SOC 2 company profile

What SOC 2 provider does PostHog use?

See the auditors, compliance platforms, and trust-center services connected to PostHog’s SOC 2 program.

SOC 2 statusself attested
Report typeNot publicly specified
Providers found2
Last checked2026-08-29
Providers

PostHog’s SOC 2 stack

trust center

SafeBase

SafeBase is named in PostHog's security or compliance materials.

menu bar and choosing "My device".Fleet does not see:your screenyour messages or photoswhat you typewhich URLs you visitSOC 2Visit our Trust CenterUse our Trust Center powered by SafeBase to self-serve reports, policies, and certifications.PostHog is certified as SOC 2 Type 2 compliant, following an external audit.Our latest security report is publicly available (covering controls as of May 31, 2026). Our reporting period runs from June 1st th

Checked 2026-08-29
View source ↗
compliance platform

Drata

Drata is named in PostHog's security or compliance materials.

Our reporting period runs from June 1st through May 31st each year.PoliciesWe have a number of policies in place to support SOC 2 compliance. All team members have been invited to Drata to review these and to complete security training and background checks as part of onboarding.All of our policies are available for viewing and upon request via our Trust Center.These policies are also relevant for GDPR (see below). GDPRFor the purposes of GD

Checked 2026-08-29
View source ↗

Primary compliance evidence

PostHog public statement

tain a robust security program that follows best practice in order to meet the needs of our PostHog Cloud customers, making PostHog the ideal solution for customers who have GDPR, SOC 2, or CCPA obligations themselves. PostHog Cloud customers own the data they send to us for processing. We collect and analyze data about the use of PostHog Cloud by our customers, but that data does not include the user data that customers send to us to proces

Classification: self attested · checked 2026-08-29
Open source ↗
SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement