| ISO 27001 | ⚠️Vendor claimedSecurity page states AppSignal is ISO 27001 certified; request current certificate for vendor file. | ✅VerifiedICDQ certificate 069/23 SGSI, ISO 27001:2022, BEENARIO GMBH, scope includes Bugfender customer data (support, development, hosting, sysadmin, HR). Current issue 18 Apr 2025, expires 19 Apr 2028. Cert address Baiersbronn vs imprint Walldorf. |
|---|
| SOC 2 / SOC 3 | ?UnknownNot clearly presented on the public security page alongside ISO; confirm report availability with vendor if required. | ❌Not foundNo public SOC 2 report found. 2022 blog says they certified ISO 27001 instead of SOC 2. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedDutch entity; security page asserts GDPR compliance and EU privacy posture. | ⚠️Vendor claimedGerman controller/processor. Security and DPA help pages claim GDPR processing with access, rectification, erasure, expiry, export, and breach notice. Confirm via signed DPA. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedDPA can be signed digitally via the AppSignal organization admin. | ⚠️Vendor claimedModel DPA download plus counter-sign workflow. Pricing table lists GDPR DPA on paid plans, not Free. Vendor article says SCC/Schrems II language is unnecessary because they are EU-based; privacy policy still names US recipients. |
|---|
| HIPAA | ⚠️PartialHIPAA / BAA path is offered as a paid add-on, not as default free-plan coverage. | ⚠️Vendor claimedVendor says self-service SaaS is not suitable. Dedicated HIPAA instance (BAA, AWS us-west-1 and us-east-1) or customer-hosted on-prem. Not independently verified here. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialContracting entity is AppSignal B.V. (NL) with no known US parent, but backups use Amazon Web Services EMEA SARL (AWS group) and transactional email uses Mailgun Technologies Inc. (US). That is not zero US-law-adjacent cloud exposure—treat as partial/medium diligence, request SCCs/subprocessor scope, and do not read 'EU APM' as 'no US cloud group involved'. Not legal advice. | ⚠️PartialEU entity, no known US parent, default log region EU. US-group processors on the public list: Wasabi Inc., Statuspage.io/Atlassian, Intercom, Cloudflare, Stripe. Optional AWS (Private Instance any region; HIPAA SaaS us-west-1/us-east-1). Not legal advice. |
|---|
| Independent security / no-logs audit report | ⚠️PartialSecurity page cites regular pentests under ISO 27001; public full audit reports not reviewed in this draft—request under NDA if needed. | ❌Not foundVendor claims penetration tests and SDLC reviews. No public independent audit report or no-logs attestation found (this product stores customer logs by design). |
|---|
| EU AI Act | ⚠️PartialCore product is APM SaaS; MCP/AI-assisted debugging features may need separate review if your AI Act inventory includes coding copilots connected to production data. | —Not applicableLogging and crash product. MCP is a read connector to existing tenant data, not an AI system they market as high-risk. |
|---|