SOC 2 Type 2
Independently audited controls for security, availability, and confidentiality.
Observability data can reflect critical business systems. See how Pydantic Logfire protects it, what our controls cover, and the evidence available for your review.
Trusted by the world's best engineering teams
Security and privacy are core to how Pydantic builds Logfire. Our commitment to security is audited and mapped to frameworks your security review expects.
Independently audited controls for security, availability, and confidentiality.
Aligned with EU and UK data protection requirements, with a Data Processing Addendum available.
Configured to support protected health information under a signed Business Associate Agreement.
Sensitive data is encrypted at rest, access is tightly controlled, and the systems behind Logfire are monitored and regularly tested.
Data is encrypted in transit across internal and external networks. Sensitive data is encrypted at rest on the systems where it is stored.
MFA protects administrative access to critical systems and supported external applications. Least-privilege access is approved and reviewed at least annually.
Web application and network firewalls, automated scanning, infrastructure as code, and restricted production access.
Audit logs are collected from systems and monitored, with an established incident-response policy and process.
Automated backups with recovery data isolated from production, and disaster recovery plans tested on a regular basis.
Independent penetration testing at least every 12 months, with findings remediated. The latest report is available on request.
Open any category to see the controls mapped across Pydantic's compliance program.
Your traces can hold sensitive parts of your production systems. You control what you send and what stays masked. Retention varies by plan, with custom options available for enterprise customers.
Encrypted from your services to Logfire.
Sensitive data is stored encrypted, with automated backups protecting high-risk data and critical systems.
Control what you send and mask, with retention options defined by plan.
Access our latest audit and test reports, investigate our security controls or review our canonical legal and privacy references.
The common questions about evidence access, HIPAA, legal terms, and the role of our compliance portal.
This page publishes Pydantic's compliance posture, control catalog, data safeguards, legal terms, and subprocessor list. The SOC 2 and penetration test reports require an access request.
Request either report through our secure document portal. The portal handles verification, approvals, and controlled delivery of the latest restricted evidence.
Pydantic owns and publishes the security information on this page. We use Oneleet to manage compliance evidence and securely fulfill requests for restricted reports.
Yes. Logfire can support protected health information when Pydantic and the customer have signed a Business Associate Agreement. Contact us to confirm the right plan and terms before sending PHI.
Our Data Processing Addendum describes processing safeguards, and our subprocessor list identifies the vendors that help operate Logfire.
Email our security team with enough detail to reproduce and assess the issue. We will coordinate directly with you on the next steps.
Get in touch with our team to disclose any security concerns