Skip to main content

Public versus private monitor information

Understand which monitor fields can appear in a public status-page snapshot and which account, credential, diagnostic, and infrastructure fields remain private.

A status page is a public product surface. Anyone with the shared or custom URL can view its published information, and the browser downloads a limited public snapshot to render the page.

Search-engine noindex settings do not make this data private.

Core information made public

An enabled page can publish:

  • Page slug, title, description, brand name, logo, favicon, and colors.
  • Monitor name and monitored URL.
  • Current Up, Down, Unknown, or Paused state.
  • Latest check and status times, HTTP code, and response time.
  • Check interval and request method in the public snapshot.
  • Seven-day uptime totals and average response information.
  • Status-page verification state, without its token or evidence.
  • An enabled Google tag ID and the custom-domain indexing preference.

Google tag IDs and branding asset URLs are public by design when those features are enabled.

Optional history

The Display settings control the visible timeline, response chart, Recent History, and Incidents sections.

  • The timeline can use up to 24 bounded recent checks.
  • The response chart can use up to 10 recent response measurements.
  • Recent History can show up to 20 rows.
  • Incidents can show up to 10 recent incident summaries.

Recent check records contain time, Up or Down result, HTTP status, response time, and a customer-safe diagnosis category. Incident summaries contain start, recovery, duration, and open or resolved state.

Turning off Recent History hides its table, but a bounded check sample can still be downloaded when the uptime timeline or response chart is enabled. Turn off every check-based display section if that sample should not be included in the public snapshot.

Information that remains private

Public snapshots do not include:

  • Account name, login email, contact details, plan, invoices, or payment information.
  • Alert destination addresses, phone numbers, or delivery history.
  • Saved Basic Authentication credentials, authorization values, or custom request headers.
  • Raw check errors, response bodies, full diagnostics, or detailed check logs.
  • Full incident activity, internal notes, or administrator audit records.
  • Ownership verification tokens, verification evidence, or account verification codes.
  • Certificate identifiers, edge-distribution identifiers, or internal custom-domain infrastructure records.

The public page also does not expose private account security settings or authenticator information.

Protect sensitive target URLs

Use public status pages only for monitor targets that are safe to identify publicly. Do not put passwords, API keys, access tokens, session IDs, or other secrets in a monitored URL, path, or query string.

Even when the displayed link is simplified, the status-page snapshot is public data. Create a dedicated, non-sensitive health endpoint when the normal monitoring URL contains information visitors should not see.

Review before enabling

  1. Review the monitor name and full target URL.
  2. Review the page title, description, and branding.
  3. Enable only the public history sections your audience needs.
  4. Open the public URL in a signed-out browser.
  5. Disable the page if any published field should no longer be public.

Related articles

Did this answer your question?

Your response helps improve this Help Center.