Security

PingStep is designed to receive a small status signal, not your job’s contents.

Tokens and sign-in

Job and viewer tokens are shown once when a job is created; PingStep stores their hashes rather than the token value. Sign-in uses the connected identity provider and a session cookie. Do not put a token in source control, a ticket, or a public chat.

Data minimization

Use non-sensitive job keys and stages. PingStep does not need raw logs, command output, SQL, credentials, or files processed by the job. See the privacy page for the stored data categories.

Report a concern

If you believe a token or account may be exposed, rotate by creating a replacement job and contact mantoshk234@gmail.com with only the information needed to investigate. Do not email secrets.