Skip to main content

Security and compliance

Observability data can reflect critical business systems. See how Pydantic Logfire protects it, what our controls cover, and the evidence available for your review.

Learn more about Pydantic security and compliance

Trusted by the world's best engineering teams

Compliance

Built for the enterprise

Security and privacy are core to how Pydantic builds Logfire. Our commitment to security is audited and mapped to frameworks your security review expects.

Type 2 audited

SOC 2 Type 2

Independently audited controls for security, availability, and confidentiality.

Compliant

GDPR

Aligned with EU and UK data protection requirements, with a Data Processing Addendum available.

Compliant · BAA available

HIPAA

Configured to support protected health information under a signed Business Associate Agreement.

Controls

Protected by design

Sensitive data is encrypted at rest, access is tightly controlled, and the systems behind Logfire are monitored and regularly tested.

Encryption

Data is encrypted in transit across internal and external networks. Sensitive data is encrypted at rest on the systems where it is stored.

Access and MFA

MFA protects administrative access to critical systems and supported external applications. Least-privilege access is approved and reviewed at least annually.

Infrastructure

Web application and network firewalls, automated scanning, infrastructure as code, and restricted production access.

Monitoring and response

Audit logs are collected from systems and monitored, with an established incident-response policy and process.

Backups and recovery

Automated backups with recovery data isolated from production, and disaster recovery plans tested on a regular basis.

Penetration testing

Independent penetration testing at least every 12 months, with findings remediated. The latest report is available on request.

95 controls, organized for review

Open any category to see the controls mapped across Pydantic's compliance program.

Reviewed
Access control Least-privilege approvals, regular reviews, revocation, MFA, and password safeguards. 9
  • Access granting process used
  • Access requests to sensitive data required
  • Access requests to sensitive infrastructure required
  • Access revoking process enforced
  • Automated decision-making and profiling has oversight
  • Employee access regularly reviewed
  • MFA required for administrative access
  • MFA required for applications
  • Password management policy enforced
Data management Encryption, classification, retention, masking, transfer safeguards, and privacy processes. 12
  • Consent for collecting and managing data obtained
  • Data encrypted at rest
  • Data encrypted in transit
  • Data inventory maintained
  • Data labeled by sensitivity level
  • Data management and retention policy established
  • Data masking procedures used
  • Data processing integrity and output validated
  • Data transfer mechanisms established
  • External privacy inquiries managed
  • Privacy disclosure and notification mechanisms established
  • Privacy policy created and maintained
Disaster recovery Automated backups, isolated recovery data, documented continuity, and tested recovery plans. 5
  • Automated backups enabled
  • Business continuity and disaster recovery policy established
  • Data recovery process established
  • Disaster recovery plans tested
  • Recovery data isolated
Email security Domain authentication, restricted account access, and malicious-content protections. 3
  • DMARC policy and verification used
  • Email account access restricted
  • Email settings block malicious content
Endpoint security Anti-malware, device encryption, and firewalls on end-user systems. 3
  • Anti-malware deployed on end-user devices
  • Data encrypted on end-user devices
  • Firewall maintained on end-user devices
Infrastructure security Reviewed infrastructure-as-code changes, continuous updates, scanning, and layered network controls. 12
  • Anti-malware deployed on infrastructure
  • Automated security scanning performed on infrastructure
  • Buckets not exposed publicly
  • Configuration management system established
  • Firewall restricts public access to infrastructure
  • Infrastructure changes logged
  • Infrastructure changes require review
  • Infrastructure deployed using an infrastructure-as-code tool
  • Network infrastructure continuously updated
  • Production deployment access restricted
  • Unique production database authentication enforced
  • Web Application Firewall (WAF) used
Monitoring & response Centralized audit logging, infrastructure monitoring, breach notification, and response exercises. 9
  • Adequate audit log storage maintained
  • Audit log management process maintained
  • Audit logs collected
  • Breach notification process established
  • Incident response exercises performed
  • Incident response policy established
  • Infrastructure performance monitored
  • Log management used
  • Network infrastructure monitored
Organizational security Security governance, workforce practices, training, vendor oversight, and a controlled development lifecycle. 34
  • Acceptable use policy established
  • Asset management policy established
  • Code of conduct acknowledged by contractors
  • Code of conduct acknowledged by employees
  • Code of conduct established
  • Company security commitments externally communicated
  • Confidentiality Agreement acknowledged by contractors
  • Confidentiality Agreement acknowledged by employees
  • Contact with authorities established
  • Data-flow diagrams maintained
  • External support resources available (for example, documentation)
  • Information security program established
  • Internal documentation maintained
  • Internal privacy policies established
  • Internal security audit performed
  • Offboarding process established
  • Onboarding process established
  • Performance evaluations conducted
  • Physical access restricted
  • Physical security policy established
  • Policy for compelled disclosure from law enforcement established
  • Reference calls performed for employees
  • Roles and responsibilities specified
  • Sanction policy established
  • Scope for compliance framework established
  • Security awareness training conducted
  • Security official assigned
  • Service description communicated
  • Software development lifecycle established
  • System changes externally communicated
  • System changes internally communicated
  • Third-party security oversight conducted
  • Vendor agreements established
  • Workstation use and security policy established
Risk management Data protection impact assessment, recurring risk assessments, and vendor risk management. 4
  • Data Protection Impact Assessment (DPIA) completed
  • Risk assessments performed
  • Risk management policy established
  • Vendor management program established
Vulnerability management Automated patching, annual independent penetration testing, and tracked remediation. 4
  • Automated software patch management performed
  • Penetration testing findings remediated
  • Penetration testing performed within the last 12 months
  • Vulnerability management policy established
Your data

Your data stays yours

Your traces can hold sensitive parts of your production systems. You control what you send and what stays masked. Retention varies by plan, with custom options available for enterprise customers.

In transit

Encrypted from your services to Logfire.

At rest

Sensitive data is stored encrypted, with automated backups protecting high-risk data and critical systems.

In your control

Control what you send and mask, with retention options defined by plan.

Documents

Documents for your security review

Access our latest audit and test reports, investigate our security controls or review our canonical legal and privacy references.

FAQs

Answers before the security review

The common questions about evidence access, HIPAA, legal terms, and the role of our compliance portal.

What can I review without requesting access?

This page publishes Pydantic's compliance posture, control catalog, data safeguards, legal terms, and subprocessor list. The SOC 2 and penetration test reports require an access request.

How do I get the SOC 2 or penetration test report?

Request either report through our secure document portal. The portal handles verification, approvals, and controlled delivery of the latest restricted evidence.

Why does the document request open Oneleet?

Pydantic owns and publishes the security information on this page. We use Oneleet to manage compliance evidence and securely fulfill requests for restricted reports.

Can Logfire support HIPAA-regulated workloads?

Yes. Logfire can support protected health information when Pydantic and the customer have signed a Business Associate Agreement. Contact us to confirm the right plan and terms before sending PHI.

Where can I review Pydantic's processing terms and subprocessors?

Our Data Processing Addendum describes processing safeguards, and our subprocessor list identifies the vendors that help operate Logfire.

How do I report a security vulnerability?

Email our security team with enough detail to reproduce and assess the issue. We will coordinate directly with you on the next steps.

Report a security vulnerability

Get in touch with our team to disclose any security concerns

Contact us