Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with New Relic, your compliance team needs documented proof they can be trusted. ThirdProof investigated New Relic across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
24 sources queried. 94% confidence. Every New Relic investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get New Relic's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 36% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
New Relic Inc. holds ISO/IEC 27001:2013 certification with annual surveillance audits, certified by A-LIGN Compliance and Security, Inc.
Q41
FedRAMP authorized: Product: New Relic; Provider: New Relic; Status: Compliant; Impact Level: Moderate; Authorization Date: 2020-02-27T05:00:00.000Z
Q40
New Relic offers HIPAA-compliant services and requires Business Associate Agreements (BAA) for customers processing Protected Health Information (PHI).
Q42
New Relic provides Data Processing Addendums (DPA) compliant with GDPR requirements and Standard Contractual Clauses for EU and Swiss data protection.
+ 4 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get New Relic's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
New Relic is not listed on the FedRAMP Marketplace.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
24
Sources Queried
22
Sources With Data
March 25, 2026
Last Assessed
AI-generated analysis for Newrelic
New Relic (newrelic.com) is an AI-powered observability platform that has been assessed at Risk Tier 3 (Moderate Risk) with a 94% confidence score, reflecting a well-established vendor with strong compliance credentials offset by several operational and transparency gaps requiring attention. New Relic presents a number of meaningful positive signals that distinguish it from typical SaaS vendors at this tier:
Independence Statement
All evidence in this report was independently sourced from external data registries, public domain analysis tools, threat intelligence databases, and compliance certification registries without any participation, disclosure, or input from New Relic.
3 findings identified for Newrelic
The SSL certificate for newrelic.com expires in 20 days.
newrelic.com received a poor grade (D-) from Mozilla HTTP Observatory. Multiple security headers or configurations are missing. Note: This scan was performed on the marketing site (newrelic.com). The application endpoint (login.newrelic.com) may have different security headers. Verify the application domain separately.
An AI-specific data usage policy was not discoverable for newrelic.com through automated scanning of common policy paths and web search. The vendor may publish relevant data handling commitments in enterprise agreement documents (DPAs, product terms, licensing portals) that are not indexed at standard public URLs. Request the vendor's Data Protection Addendum or AI-specific terms directly.
22 positive signals verified
No LEI Registry Match (Expected for Most Companies)
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Recent News Coverage
Adverse Media Scan (Fallback)
No Firmographic Data Available
Company Intelligence →2 Open Ports Detected
Infrastructure Exposure →Established Domain (19+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Minimal Tech Community Discussion
Tech Community Sentiment →Certificate Data from TLS Handshake
Certificate Transparency →Web Archive History Unavailable
Web Archive History →Domain in 50 Threat Intelligence Pulses
Threat Intelligence (OTX) →Low Abuse Score: 0% (1 reports)
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →14 Subprocessors Identified
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →HITRUST Directory Match — Manual Verification Required
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Steps to address findings for Newrelic
Verify TLS certificate renewal urgently: Check https://www.SSL/TLS analysis service.com/ssltest/analyze.html?d=newrelic.com within the next 5 business days to confirm the certificate has been renewed. If not, contact New Relic's security team directly and document their response.
Request AI data handling terms: Contact your New Relic account representative and ask for the current Data Protection Addendum (DPA) and any AI-specific product terms. Ask explicitly whether customer telemetry data is used to train AI models and which third-party AI providers (if any) process that data. Attach the written response to your vendor risk record.
Request the SOC 2 Type II report and bridge letter: New Relic claims SOC 2 on their trust portal (trust.newrelic.com). Contact their security team to request the full Type II audit report and a bridge letter covering the period since the last audit. Many vendors fulfill this via their trust portal — check trust.newrelic.com first or email security@newrelic.com.
Verify HITRUST certification status: The vendor has publicly communicated HITRUST certification via official channels, but independent registry confirmation was not achieved. Visit https://hitrustalliance.net/certified-entities/ or contact the HITRUST Alliance directly to confirm current certification status and expiry date. This is particularly important if your organization is subject to HIPAA obligations.
Verify application-layer HTTP security headers: The HTTP security scanner scan was performed on the marketing site (newrelic.com), which scored D- (25/100). Request that your New Relic security contact confirm the header configuration for the application endpoint (login.newrelic.com) and any data ingestion APIs. You can independently verify at https://observatory.mozilla.org/analyze/login.newrelic.com.
Document FedRAMP authorization in your risk register: New Relic holds FedRAMP Moderate authorization (verified via https://marketplace.fedramp.gov/products/F1607057910, authorized February 2020). If your organization operates under FedRAMP requirements, note this as a strong positive control mitigating a range of federal security baseline requirements.
24 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you New Relic? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is New Relic on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is New Relic's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is New Relic a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has New Relic appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is New Relic's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are New Relic's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does New Relic claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does New Relic depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has New Relic appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Seeing this in an audit? ThirdProof lets you investigate New Relic and every other vendor in your stack — average report time: 7 minutes. Get New Relic's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates New Relic across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.