Your telemetry is your data.
Production data is a meaningful trust decision. Here's how we handle yours.
Your telemetry never trains anyone's model
Your telemetry is never used to train AI models. To draft a root cause on paid tiers, the AI layer receives the evidence it needs — service names, error categories, timestamps, and the top error patterns and representative messages from the incident window. That content is never used for training and is not retained by the provider beyond standard abuse-monitoring windows. Statistical detection and rule packs run entirely inside our own infrastructure and never touch an external AI provider.
Encrypted in transit and at rest
TLS in transit, modern cipher suites only. Sensitive configuration (notification webhooks, integration credentials) is encrypted at rest. Application database runs on a managed relational backend with provider-side encryption.
Tenant isolation on every query
Every read, every write, and every detection query carries account and project identifiers. Ingest streams are tenant-scoped. Concurrency limits apply per tenant so no one's workload starves another.
Retention and deletion
14-day retention during trial. 30 days on Team and Growth. Per-deal retention on the Custom tier. Permanent deletion at end of retention. Tenant-scoped delete on request for GDPR right-to-erasure.
Access controls
Login via Google today. SAML / enterprise SSO is on the roadmap. API keys are scoped — read, ingest, or both — and listed per-tenant. Alert state changes are recorded with timestamps and actor for after-the-fact review.
Compliance and deployment
SOC 2 Type II is in progress — we will publish the report here when it's complete, and we won't claim it before then. GDPR-aligned, DPA on request. Primary infrastructure runs in the EU (Germany/Finland); custom residency on the Custom tier. Self-hosted and dedicated deployments on request.
We publish our subprocessors
We don't ask you to take our word for who touches your data. The full list is public, and subprocessors only receive the minimum needed for their function — none of them receive your log content.
Have a security questionnaire?
We answer SIG, CAIQ, and custom questionnaires on request. Procurement, legal, and IT teams welcome.
Contact us →