Data classification

Telemetry and Usage Data

Telemetry includes application logs, performance metrics, error traces, session recordings, and usage analytics. While often treated as low-sensitivity, telemetry can contain incidentally captured PII, credentials, and business logic.

Risk profile

Telemetry data is underestimated as a risk vector. Error traces frequently contain stack traces with database query content. Session recordings can capture form inputs. Log aggregation platforms receive everything you emit — including secrets if logging is not carefully controlled.

Applicable frameworks

SOC 2GDPRISO 27001

Example vendors

DatadogSentryNew RelicFullStory

Common questions

Does FullStory or Hotjar capture passwords and form inputs?
Both FullStory and Hotjar have input masking features that prevent capturing sensitive fields. Whether this masking is applied correctly in your implementation requires a technical review. By default, masked elements must be explicitly configured — they are not masked automatically.

Which of your vendors handle Telemetry and Usage Data?

TrustVendor tracks data class exposure across your entire vendor portfolio and computes residual risk per relationship.

Book a demo