Your DNS data, handled with care

Connecting a DNS provider means trusting us with an API token. We treat that trust as the most sensitive thing we hold — here is exactly how we protect it.

Read-only by default
For monitoring, ZoneWatcher only needs read access — and many providers support read-only API tokens we recommend using. Change Management and rollback are the only features that need write access, and only if you turn them on. Read-only setup per provider →
Credentials encrypted at rest
Provider credentials receive application-level AES-256 encryption on top of our AES-256 encrypted database — with a key that has never been stored in our codebase. They are decrypted only in memory, only while our background workers make API calls.
Payments never touch our servers
Card details are stored exclusively by Stripe, who is PCI-DSS Level 1 certified. Sensitive payment data never reaches ZoneWatcher's infrastructure.
Mapped to SOC 2 Trust Services Criteria
ZoneWatcher does not currently hold SOC 2 certification, but we operate to the same Trust Services Criteria — Security, Availability, Confidentiality, Processing Integrity, and Privacy. See our compliance guides →

Ready to protect your DNS?

Start your free trial today and get full access to all monitoring features.