Skip to main content

Security and compliance

We recognize that observability data can reflect critical business systems, and we handle that responsibility with care. Here's how we protect it with Pydantic Logfire, and what we're audited against.

Learn more

Trusted by the world's best engineering teams

Compliance

Built for the enterprise

Security and privacy are core to how Pydantic builds Logfire. Our commitment to security is audited and mapped to frameworks your security review expects.

Controls

Protected by design

Your data is encrypted, access is tightly controlled, and the platform is continuously monitored, regularly tested, and backed up.

Encryption

All data is encrypted in transit across internal and external networks, and at rest on the systems where it’s stored.

Access and MFA

Multi-factor authentication is required for critical services, with least-privilege access granted and reviewed at least annually.

Infrastructure

Web application and network firewalls, automated scanning, infrastructure as code, and restricted production access.

Monitoring and response

Audit logs are collected from systems and monitored, with an established incident-response policy and process.

Backups and recovery

Automated backups with recovery data isolated from production, and disaster recovery plans tested on a regular basis.

Penetration testing

Independent penetration testing at least yearly, with findings remediated. Report available on request.

Your data

Your data stays yours

Your traces can hold sensitive parts of your production systems. You decide what Logfire keeps, for how long, and what stays masked.

In transit

Encrypted from your services to Logfire.

At rest

Stored encrypted and backed up to durable storage.

In your control

Retention policies and masking, on your terms.

Report a security vulnerability

Get in touch with our team to disclose any security concerns

Contact us