Status

Check whether deny.sh’s health endpoint responds from your browser. This is a current availability check, not a test of every feature. Detailed uptime history and incident subscriptions are planned.

// live

Service health

Pinged client-side against /api/health each time you load this page.

API gateway Checking...
Database Checking...
Last checked :

For programmatic checks, hit /api/health directly. Returns {"status":"ok","db":"ok"} when healthy. The endpoint is public, unauthenticated, and minimal by design (no version fingerprinting, no PM2 metadata, no uptime numbers).

// posture

Certification and review status

Cyber Essentials Certified, expires 15 May 2027 (344 days)
UK GDPR data controller Privacy policy and data-processing agreement published
SOC 2 Type II Planned; no date announced
ISO 27001:2022 Planned; no date announced
Independent cryptographic audit Planned; no date announced
Penetration test Roadmap, alongside crypto audit

Full context: /compliance · /trust.

// subprocessors

Subprocessors and data regions

Vendors that process customer data on our behalf, where they sit, and what they handle. International transfer mechanism is detailed at /privacy#international-transfers.

Subprocessor Role Region
DigitalOcean Production droplet, application hosting and storage London (LON1)
Stripe Payment processing, billing, invoicing United States (Stripe Inc.) with UK / EU presence
Resend Transactional email delivery (alerts, receipts, magic links) United States (AWS-hosted)
Cloudflare DNS only (no traffic proxying, no edge caching of customer data) Global anycast
Amazon Web Services BYOK envelope encryption (customer-opt-in only) and Secrets Manager custodian (customer-opt-in only). No deny.sh-owned AWS account holds customer data. Customer-elected AWS region
BlockMark Registry / IASME Consortium Cyber Essentials certificate issuance and registry (no customer data) United Kingdom

Subprocessor change notification today: any addition or change is announced on this page within seven calendar days. A formal RSS / email subscription for subprocessor changes is on the post-launch roadmap.

// incidents

Last incident

NONE PUBLICLY RECORDED

The open beta opened on 4 July 2026. Public incident disclosure covers the open beta onward. Incidents are recorded here with timeline, scope, customer impact, root cause, and remediation. Security findings reported via /disclosure are handled separately under coordinated disclosure.

// scope of this page

What this page is not

This page checks service health, not every customer journey. It does not currently provide multi-region uptime tracking, per-component status (encrypt, restore, audit, BYOK, SAML), historical SLA numbers, scheduled-maintenance windows, or an RSS / webhook subscription for status changes. All of that is on the post-launch roadmap. The probe above reports the health endpoint response, not an end-to-end guarantee for every feature. If you need more than that, tell us what your procurement team requires.