| Independent security / no-logs audit | ❌Not foundVendor claims penetration tests and SDLC reviews. No public independent audit report or no-logs attestation found (this product stores customer logs by design). | ❌Not foundDPA allows customer-funded audits by agreement; no public third-party audit report reviewed. |
|---|
| ISO 27001 | ✅VerifiedICDQ certificate 069/23 SGSI, ISO 27001:2022, BEENARIO GMBH, scope includes Bugfender customer data (support, development, hosting, sysadmin, HR). Current issue 18 Apr 2025, expires 19 Apr 2028. Cert address Baiersbronn vs imprint Walldorf. | ❌Not foundNo public ISO certificate referenced on privacy/DPA pages reviewed. |
|---|
| SOC 2 / SOC 3 | ❌Not foundNo public SOC 2 report found. 2022 blog says they certified ISO 27001 instead of SOC 2. | ❌Not foundNo public SOC report found in materials reviewed. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedGerman controller/processor. Security and DPA help pages claim GDPR processing with access, rectification, erasure, expiry, export, and breach notice. Confirm via signed DPA. | ⚠️Vendor claimedDutch controller/processor materials; hosted data in EU per DPA; self-host keeps events local. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity, no known US parent, default log region EU. US-group processors on the public list: Wasabi Inc., Statuspage.io/Atlassian, Intercom, Cloudflare, Stripe. Optional AWS (Private Instance any region; HIPAA SaaS us-west-1/us-east-1). Not legal advice. | ⚠️PartialNo known US parent; hosted app data path is EU (Hetzner/Scaleway). Stripe (US) processes payments only. Self-host keeps error payloads local but phone-home goes to Bugsink. Not a zero-adjacency claim; not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedModel DPA download plus counter-sign workflow. Pricing table lists GDPR DPA on paid plans, not Free. Vendor article says SCC/Schrems II language is unnecessary because they are EU-based; privacy policy still names US recipients. | ⚠️Vendor claimedPublic hosted DPA available; covers subprocessors, EU location, retention, audits at controller expense. |
|---|
| EU AI Act | —Not applicableLogging and crash product. MCP is a read connector to existing tenant data, not an AI system they market as high-risk. | —Not applicableError tracking product; not positioned as an AI system. |
|---|
| HIPAA (dedicated / on-prem) | ⚠️Vendor claimedVendor says self-service SaaS is not suitable. Dedicated HIPAA instance (BAA, AWS us-west-1 and us-east-1) or customer-hosted on-prem. Not independently verified here. | Non indicato |
|---|