Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Datadog, your compliance team needs documented proof they can be trusted. ThirdProof investigated Datadog across 27 intelligence sources — here's what we found.
✓ FedRAMP Status: Authorized (Moderate) — verified against marketplace.fedramp.gov
26 sources queried. 98% confidence. Every Datadog investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Datadog's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 57% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
FedRAMP authorized: Product: Datadog; Provider: Datadog; Status: Compliant; Impact Level: LI-SaaS; Authorization Date: 2020-05-05T04:00:00.000Z
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
+ 6 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Datadog's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Verified against the official FedRAMP Marketplace API as of March 2026.
Datadog for Government authorized at Moderate impact level.
Low Risk
Vendor Risk Assessment
Based on data availability and source coverage
26
Sources Queried
25
Sources With Data
April 15, 2026
Last Assessed
AI-generated analysis for Datadog
Datadog (datadoghq.com) is a publicly traded cloud monitoring and data analytics platform assessed at Tier 4 (Low Risk) with a 98% confidence score, reflecting a strong and well-documented security posture appropriate for a vendor with critical data access. The assessment surfaces a number of meaningful positive signals across security, compliance, and operational maturity:
Independence Statement
All evidence in this report was sourced independently through automated external data collection without vendor participation, notification, or review.
2 findings identified for Datadog
The LEI registration for ACTIONS DATADOG has status "LAPSED". This may indicate the entity no longer maintains its regulatory filings.
datadoghq.com received a poor grade (D-) from Mozilla HTTP Observatory. Multiple security headers or configurations are missing. Note: This scan was performed on the marketing site (datadoghq.com). The application endpoint (app.datadoghq.com) may have different security headers. Verify the application domain separately.
31 positive signals verified
Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Adverse Media Found
Adverse Media Scan →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Domain Infrastructure Healthy
Domain Analysis →Valid SSL Certificate
Domain Analysis →Security Headers Present
Domain Analysis →1 Open Port Detected
Infrastructure Exposure →Established Domain (15+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Tech Community Discussion: trust
Tech Community Sentiment →Tech Community Discussion: security incident
Tech Community Sentiment →Certificate Data from TLS Handshake
Certificate Transparency →Established Web Presence (15+ years)
Web Archive History →Domain in 22 Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: ISO 27001
Trust & Compliance Page Scan →Certification Claimed: PCI DSS
Trust & Compliance Page Scan →Certification Claimed: CSA STAR
Trust & Compliance Page Scan →26 Subprocessors Identified
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Deep Document Crawler Results
Deep Document Analysis →Steps to address findings for Datadog
Obtain Datadog's current SOC 2 Type II report (dated within the last 12 months) — request it directly through [trust.datadoghq.com](https://trust.datadoghq.com) or by emailing security@datadoghq.com. If the report period ended more than 6 months ago, also request a bridge letter confirming no material changes to controls. Retain both documents alongside this report as SOC 2 CC9.2 audit evidence.
Request ISO 27001 and PCI DSS documentary evidence — ask Datadog's security team for the ISO 27001 certificate (showing issuing body, certificate number, scope, and expiry) and the PCI DSS Attestation of Compliance. These are standard requests that Datadog's trust center is designed to fulfill via [trust.datadoghq.com](https://trust.datadoghq.com).
Follow up on the March 2026 GitHub Actions exploitation campaign — request a formal vendor statement via your account team or security contact confirming whether Datadog's production infrastructure was affected by the Hackerbot-Claw campaign, what remediation was taken, and whether any customer data was at risk. Document the response in your incident tracking system.
Clarify the HTTP security header configuration for app.datadoghq.com — submit a targeted security questionnaire item asking Datadog to describe the header policy applied to the application endpoint (distinct from the marketing site). This can be resolved in a single exchange and will close the contradiction flagged in contra-2.
Review Datadog's AI data usage terms before enabling AI-powered features — navigate to the [Datadog privacy policy](https://www.datadoghq.com/privacy/) and any AI-specific terms linked from [trust.datadoghq.com](https://trust.datadoghq.com) to confirm whether customer observability data (metrics, logs, traces) is used to train AI models and whether enterprise opt-out controls are available.
Document complementary user entity controls (CUECs) if Datadog is within your SOC 2 boundary — common CUECs for an observability platform include: access control configuration for the Datadog organization, API key rotation policies, log forwarding configuration, and role-based access assignments. Your SOC 2 auditor may request evidence of these controls during fieldwork.
26 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Datadog? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Datadog on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Datadog's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Datadog a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Datadog appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Datadog's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Datadog's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Datadog claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Datadog depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Datadog appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Datadog claims SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, and CSA STAR certifications. Datadog for Government holds FedRAMP authorization at Moderate impact level — independently verifiable at marketplace.fedramp.gov. ThirdProof's assessment cross-references certification attestations on Datadog's trust page with the FedRAMP Marketplace. Organizations evaluating Datadog should confirm that the specific services they use fall within scope — FedRAMP authorization covers the Government deployment, not the commercial platform.
ThirdProof investigated Datadog across 27 intelligence sources and assigned a Low Risk (Tier 4) rating with 88% confidence. Sanctions screening returned clear with no matches found. Domain reputation is clean across 94 security engines with an A+ SSL/TLS grade. No adverse media, enforcement actions, or malware indicators were detected. The 15-year domain history and publicly traded status (NASDAQ: DDOG) provide additional transparency into Datadog's operations and security investments.
Seeing this in an audit? ThirdProof lets you investigate Datadog and every other vendor in your stack — average report time: 7 minutes. Get Datadog's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Datadog across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.