and paid. Each account includes a security log showing login attempts, devices, and IP addresses — exportable to CSV for your own audits.

4. Payments

All payments are processed by Stripe. Your card details never touch our servers.

5. Private network monitoring

The CaneCron agent only ever makes outbound connections from your network — we never need inbound access, and you never open a port for us. Agent authentication uses two keys: an API key that identifies the monitor, and a secret key that is shown once and stored only as a hash.

6. Data retention & deletion

Monitor history is retained according to your plan — from 30 days on the free plan up to 2 years on Business. When you delete your account, your data is removed within 30 days. Full details are in our Privacy Policy.

7. What we don't do

We don't sell your data. We don't use tracking or advertising cookies — only essential session cookies required for login. We collect only what the product needs to work.

8. Certifications

We don't currently hold SOC 2 or ISO 27001 certification — audits at that level are ahead of where a product our size honestly is. If your organisation has specific compliance requirements, talk to us.

9. Reporting a vulnerability

Found a security issue? Email support@canecron.com and we'll respond as quickly as we can. We appreciate responsible disclosure and will credit you if you'd like.