HIPAA-Compliant DevOps & Monitoring Vendors
DevOps & Monitoring vendors that hold HIPAA certification
Datadog
17/32Cloud monitoring and analytics platform for infrastructure, applications, and logs.
Listed on Datadog Trust Center
MongoDB Atlas
17/32Fully managed cloud database service with multi-cloud support.
Listed on MongoDB Trust Portal
Mendix
13/32Low-code application development platform, owned by Siemens.
Freshservice
10/32IT service management (ITSM) platform from Freshworks.
Freshworks commitment to HIPAA compliance documented for eligible products
Google Apigee
10/32API management platform, part of Google Cloud.
Postman
9/32API platform for building, testing, and documenting APIs.
JFrog
7/32DevOps platform for artifact management, binary repositories, and software supply chain security.
Referenced elsewhere on site regarding regulatory standards, not itemized on the certificate program page
New Relic
6/32Observability and application performance monitoring (APM) platform.
HIPAA-enabled capabilities for eligible accounts
MuleSoft
6/32Integration and API management platform (Anypoint Platform), part of Salesforce.
Bitbucket
5/32Git-based source code repository and CI/CD platform from Atlassian.
Atlassian Cloud offers HIPAA-compliant solutions
LaunchDarkly
5/32Feature management and experimentation platform for software delivery.
Enables customer HIPAA compliance
Rollbar
5/32Real-time error monitoring and crash reporting platform for applications.
Compliant SaaS solution with BAA
Supabase
4/32Open-source Firebase alternative with PostgreSQL database, auth, and storage.
HIPAA compliant with BAA available for enterprise/team plans
Honeycomb
4/32Observability platform for distributed tracing and debugging production systems.
BAA available for eligible customers
OutSystems
4/32Low-code application development platform.
Available to Sentry-entitled (higher tier) customers
Kong
4/32API gateway and AI/API connectivity platform.
Sentry
3/32Application monitoring and error-tracking platform for developers.
Attestation
ManageEngine
3/32IT management software suite (ITSM, endpoint, network, security), part of Zoho.
SOC 2 + HIPAA Type 2 for specific products (ServiceDesk Plus, Endpoint Central, ADManager Plus)
ConnectWise
2/32Business management and RMM/PSA software suite for MSPs.
BAA available for covered services on request
These devops & monitoring vendors do not currently hold HIPAA certification:
- PagerDuty
- GitHub
- ServiceNow (not documented)
- GitLab (not documented)
- CircleCI (not documented)
- Travis CI (not documented)
- Jenkins (not documented)
- AppDynamics (not documented)
- Grafana Cloud (not documented)
- Bugsnag (not documented)
- Zapier (not documented)
- Bubble (not documented)
- Make (not documented)
- n8n (not documented)
- Retool (not documented)
- Betty Blocks (not documented)
- Glide (not documented)
- Softr (not documented)
- SolarWinds (not documented)
- Datto RMM (not documented)
- Kaseya (not documented)
- NinjaOne (not documented)
- Tyk (not documented)
- BrowserStack (not documented)
- Sauce Labs (not documented)
- LambdaTest (not documented)
- TestRail (not documented)
- Cypress.io (not documented)
- Applitools (not documented)
- SonarQube (not documented)
Know a vendor we're missing?