Security
Security you can actually verify.
Servbyte watches your servers, so we're careful about what we ask you to trust us with. This page describes the controls we implement today — no marketing language, no aspirational claims.
Encrypted TLS transport
The agent connects to Servbyte over TLS. All metric samples, service state, and incident payloads travel over HTTPS with modern cipher suites.
Outbound-only, unprivileged agent
The agent runs as an unprivileged systemd service. It opens no inbound ports and requires no changes to your firewall — outbound HTTPS is all it needs.
Operational-metrics-only data boundary
Servbyte collects host and service telemetry: CPU, memory, disk, network, systemd/container state, and error-log signals. It does not read your application source, request bodies, database rows, or end-user data.
Account-level access controls
Workspaces isolate hosts and dashboards. Team-plan workspaces add role-based access control (Owner / Admin / Member / Viewer) so contractors and juniors see only what they should.
Configurable retention
Raw metric retention aligns with your plan: Hobby 7 days, Pro 30 days, Team 90 days. Deleting a workspace removes its metric history from the primary store on the schedule described in the privacy policy.
PCI DSS Level 1 payment handling
All card data is handled by a PCI DSS Level 1 certified payment provider. Servbyte servers never see raw card numbers.
On certifications — plainly
Servbyte does not currently hold SOC 2, ISO 27001, or HIPAA certification. We describe only the controls we actually implement. If your procurement process requires an attested audit report today, Servbyte is likely not the right fit yet, and we'd rather say so than send you a compliance one-pager that overstates our posture.
How the agent connects
- • Installed as a systemd service under a dedicated unprivileged user.
- • Requires only outbound HTTPS (TCP/443) to ingest.servbyte.io. No inbound ports opened on your host.
- • Authenticates with a per-workspace token you can rotate at any time from the dashboard.
- • Reads host-level metrics from /proc, /sys, systemd's D-Bus interface, and the Docker socket if present. Does not read from /home, /var/lib application directories, or your source tree.
- • Buffers samples locally during a network partition and flushes them in order when connectivity returns.
Reporting a vulnerability
If you believe you've found a security issue in Servbyte, please email contact@servbyte.io with reproduction steps and, if possible, a proof-of-concept. We'll acknowledge within two business days.
Questions we haven't answered? Talk to us before you sign up.
