Vendor category

Observability vendors

Observability vendors — APM, log management, distributed tracing, and error monitoring tools — have access to application telemetry that frequently contains incidentally captured PII, database query content, and in some cases, credentials.

Risk profile for this category

High data sensitivity (logs and traces often contain PII), high integration depth (agents run in production environments), and broad subprocessor footprint (typically use cloud storage for log retention). Require SOC 2 Type II and clear data retention and deletion commitments.

Sample vendors in this category

Datadog

datadoghq.com

SOC 2 Type II, ISO 27001. 40+ subprocessors.

View profile →

New Relic

newrelic.com

SOC 2 Type II, FedRAMP Moderate.

View profile →

Sentry

sentry.io

SOC 2 Type II. Open-source self-hosted option.

View profile →

This is a sample of vendors in this category. Search the full TrustVendor graph for comprehensive coverage including posture scores, certifications, and subprocessor counts.

Search all Observability vendors →

Common questions

Do observability vendors see my users' personal data?
Potentially yes. Application logs and error traces often capture request parameters, headers, and database queries that contain PII. Review your logging configuration and ensure PII scrubbing is in place before connecting an observability vendor.
Should I use a self-hosted observability solution to reduce third-party risk?
Self-hosting reduces vendor risk but increases operational complexity. For most organizations, a SOC 2-compliant vendor with appropriate DPAs and data scrubbing configuration is a better tradeoff than running self-hosted observability infrastructure.

Monitor your Observability vendors.

Get continuous posture scores, subprocessor monitoring, and certification tracking for every Observability vendor in your portfolio.

Book a demo