Skip to content
IncidentBot

Enterprise incident management software with the controls your security team asks for

IncidentBot holds some of the most sensitive operational data a company has: who is on call and how to reach them, what broke, when, and what was said while it was broken. This page describes how access is controlled, how data is protected and stored, how paging stays reliable, and what your procurement and security teams receive when you buy the Enterprise plan.

Audit log

TimeActorEvent
09:12:40Workspace adminSAML single sign-on enforced for all users
09:20:05Workspace adminEscalation policy checkout-api: tier 1 timeout 10 min to 5 min
10:02:18SCIMUser deprovisioned, removed from Payments schedule
14:12:30CommsStatus page update published: Checkout

Single sign-on with SAML

On Business and Enterprise, responders and stakeholders sign in through your identity provider with SAML single sign-on. You decide who gets in, you enforce your own multi-factor policy, and leaving the company in your directory means leaving IncidentBot.

  • SAML SSO with the identity providers enterprises already run, such as Okta, Microsoft Entra ID and Google Workspace.
  • Optional enforcement, so password sign-in is switched off for your workspace once SSO is live.
  • Session length set by your policy, not ours.

SCIM provisioning on Enterprise

SCIM keeps the user list in step with your directory. New engineers appear with the right team and role, and people who leave are deprovisioned without anyone opening a ticket. Group membership maps to teams, which is how on-call schedules stay accurate after a reorganisation.

Roles and permissions

Every plan separates responders (billed seats that can be on call and act on incidents) from stakeholder viewers (read-only, never billed). Enterprise adds advanced roles and permissions: who can edit a schedule, change an escalation policy, publish to a status page, export reports or manage integrations, scoped per team where you need it.

An audit log for every change that matters

On Business and Enterprise, the audit log records who changed what and when: schedule edits, overrides, escalation policy changes, integration keys created or revoked, role changes, status page publications and workspace settings. Entries are read-only for everyone, including administrators, and export for your own review or your SIEM.

  • Configuration changes with the before and after value.
  • Sign-ins and permission changes.
  • Status page updates, including who published them.
  • Incident timeline events, captured separately as part of each incident record.

How we protect incident data

Security practice is described here in plain terms, because a questionnaire answer should match what the product does.

  • Encryption in transit: every connection to the application, the API and the integrations uses TLS.
  • Encryption at rest: databases, backups and file attachments are encrypted at rest.
  • Least-privilege access: staff access to production is limited to the people who need it for their role, granted per task and logged.
  • Integration secrets and webhook keys are stored encrypted and shown once at creation.
  • Customer data is logically separated per workspace, and every request is authorised against the workspace it belongs to.
  • Backups are taken regularly and restores are tested.

What data IncidentBot holds

Alert payloads your monitoring tools send, on-call schedules and escalation policies, contact details used for paging (email, phone number for SMS and voice, mobile push tokens), incident records and timelines, status page content, postmortems and action items. In Slack, the bot reads messages only in the incident channels it creates or is invited to, so it can build the timeline. It does not read the rest of your workspace.

Data residency in the US or the EU

Enterprise customers choose where their workspace data is stored: in the United States or in the European Union. The choice is made when the workspace is set up and covers incident records, timelines, schedules, alert payloads and status page content.

Custom retention

By default, incident history is kept for as long as your subscription is active, because trends in incident tracking depend on it. Enterprise sets custom retention: alert payloads can be kept for a shorter period than incident records, and data past the window is deleted on schedule.

A 99.99 percent paging uptime SLA

Paging is the part of incident management software that cannot fail quietly. Enterprise contracts include a 99.99 percent uptime SLA on paging, with service credits defined in the agreement.

  • Paging does not depend on Slack. If Slack is unavailable, push, SMS, voice and email still reach the on-call engineer.
  • Escalation policies keep moving when nobody acknowledges, tier by tier, until someone does. The detail is on on-call management.
  • Your own status page is separate from the application that pages you, so an outage on one side does not silence the other.

DPA, security questionnaire and purchasing

Enterprise includes what procurement needs to sign.

  • A data processing agreement covering GDPR, with the list of subprocessors.
  • Security questionnaire completed by our team, in your format or a standard one. Our answers describe current controls as they are, and we do not claim certifications we do not hold.
  • Annual invoicing and purchase orders.
  • A dedicated success manager, onboarding, and migration from Opsgenie or PagerDuty. See the Opsgenie alternative page for the migration steps.

Questions from security reviews

Which plan includes SSO?

SAML single sign-on and the audit log are included in Business and Enterprise. SCIM, advanced roles, data residency, custom retention and the paging SLA are on Enterprise. Every plan and price is on the pricing page.

Do stakeholders need accounts with the same controls?

Stakeholder viewers sign in through the same SSO and appear in the same audit log. They are read-only and are not billed as seats.

Can we evaluate before a security review is finished?

Yes. The incident simulator demo runs in your browser on a sample scenario and needs no account and no company data, so engineers can evaluate the workflow while the review runs.

Where do we send our questionnaire?

Send it to [email protected] with the plan you are evaluating. The same address handles DPA requests and security questions.

Bring your security review

Enterprise is 398 USD per user per month, or 199 USD billed annually, and starts by card on the pricing page. Send your questionnaire and DPA request to [email protected] and the answers come back by email.

See pricing