How OKStatus handles data retention and communicates incidents — to help you meet your own compliance requirements (SOC 2, ISO 27001, DORA, NIS2).
No plan has unlimited retention: beyond the window covered by your plan, the oldest data is automatically deleted — consistent with GDPR's data minimization principle. An extended option (24 months) may be offered as an add-on on the Max plan — not available yet.
OKStatus automatically detects outages through continuous monitoring (multi-region HTTP/TCP/DNS checks) and triggers alerts to your team. An incident follows a documented, timestamped cycle — investigating → identified → monitoring → resolved — each step attributed to the team member who performed it. Automated monitoring doesn't catch everything: every public status page can also offer a "Report an issue" form, which the organization can disable if needed.
Every incident update appears immediately on your public status page.
Your users choose how to follow updates, no account needed.
Maintenance windows are announced ahead of time, not discovered live.
External incident communication, documented retention, timestamped history — heading in that direction, not a certification obtained today.
Same product roadmap as SOC 2 — a direction, not yet a certification.
OKStatus isn't your regulatory reporting body (the 4h/24h/72h deadlines are filed with your competent authority), but severity classification, timestamping and a designated external communication channel help you meet your own obligations.
A Data Processing Agreement tailored to your compliance needs, and a team reachable for any security question — contact@clearcloud.fr
See the DPA page