Security and compliance
We recognize that observability data can reflect critical business systems, and we handle that responsibility with care. Here's how we protect it with Pydantic Logfire, and what we're audited against.
Trusted by the world's best engineering teams
Built for the enterprise
Security and privacy are core to how Pydantic builds Logfire. Our commitment to security is audited and mapped to frameworks your security review expects.
Protected by design
Your data is encrypted, access is tightly controlled, and the platform is continuously monitored, regularly tested, and backed up.
Encryption
All data is encrypted in transit across internal and external networks, and at rest on the systems where it’s stored.
Access and MFA
Multi-factor authentication is required for critical services, with least-privilege access granted and reviewed at least annually.
Infrastructure
Web application and network firewalls, automated scanning, infrastructure as code, and restricted production access.
Monitoring and response
Audit logs are collected from systems and monitored, with an established incident-response policy and process.
Backups and recovery
Automated backups with recovery data isolated from production, and disaster recovery plans tested on a regular basis.
Penetration testing
Independent penetration testing at least yearly, with findings remediated. Report available on request.
Your data stays yours
Your traces can hold sensitive parts of your production systems. You decide what Logfire keeps, for how long, and what stays masked.
Encrypted from your services to Logfire.
Stored encrypted and backed up to durable storage.
Retention policies and masking, on your terms.
Everything that procurement asks for
Access our latest audit and test reports, investigate our security controls or review our canonical legal and privacy references.
Explore the Trust Center by category
Report a security vulnerability
Get in touch with our team to disclose any security concerns