Agent security
How the StatusTick private agent is kept safe inside your network: what it does, what never leaves, and what stops misuse of StatusTick or of a stolen token.
Updated 1 Oct 2026
The private agent runs inside your network and takes check definitions from StatusTick. This page sums up how it stays safe; your security team can ask us for the full threat model.
What the agent does
- Outbound only. It calls one host,
agent.statustick.com, over HTTPS, and the targets of its checks. It opens no port; StatusTick never connects to it. - Checks are data, not code. A check is a fixed set of fields (URL, method, timeout, expected text and similar). Unknown fields are dropped, a field of the wrong type refuses the check, and nothing is ever run as code or as a shell command. The browser image is the one exception you choose on purpose: it runs your own Playwright scripts.
- Results only. What leaves your network is the status, response time, HTTP status code, error text, keyword match, which expected header did not match (compared on the agent), DNS records and ping statistics. Never a response body, header values, cookies or the addresses of a page's assets.
What stops misuse
| If… | Then… |
|---|---|
| a location token is stolen | it works only for that location's checks and results. Rotate or revoke it in the dashboard; a revoked token stops on its next call. |
| StatusTick itself were compromised | STATUSTICK_ALLOW keeps the agent to the targets you list, and StatusTick cannot change it. Cloud metadata addresses are always refused unless you list them. Only result fields come back, never page content. |
| someone in your organization points a monitor at an internal host | only owners and admins change monitors, every change is in the audit log, and internal targets work only on monitors that use private locations alone. |
| someone intercepts the connection | the agent talks to StatusTick only over HTTPS and checks the certificate; extra CA files you mount only add trust for your own proxy. |
| a target misbehaves | the agent reads at most 5 MB of a response, stops at the check's timeout even while the body is still arriving, follows at most 5 redirects and checks every hop against your rules. |
Your controls
STATUSTICK_ALLOW: the only targets the agent may check, for example10.0.0.0/8,*.corp.example.- Run the agent with a read-only file system and no extra privileges; it runs as an unprivileged user.
statustick-agent doctorshows what the agent can reach, without sending data anywhere but StatusTick.