Bugfender vs Bugsink

Comparez Bugfender et Bugsink sur les capacités, la juridiction, les garanties et l'adéquation pour les acheteurs européens.

Tous deux listés comme alternatives à: Sentry

Logo: Bugfender

Bugfender

Germany· Error Tracking Software

Needs review

Shortlist Bugfender when you need device-centric remote logs and crash context from mobile or frontend apps, a German contracting party, and a published ISO 27001 certificate. Skip it when you need backend APM or a Sentry-protocol collector. Consider Bugsink for self-hosted Sentry-compatible errors, or AppSignal for backend performance.

EU-operated (DE)ISO 27001 (certificate published)Remote client loggingMobile-first SDKsOn-prem Docker/HelmDPA on paid plans
Logo: Bugsink

Bugsink

Netherlands· Cloud Computing

Needs review

Shortlist Bugsink when you need Sentry-SDK-compatible error tracking you can self-host lightly (or run as EU-hosted SaaS under a Dutch B.V.). Skip if you need full APM or an OSI open-source license—consider AppSignal for Dutch APM SaaS, or Sentry/self-hosted Sentry for broader platform depth.

Built to self-hostSentry SDK compatibleDutch vendor (Bugsink B.V.)EU-hosted SaaS optionSource available (Polyform Shield)SQLite-default stack
Bugfender vs Bugsink: Aperçu
CaractéristiqueLogo: BugfenderBugfenderLogo: BugsinkBugsink
Pays d'origineGermanyNetherlands
CatégorieError Tracking SoftwareCloud Computing
Open sourceNonNon
Auto-hébergéOuiOui
SiègeGermanyNetherlands
Entité légaleBeenario GmbH, Altrottstraße 31, 69190 Walldorf, Germany (Amtsgericht Stuttgart HRB 752438, VAT DE299463958)Bugsink B.V., Peter Schathof 41, 3533HZ Utrecht, NL (KvK 93064993)
Droit applicableNon indiquéDPA governed by laws of the Netherlands (hosted DPA)
Maison mère / contrôle USAucune maison mère US connueAucune maison mère US connue
Exposition CLOUD Act (indicative)MoyenFaible
Hébergement / résidenceDefault SaaS: EU ISO 27001-certified datacenters, operator not named; multiple distant EU sites. Privacy policy names Wasabi Technologies, Inc. (US company, storage stated as EU) and Statuspage.io / Atlassian for status. Site uses Cloudflare and Intercom. Payments via Stripe. Private Instance may be any AWS or DigitalOcean region. HIPAA dedicated SaaS uses AWS us-west-1 and us-east-1. On-premises is customer-hosted Docker/Helm.Hosted: DPA lists Hetzner (EU infra for event data), Scaleway (transactional email, EU), Stripe (payments only; no error/app data). Self-host: error events on your servers; phone-home metadata to Bugsink (usage/settings/install ID/IP) per privacy policy.
Résumé

German-operated remote logging, crash reporting, and in-app feedback for mobile and frontend apps, with a device-centric dashboard and an official on-premises edition.

Dutch error tracker with Sentry SDK compatibility—self-host lightly or use EU-hosted SaaS, built for teams that want stacktrace debugging without a heavyweight observability suite.

Tags
En un coup d'œil: Bugfender vs Bugsink
En un coup d'œilLogo: BugfenderBugfenderLogo: BugsinkBugsink
Legal entityBeenario GmbH (Walldorf, Germany)Non indiqué
Founded2014 (press kit)Non indiqué
Product typeSaaS remote logger; Enterprise on-premError tracking (self-host + optional EU SaaS)
Default hostingEU ISO 27001 datacenters (operator unnamed)Non indiqué
Commercial modelFree tier plus subscription with reserved log volume and optional PAYG capNon indiqué
Open sourceNo (client SDKs published, proprietary license)Non indiqué
Legal entity / HQNon indiquéBugsink B.V., Utrecht, Netherlands (KvK 93064993)
SDK modelNon indiquéSentry open-source SDK compatible (DSN switch)
LicenseNon indiquéPolyform Shield (source available; free non-competing self-host)
Self-host stackNon indiquéDocker/single app; SQLite default; MySQL/PostgreSQL optional
Hosted data locationNon indiquéEU (per DPA); Hetzner + Scaleway + Stripe listed
Hosted raw retentionNon indiqué60 days raw events (per DPA); aggregates until removed
ISO / SOC public certsNon indiquéNot found on public pages in this research
Key capabilities: Bugfender vs Bugsink
Key capabilitiesLogo: BugfenderBugfenderLogo: BugsinkBugsink
EU-operated (DE)OuiNon indiqué
ISO 27001 (certificate published)OuiNon indiqué
Remote client loggingOuiNon indiqué
Mobile-first SDKsOuiNon indiqué
On-prem Docker/HelmOuiNon indiqué
DPA on paid plansOuiNon indiqué
Built to self-hostNon indiquéOui
Sentry SDK compatibleNon indiquéOui
Dutch vendor (Bugsink B.V.)Non indiquéOui
EU-hosted SaaS optionNon indiquéOui
Source available (Polyform Shield)Non indiquéOui
SQLite-default stackNon indiquéOui

Bugfender

  • Device-centric remote logging

    The SDK ships client logs continuously, including sessions that never crash. The dashboard filters to one device or user by log text, OS, model, or custom user ID. Logging can be enabled or disabled per device so support can turn capture on only for the ticket in front of them.

  • Crash and exception context with symbolication

    Crash reporting attaches stack traces, automatic code symbolication, preceding logs, user actions (when UI event logging is enabled), and device facts such as OS version, model, and available memory. Crash reporting is on paid SaaS plans, not the free remote-logging tier.

  • Offline-aware mobile SDK with per-device control

    Official SDKs cover iOS, Android, JavaScript, React, Angular, Vue, Svelte, Flutter, React Native, Ionic, Cordova, .NET MAUI, Unity, and Xamarin. The vendor describes batched uploads, small payloads, and an on-device buffer with a size limit you set, flushed when the device is back online.

  • In-app feedback with the same log trail

    A drop-in or custom feedback screen sends the report with device info, app version, and surrounding logs into the same dashboard. The help pages say the UI is invoked only when the developer requests it and transmission is asynchronous. This feature is listed on paid plans.

  • On-prem Docker or Helm, plus MCP read access

    The On-Premises edition ships as amd64 Docker images with Compose (single server) or Helm (cluster) samples, an admin manual, and vendor update or monitoring support. Bugfender MCP (`npx @bugfender/mcp`) gives user-scoped read tools for logs, crashes, issues, devices, and feedback from an IDE or CLI.

Bugsink

  • Sentry SDK drop-in (DSN switch)

    Works with Sentry’s open-source SDKs across major languages/frameworks: keep existing instrumentation and point the DSN at Bugsink hosted or self-hosted endpoints—reducing migration cost versus rewriting agents.

  • Stacktrace-first error debugging

    Surfaces production failures with stacktraces, code context, and local variables, plus automatic issue grouping so high event volume collapses into a worklist of distinct problems.

  • Lightweight self-host footprint

    Designed to run as a single application with SQLite by default (MySQL/PostgreSQL optional), Docker-friendly install, no mandatory message queue, and claims of high event throughput on modest hardware including ARM.

  • EU hosted option with public DPA

    Managed SaaS stores hosted application data in the EU per DPA, with named EU infrastructure/email subprocessors (Hetzner, Scaleway) and Stripe limited to payments—useful when you want Sentry-like DX without self-ops.

  • Alerts, search/tags, and sourcemaps

    Email alerting when issues break, search across tags such as release/environment/user, and sourcemaps support so minified front-end stacks map back to original sources.

  • Dual deployment with portable workflow

    Same SDK workflow for hosted and self-hosted; vendor positions easy switching between modes so teams can start hosted and move to self-host (or the reverse) without re-instrumenting applications.

Assurance & compliance: Bugfender vs Bugsink
Assurance & complianceLogo: BugfenderBugfenderLogo: BugsinkBugsink
Independent security / no-logs audit
Not found

Vendor claims penetration tests and SDLC reviews. No public independent audit report or no-logs attestation found (this product stores customer logs by design).

Not found

DPA allows customer-funded audits by agreement; no public third-party audit report reviewed.

ISO 27001
Verified

ICDQ certificate 069/23 SGSI, ISO 27001:2022, BEENARIO GMBH, scope includes Bugfender customer data (support, development, hosting, sysadmin, HR). Current issue 18 Apr 2025, expires 19 Apr 2028. Cert address Baiersbronn vs imprint Walldorf.

Not found

No public ISO certificate referenced on privacy/DPA pages reviewed.

SOC 2 / SOC 3
Not found

No public SOC 2 report found. 2022 blog says they certified ISO 27001 instead of SOC 2.

Not found

No public SOC report found in materials reviewed.

GDPR / EU data protection
Vendor claimed

German controller/processor. Security and DPA help pages claim GDPR processing with access, rectification, erasure, expiry, export, and breach notice. Confirm via signed DPA.

Vendor claimed

Dutch controller/processor materials; hosted data in EU per DPA; self-host keeps events local.

US CLOUD Act exposure (indicative)
Partial

EU entity, no known US parent, default log region EU. US-group processors on the public list: Wasabi Inc., Statuspage.io/Atlassian, Intercom, Cloudflare, Stripe. Optional AWS (Private Instance any region; HIPAA SaaS us-west-1/us-east-1). Not legal advice.

Partial

No known US parent; hosted app data path is EU (Hetzner/Scaleway). Stripe (US) processes payments only. Self-host keeps error payloads local but phone-home goes to Bugsink. Not a zero-adjacency claim; not legal advice.

Data processing agreement (B2B)
Vendor claimed

Model DPA download plus counter-sign workflow. Pricing table lists GDPR DPA on paid plans, not Free. Vendor article says SCC/Schrems II language is unnecessary because they are EU-based; privacy policy still names US recipients.

Vendor claimed

Public hosted DPA available; covers subprocessors, EU location, retention, audits at controller expense.

EU AI Act
Not applicable

Logging and crash product. MCP is a read connector to existing tenant data, not an AI system they market as high-risk.

Not applicable

Error tracking product; not positioned as an AI system.

HIPAA (dedicated / on-prem)
Vendor claimed

Vendor says self-service SaaS is not suitable. Dedicated HIPAA instance (BAA, AWS us-west-1 and us-east-1) or customer-hosted on-prem. Not independently verified here.

Non indiqué
Considerations & known limitations: Bugfender vs Bugsink
Considerations & known limitationsLogo: BugfenderBugfenderLogo: BugsinkBugsink
US-group subprocessors on default SaaS
Medium

Privacy and cookie pages name Wasabi Inc., Statuspage/Atlassian, Intercom, Cloudflare, and Stripe. Default logs are claimed EU-resident, but US legal entities still sit on the path. On-prem or a tightly scoped private instance is the way to shrink that surface.

Non indiqué
At-rest encryption documentation conflict
Medium

Security marketing says encryption at rest always. A 2018 help article says logs are not always encrypted at rest in the datacenter or on the device. Do not log secrets or health data until Beenario confirms the current control.

Non indiqué
Default datacenter operator not named
Low

Help pages say EU ISO 27001 datacenters in multiple locations but do not publish the colocation or cloud brand for standard SaaS. That complicates supplier questionnaires.

Non indiqué
Vendor staff can read tenant logs
Low

Support can open an account when you contact them; operators can reach production databases for maintenance. The security page says support access is audit-logged and staff use 2FA. Still a residual insider-access fact for sensitive payloads.

Non indiqué
No backend logging
Low

Official FAQ: no server-side logs. Teams expecting one tool for API and mobile will still need a second stack.

Non indiqué
Self-host phone-home telemetryNon indiqué
Medium

Self-hosted installs periodically send usage/settings metadata and the install’s IP to Bugsink. Error events stay local, but zero-egress policies need an explicit review of phone-home behaviour.

Polyform Shield (not OSI open source)Non indiqué
Medium

Source is public and free for non-competing use, but the license restricts competing hosted offerings. Do not treat as MIT/Apache-style open source in procurement checklists.

Errors-only product scopeNon indiqué
Low

Not a substitute for full APM/observability platforms if you need traces, infra metrics, and log platforms.

Limited public enterprise cert packageNon indiqué
Medium

ISO/SOC materials not found publicly; hosted buyers may need NDA artifacts beyond the published DPA.

Stripe for hosted paymentsNon indiqué
Low

DPA states Stripe does not receive error/application data; still a US payment subprocessor for billing identity.

Adéquation

Bugfender

Best fit when

  • Mobile or hybrid teams that must inspect one user's device logs without physical access
  • Frontend teams that want crash stacks plus the preceding client log trail
  • Support orgs that want in-app feedback attached to the same device record
  • Buyers who need a German GmbH contract, a published ISO 27001:2022 certificate, and a downloadable DPA
  • Enterprises that will pay for on-premises Docker/Helm or a dedicated private instance

Poor fit when

  • Backend or platform teams collecting server logs, traces, or full APM
  • Teams that need a Sentry-compatible ingest DSN without changing SDKs (see Bugsink)
  • Organisations that require a publicly named EU-only host with no US-group subprocessors on the default SaaS
  • HIPAA or similar workloads on the self-service SaaS (vendor says dedicated instance or on-prem only)
  • Projects that only want crash dumps and already have Crashlytics or Sentry covering that job

Consider instead when

  • When: You already use Sentry SDKs and want a self-hosted or Dutch-hosted error inbox without rewriting clients

    Consider: Bugsink

    Bugsink speaks the Sentry protocol. It is not a device-centric mobile remote logger.

  • When: The pain is backend performance, serverside exceptions, or APM rather than client devices

    Consider: AppSignal

    AppSignal is a Dutch APM suite. Bugfender's own FAQ says it does not take backend logs.

  • When: You need a full-stack US incumbent with session replay, performance, and a huge SDK matrix, and jurisdiction is not the filter

    Consider: Sentry

    Sentry is the capability superset. Bugfender is narrower and EU-operated.

Bugsink

Best fit when

  • You want to keep Sentry open-source SDKs and only change the DSN/backend
  • Error payloads must stay on infrastructure you control (self-host) or with an EU-hosted Dutch processor
  • You found full self-hosted Sentry too heavy (queues, many services) and want a single-app footprint
  • You need stacktraces with local variables, grouping, alerts, search/tags, and sourcemaps—not full APM
  • Self-host license cost must be free for non-competing internal use

Poor fit when

  • You need traces, host metrics, logs, and SLOs in one product (use an APM suite)
  • Procurement requires OSI-approved open source (Polyform Shield is source-available with a competition carve-out)
  • Zero outbound network from the install (self-host phone-home must be reviewed)
  • You need a mature enterprise compliance pack (public ISO/SOC materials not found in this research)

Consider instead when

  • When: You need Dutch/EU APM with errors + performance + hosts + logs as SaaS

    Consider: AppSignal

    Different product class; not a Sentry DSN drop-in.

  • When: You need maximum feature depth and ecosystem, and can accept Sentry’s SaaS model

    Consider: Sentry (hosted, with EU data options as offered by Sentry)

  • When: You want Sentry feature parity self-hosted and can staff the ops burden

    Consider: Self-hosted Sentry

    Heavier stack; Bugsink optimizes for operational simplicity instead.

Open questions for due diligence

Bugfender

  • What company operates the default EU SaaS datacenters, and is Wasabi used for primary log objects, backups, or both?
  • Is application log data encrypted at rest today, with what key management, given the 2018 help article?
  • Does the signed DPA list Wasabi, Atlassian Statuspage, Intercom, Cloudflare, and Stripe, and which transfer tool applies?
  • Which registered address is current: Walldorf (imprint) or Baiersbronn (ISO certificate)?
  • For a residency-sensitive tenant, can Private Instance be limited to a named EU region with no US-group subprocessors for status, chat, or email?

Bugsink

  • Can phone-home be disabled or proxied for air-gapped / zero-egress self-host deployments?
  • What is the current GitHub release/version line and support policy for production self-host upgrades?
  • Are any additional hosted subprocessors or regions used beyond Hetzner, Scaleway, and Stripe?
  • Can Bugsink provide security questionnaire answers or audit evidence under NDA for enterprise onboarding?
  • For hosted: exact Hetzner regions and backup/DR locations in the current production footprint?