Dash0 acquires Polar Signals

Enterprise-Grade Security

Security & Trust

At Dash0, your security, privacy, and trust are our top priorities. We are committed to creating a secure and reliable environment for your observability data.

PDF · Revision 08/2026

Security & Compliance Overview

A single document covering our platform and hosting, data processing, compliance & assurance, security controls, data retention, and subprocessors.

Download overview

Certified & Compliant

Our commitment to security is validated by industry-leading certifications and compliance frameworks.

SOC 2 Type II certification badge

SOC 2 Type II

Verified security, availability, and confidentiality controls

GDPR certification badge

GDPR

Full compliance with EU data protection regulations

HIPAA certification badge

HIPAA

Healthcare data protection and privacy compliance, with BAAs available for customers

ISO 27001 certification badge

ISO 27001

International standard for information security management

In progress · Certified Q1 2027
PCI DSS certification badge

PCI DSS

Payment card industry data security standard compliance

In progress · Certified Q1 2027

How We Protect Your Data

Multiple layers of security controls ensure your observability data remains protected at every stage.

End-to-End Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Your observability data never travels unprotected.

Secure Infrastructure

Hosted on enterprise-grade cloud infrastructure with SOC 2 Type II certified data centers and multi-region redundancy.

Access Controls

Role-based access control (RBAC), SSO/SAML integration, multi-factor authentication, and detailed audit logs for complete visibility.

Data Sovereignty

Choose your data residency region. We offer EU and US data centers to help you meet local compliance requirements.

Security and Compliance Center

Dash0 uses Safebase to manage and publish all its certifications, security, trust and legal related documents. Access detailed security documentation, request compliance reports, and get answers to your security questions.

Legal Documentation

Review our policies and agreements that govern our services.

Responsible Disclosure

Security Hall of Fame

We are grateful to the security researchers who have responsibly disclosed vulnerabilities and helped us keep Dash0 secure for everyone.

Have Security Questions?

Our security team is ready to help. Reach out for security assessments, compliance documentation, or any security-related inquiries.

FAQ

Telemetry (logs, metrics, and traces via OpenTelemetry) plus the minimal account data needed to provision access (name, email). Dash0 doesn't require special-category or payment data to function, and has no reason to collect it.

Yes. The OpenTelemetry Collector runs in the customer's own environment, and customers decide what it sends. Built-in filtering, allowlisting, and redaction let customers strip sensitive fields, such as PII or secrets, at the source, before it reaches Dash0.

In transit via TLS, at rest via AES-256, with keys managed through native cloud key management (AWS KMS / GCP KMS).

SOC 2 Type II, independently audited. ISO 27001 is in progress. Reports, our GDPR Data Transfer Impact Assessment, DPAs and HIPAA BAA are available under NDA at trust.dash0.com.

No. Dash0 doesn't train or operate foundation models. Agent0 runs on models hosted by AWS Bedrock and GCP Vertex under Zero Data Retention agreements, so neither Dash0 nor the model providers use customer data or prompts to train models. Full detail is available in the Agent0 Security Whitepaper on our trust center.

Each session runs in its own ephemeral, sandboxed environment with a pinned execution image and restricted network egress. Sandboxes are torn down after use, tool access is scoped and largely read-only, and write actions (like code changes) go through a pull request. See the Agent0 Security Whitepaper on our trust center at trust.dash0.com for the full architecture.

Exclusively on AWS and GCP. Dash0 owns no physical data centers. EU customers can pin telemetry storage to the EU as a data residency setting.