| Independent security / no-logs audit | ❌Not foundVendor claims penetration tests and SDLC reviews. No public independent audit report or no-logs attestation found (this product stores customer logs by design). | ❌Not foundNo public third-party security audit PDF located on tindra.sh or GitHub README. |
|---|
| ISO 27001 | ✅VerifiedICDQ certificate 069/23 SGSI, ISO 27001:2022, BEENARIO GMBH, scope includes Bugfender customer data (support, development, hosting, sysadmin, HR). Current issue 18 Apr 2025, expires 19 Apr 2028. Cert address Baiersbronn vs imprint Walldorf. | ❌Not foundNo ISO 27001 claim found on imprint, privacy, DPA, or product pages. |
|---|
| SOC 2 / SOC 3 | ❌Not foundNo public SOC 2 report found. 2022 blog says they certified ISO 27001 instead of SOC 2. | ❌Not foundNo SOC 2/3 report referenced on public legal/trust pages. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedGerman controller/processor. Security and DPA help pages claim GDPR processing with access, rectification, erasure, expiry, export, and breach notice. Confirm via signed DPA. | ⚠️Vendor claimedEU controller/processor (Blendbyte GmbH); public DPA; German supervisory authority cited on privacy page. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity, no known US parent, default log region EU. US-group processors on the public list: Wasabi Inc., Statuspage.io/Atlassian, Intercom, Cloudflare, Stripe. Optional AWS (Private Instance any region; HIPAA SaaS us-west-1/us-east-1). Not legal advice. | ⚠️PartialEU entity / no known US parent, but Managed hosting vendors are not named publicly and billing uses Paddle; website analytics use Fathom. Not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedModel DPA download plus counter-sign workflow. Pricing table lists GDPR DPA on paid plans, not Free. Vendor article says SCC/Schrems II language is unnecessary because they are EU-based; privacy policy still names US recipients. | ⚠️Vendor claimedPublic Art. 28 DPA for Tindra Managed; incorporated into Terms. |
|---|
| EU AI Act | —Not applicableLogging and crash product. MCP is a read connector to existing tenant data, not an AI system they market as high-risk. | —Not applicableMonitoring/debugging product; built-in MCP is an integration surface, not an AI system offering under typical AI Act product framing. |
|---|
| HIPAA (dedicated / on-prem) | ⚠️Vendor claimedVendor says self-service SaaS is not suitable. Dedicated HIPAA instance (BAA, AWS us-west-1 and us-east-1) or customer-hosted on-prem. Not independently verified here. | Niet vermeld |
|---|