SOC 2-Compliant DevOps & Monitoring Vendors

DevOps & Monitoring vendors are evaluated against SOC 2 when they handle the workflows this framework governs. Currently, 40 vendors in our DevOps & Monitoring category hold SOC 2 certification and 5 hold it partially or conditionally. Each listing below links to the vendor's full compliance profile.

DevOps & Monitoring vendors that hold SOC 2 certification

Datadog logo

Datadog

17/32

Cloud monitoring and analytics platform for infrastructure, applications, and logs.

Listed on Datadog Trust Center at trust.datadoghq.com

MongoDB Atlas logo

MongoDB Atlas

17/32

Fully managed cloud database service with multi-cloud support.

Listed on MongoDB Trust Portal

ServiceNow logo

ServiceNow

17/32

Cloud platform for IT service management, workflow automation, and enterprise operations.

GitHub logo

GitHub

13/32

Code hosting platform with version control, CI/CD, and collaboration tools.

Listed on GitHub security page and Microsoft certification

Mendix logo

Mendix

13/32

Low-code application development platform, owned by Siemens.

Freshservice logo

Freshservice

10/32

IT service management (ITSM) platform from Freshworks.

Google Apigee logo

Google Apigee

10/32

API management platform, part of Google Cloud.

Postman logo

Postman

9/32

API platform for building, testing, and documenting APIs.

JFrog logo

JFrog

7/32

DevOps platform for artifact management, binary repositories, and software supply chain security.

PagerDuty logo

PagerDuty

6/32

Incident management and digital operations platform for IT teams.

Listed on PagerDuty security page and assurance profile

New Relic logo

New Relic

6/32

Observability and application performance monitoring (APM) platform.

MuleSoft logo

MuleSoft

6/32

Integration and API management platform (Anypoint Platform), part of Salesforce.

BrowserStack logo

BrowserStack

6/32

Cloud-based cross-browser and mobile app testing platform.

Bitbucket logo

Bitbucket

5/32

Git-based source code repository and CI/CD platform from Atlassian.

Varies by product scope

LaunchDarkly logo

LaunchDarkly

5/32

Feature management and experimentation platform for software delivery.

Rollbar logo

Rollbar

5/32

Real-time error monitoring and crash reporting platform for applications.

Type I and Type II

Supabase logo

Supabase

4/32

Open-source Firebase alternative with PostgreSQL database, auth, and storage.

Listed on Supabase security page and trust center

Honeycomb logo

Honeycomb

4/32

Observability platform for distributed tracing and debugging production systems.

Zapier logo

Zapier

4/32

No-code workflow automation and app integration platform.

Make logo

Make

4/32

Visual workflow automation and integration platform (formerly Integromat).

Retool logo

Retool

4/32

Low-code platform for building internal business applications.

OutSystems logo

OutSystems

4/32

Low-code application development platform.

Available to Sentry-entitled (higher tier) customers

Datto RMM logo

Datto RMM

4/32

Remote monitoring and management platform for MSPs, part of Kaseya.

Covered under parent company Kaseya's trust center program

Kaseya logo

Kaseya

4/32

IT management and security software suite for MSPs.

Kong logo

Kong

4/32

API gateway and AI/API connectivity platform.

Tyk logo

Tyk

4/32

Open-source API gateway and management platform.

GitLab logo

GitLab

3/32

DevSecOps platform for source code management, CI/CD, and software delivery.

Sentry logo

Sentry

3/32

Application monitoring and error-tracking platform for developers.

Type I and Type II

Grafana Cloud logo

Grafana Cloud

3/32

Managed observability platform (metrics, logs, traces, dashboards) from Grafana Labs.

Bugsnag logo

Bugsnag

3/32

Application stability monitoring and error tracking tool, owned by SmartBear.

Referenced at SmartBear parent-company trust center level; not itemized separately for Bugsnag

n8n logo

n8n

3/32

Workflow automation platform with a self-hostable, source-available core.

SolarWinds logo

SolarWinds

3/32

IT infrastructure monitoring and management software.

SOC 2 Type II available for specific products (Pingdom, Loggly, Service Desk, Observability SaaS)

ManageEngine logo

ManageEngine

3/32

IT management software suite (ITSM, endpoint, network, security), part of Zoho.

NinjaOne logo

NinjaOne

3/32

Unified IT and endpoint management platform for MSPs and IT teams.

Sauce Labs logo

Sauce Labs

3/32

Cloud-based continuous testing platform for web and mobile apps.

CircleCI logo

CircleCI

2/32

Continuous integration and continuous delivery (CI/CD) platform.

Bubble logo

Bubble

2/32

No-code platform for building web applications.

Betty Blocks logo

Betty Blocks

2/32

No-code application development platform.

ConnectWise logo

ConnectWise

2/32

Business management and RMM/PSA software suite for MSPs.

SonarQube logo

SonarQube

2/32

Static code analysis and code quality/security platform, by Sonar (SonarSource).

Glide logo

Glide

1/32

No-code platform for building mobile and web apps from spreadsheets/data.

TestRail logo

TestRail

1/32

Test case management software, part of Idera.

Referenced via dedicated SOC 2 compliance page; badge/report not independently verified from this page

Cypress.io logo

Cypress.io

1/32

JavaScript end-to-end testing framework and cloud (Cypress Cloud).

AppDynamics logo

AppDynamics

0/32

Application performance monitoring (APM) and observability platform, owned by Cisco (part of Splunk).

Now under Splunk/Cisco ownership; compliance largely follows the parent's programs, not itemized separately for AppDynamics

LambdaTest logo

LambdaTest

0/32

Cloud-based cross-browser testing platform (rebranded as TestMu AI).

Referenced on company trust page; full public report not independently confirmed

These devops & monitoring vendors do not currently hold SOC 2 certification:

Know a vendor we're missing?

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026