Security & Trust
At Dash0, your security, privacy, and trust are our top priorities. We are committed to creating a secure and reliable environment for your observability data.
Security & Compliance Overview
A single document covering our platform and hosting, data processing, compliance & assurance, security controls, data retention, and subprocessors.
Download overviewCertified & Compliant
Our commitment to security is validated by industry-leading certifications and compliance frameworks.

SOC 2 Type II
Verified security, availability, and confidentiality controls

GDPR
Full compliance with EU data protection regulations

HIPAA
Healthcare data protection and privacy compliance, with BAAs available for customers

ISO 27001
International standard for information security management

PCI DSS
Payment card industry data security standard compliance
How We Protect Your Data
Multiple layers of security controls ensure your observability data remains protected at every stage.
End-to-End Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Your observability data never travels unprotected.
Secure Infrastructure
Hosted on enterprise-grade cloud infrastructure with SOC 2 Type II certified data centers and multi-region redundancy.
Access Controls
Role-based access control (RBAC), SSO/SAML integration, multi-factor authentication, and detailed audit logs for complete visibility.
Data Sovereignty
Choose your data residency region. We offer EU and US data centers to help you meet local compliance requirements.
Security and Compliance Center
Dash0 uses Safebase to manage and publish all its certifications, security, trust and legal related documents. Access detailed security documentation, request compliance reports, and get answers to your security questions.
Legal Documentation
Review our policies and agreements that govern our services.
Security Hall of Fame
We are grateful to the security researchers who have responsibly disclosed vulnerabilities and helped us keep Dash0 secure for everyone.
Have Security Questions?
Our security team is ready to help. Reach out for security assessments, compliance documentation, or any security-related inquiries.
FAQ
Telemetry (logs, metrics, and traces via OpenTelemetry) plus the minimal account data needed to provision access (name, email). Dash0 doesn't require special-category or payment data to function, and has no reason to collect it.
Yes. The OpenTelemetry Collector runs in the customer's own environment, and customers decide what it sends. Built-in filtering, allowlisting, and redaction let customers strip sensitive fields, such as PII or secrets, at the source, before it reaches Dash0.
In transit via TLS, at rest via AES-256, with keys managed through native cloud key management (AWS KMS / GCP KMS).
SOC 2 Type II, independently audited. ISO 27001 is in progress. Reports, our GDPR Data Transfer Impact Assessment, DPAs and HIPAA BAA are available under NDA at trust.dash0.com.
No. Dash0 doesn't train or operate foundation models. Agent0 runs on models hosted by AWS Bedrock and GCP Vertex under Zero Data Retention agreements, so neither Dash0 nor the model providers use customer data or prompts to train models. Full detail is available in the Agent0 Security Whitepaper on our trust center.
Each session runs in its own ephemeral, sandboxed environment with a pinned execution image and restricted network egress. Sandboxes are torn down after use, tool access is scoped and largely read-only, and write actions (like code changes) go through a pull request. See the Agent0 Security Whitepaper on our trust center at trust.dash0.com for the full architecture.
Exclusively on AWS and GCP. Dash0 owns no physical data centers. EU customers can pin telemetry storage to the EU as a data residency setting.