Logo: Bugfender

Bugfender

German-operated remote logging, crash reporting, and in-app feedback for mobile and frontend apps, with a device-centric dashboard and an official on-premises edition.

Auto-hébergé

Bugfender is a client-side remote logging, crash reporting, and in-app feedback service for mobile and frontend applications. Beenario GmbH, registered in Walldorf, Germany, operates the product. The press kit still describes a Barcelona office and a remote-friendly team. It exists because production logs and non-crash failures are hard to retrieve once an app is in the field.

Developers install a first-party SDK, send logs from user devices, and inspect them per device in a web dashboard. The company says the SDK is built for mobile constraints: offline buffering with a configurable size limit, batched uploads, and the ability to enable or disable logging for a specific device.

The concrete differentiator versus crash-only tools is continuous remote logging plus a device-centric console. You can filter to one user or device, attach custom keys, and read the steps around an error even when the process did not crash. Official SDKs cover iOS, Android, JavaScript frontends, and common hybrid stacks. An on-premises edition is sold as Docker images with Compose or Helm examples.

EU-operated (DE)ISO 27001 (certificate published)Remote client loggingMobile-first SDKsOn-prem Docker/HelmDPA on paid plans

Shortlist Bugfender when you need device-centric remote logs and crash context from mobile or frontend apps, a German contracting party, and a published ISO 27001 certificate. Skip it when you need backend APM or a Sentry-protocol collector. Consider Bugsink for self-hosted Sentry-compatible errors, or AppSignal for backend performance.

Key capabilities

The SDK ships client logs continuously, including sessions that never crash. The dashboard filters to one device or user by log text, OS, model, or custom user ID. Logging can be enabled or disabled per device so support can turn capture on only for the ticket in front of them.

Crash reporting attaches stack traces, automatic code symbolication, preceding logs, user actions (when UI event logging is enabled), and device facts such as OS version, model, and available memory. Crash reporting is on paid SaaS plans, not the free remote-logging tier.

Official SDKs cover iOS, Android, JavaScript, React, Angular, Vue, Svelte, Flutter, React Native, Ionic, Cordova, .NET MAUI, Unity, and Xamarin. The vendor describes batched uploads, small payloads, and an on-device buffer with a size limit you set, flushed when the device is back online.

A drop-in or custom feedback screen sends the report with device info, app version, and surrounding logs into the same dashboard. The help pages say the UI is invoked only when the developer requests it and transmission is asynchronous. This feature is listed on paid plans.

The On-Premises edition ships as amd64 Docker images with Compose (single server) or Helm (cluster) samples, an admin manual, and vendor update or monitoring support. Bugfender MCP (`npx @bugfender/mcp`) gives user-scoped read tools for logs, crashes, issues, devices, and feedback from an IDE or CLI.

En un coup d'œil

Legal entity
Beenario GmbH (Walldorf, Germany)
Founded
2014 (press kit)
Product type
SaaS remote logger; Enterprise on-prem
Default hosting
EU ISO 27001 datacenters (operator unnamed)
Commercial model
Free tier plus subscription with reserved log volume and optional PAYG cap
Open source
No (client SDKs published, proprietary license)

Best fit when

  • Mobile or hybrid teams that must inspect one user's device logs without physical access
  • Frontend teams that want crash stacks plus the preceding client log trail
  • Support orgs that want in-app feedback attached to the same device record
  • Buyers who need a German GmbH contract, a published ISO 27001:2022 certificate, and a downloadable DPA
  • Enterprises that will pay for on-premises Docker/Helm or a dedicated private instance

Poor fit when

  • Backend or platform teams collecting server logs, traces, or full APM
  • Teams that need a Sentry-compatible ingest DSN without changing SDKs (see Bugsink)
  • Organisations that require a publicly named EU-only host with no US-group subprocessors on the default SaaS
  • HIPAA or similar workloads on the self-service SaaS (vendor says dedicated instance or on-prem only)
  • Projects that only want crash dumps and already have Crashlytics or Sentry covering that job

Consider instead when

  • When: You already use Sentry SDKs and want a self-hosted or Dutch-hosted error inbox without rewriting clients

    Consider: Bugsink

    Bugsink speaks the Sentry protocol. It is not a device-centric mobile remote logger.

  • When: The pain is backend performance, serverside exceptions, or APM rather than client devices

    Consider: AppSignal

    AppSignal is a Dutch APM suite. Bugfender's own FAQ says it does not take backend logs.

  • When: You need a full-stack US incumbent with session replay, performance, and a huge SDK matrix, and jurisdiction is not the filter

    Consider: Sentry

    Sentry is the capability superset. Bugfender is narrower and EU-operated.

Juridiction et propriété

Entité légale
Beenario GmbH, Altrottstraße 31, 69190 Walldorf, Germany (Amtsgericht Stuttgart HRB 752438, VAT DE299463958)
Maison mère / contrôle US
Aucune maison mère US connue
Exposition CLOUD Act (indicative)
Medium
Hébergement / résidence
Default SaaS: EU ISO 27001-certified datacenters, operator not named; multiple distant EU sites. Privacy policy names Wasabi Technologies, Inc. (US company, storage stated as EU) and Statuspage.io / Atlassian for status. Site uses Cloudflare and Intercom. Payments via Stripe. Private Instance may be any AWS or DigitalOcean region. HIPAA dedicated SaaS uses AWS us-west-1 and us-east-1. On-premises is customer-hosted Docker/Helm.

No known US parent. Press kit still cites a Barcelona office. ISO certificate address is Baiersbronn, not Walldorf. Named US-group processors keep CLOUD Act exposure at medium even though default log region is EU. Indicative only, not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Verified
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +4

Considerations & known limitations

  • MediumUS-group subprocessors on default SaaS

    Privacy and cookie pages name Wasabi Inc., Statuspage/Atlassian, Intercom, Cloudflare, and Stripe. Default logs are claimed EU-resident, but US legal entities still sit on the path. On-prem or a tightly scoped private instance is the way to shrink that surface.

  • MediumAt-rest encryption documentation conflict

    Security marketing says encryption at rest always. A 2018 help article says logs are not always encrypted at rest in the datacenter or on the device. Do not log secrets or health data until Beenario confirms the current control.

  • LowDefault datacenter operator not named

    Help pages say EU ISO 27001 datacenters in multiple locations but do not publish the colocation or cloud brand for standard SaaS. That complicates supplier questionnaires.

  • LowVendor staff can read tenant logs

    Support can open an account when you contact them; operators can reach production databases for maintenance. The security page says support access is audit-logged and staff use 2FA. Still a residual insider-access fact for sensitive payloads.

  • LowNo backend logging

    Official FAQ: no server-side logs. Teams expecting one tool for API and mobile will still need a second stack.

Open questions for due diligence

  • What company operates the default EU SaaS datacenters, and is Wasabi used for primary log objects, backups, or both?
  • Is application log data encrypted at rest today, with what key management, given the 2018 help article?
  • Does the signed DPA list Wasabi, Atlassian Statuspage, Intercom, Cloudflare, and Stripe, and which transfer tool applies?
  • Which registered address is current: Walldorf (imprint) or Baiersbronn (ISO certificate)?
  • For a residency-sensitive tenant, can Private Instance be limited to a named EU region with no US-group subprocessors for status, chat, or email?

Questions Fréquemment Posées

Client-side only. The remote-logging FAQ states Bugfender does not support backend logs and is optimized for mobile, web, and IoT applications. If your primary need is server traces or OpenTelemetry APM, look at a backend tool (for example AppSignal) instead of stretching Bugfender.

The help center says default storage is the European Union in an ISO 27001-certified data center. That default operator is not named. Private Instance can be placed in any AWS or DigitalOcean region you choose. The HIPAA help article says a dedicated HIPAA SaaS instance uses AWS us-west-1 and us-east-1 for hosting, email, and backups. On-premises keeps data in your own environment. The privacy policy also names Wasabi Technologies, Inc. for storage (EU location claimed) plus Statuspage.io, and the site uses Cloudflare and Intercom.

Yes on paid plans that list a GDPR DPA in the pricing comparison. The help article hosts a model contract: you fill the team account ID, send a signed copy, and they counter-sign. The free plan is described as GDPR-compliant for you as a customer (controller duties toward your own account data) but is not the path they document for storing end-user personal data under a DPA. Retention on DPA-capable plans is stated as up to 30 days of logs, with backups generally kept up to 90 days after that.

Enterprise On-Premises: amd64 Docker images, Compose for a single node or Helm for a cluster. Vendor-stated ballpark sizing is about 2 CPU cores and 4 GB RAM per million devices, and about 4 TB disk per 100 million log lines per day (8 TB if you want high availability). They recommend TLS (Let's Encrypt is mentioned), an SMTP server, optional Amazon SNS for SMS 2FA, and an S3-compatible bucket for rolling backups. This is a licensed product, not an open-source server you can run without a contract.

Do not treat this as settled from public pages alone. The security page says data is always encrypted in transit (TLS 1.3, TLS 1.2 accepted) and at rest. A help article dated 2018 says logs are encrypted in transit but are not always encrypted at rest in the datacenter or in the on-device cache. Ask for a current written statement (and whether Wasabi objects are encrypted with customer-controlled keys) before you log regulated payloads.