Compliance frameworks, security audits, and quality certifications this company maintains.
Grafana Labs maintains SOC 2 Type II certification for Grafana Cloud, demonstrating rigorous security, availability, and confidentiality controls over the observability data — including metrics, logs, and traces — stored and processed on behalf of enterprise customers.
Grafana Labs holds ISO 27001 certification covering its information security management systems for the Grafana Cloud platform, providing enterprise customers with internationally recognized assurance of data protection and security governance practices.
Grafana Labs is fully compliant with the EU General Data Protection Regulation, offering Grafana Cloud customers EU-region data storage options and signed data processing agreements to ensure observability telemetry containing personal data is handled in compliance with GDPR requirements.
Grafana Labs complies with the California Consumer Privacy Act, providing California residents with transparency and control over personal data collected through use of Grafana Cloud accounts and the Grafana.com developer portal.
Grafana Cloud Enterprise supports HIPAA-compliant configurations, enabling healthcare organizations to use Grafana for monitoring clinical application performance and infrastructure without exposing protected health information through improperly secured observability pipelines.
Grafana Labs supports PCI DSS compliance for financial services and e-commerce customers using Grafana Cloud Enterprise, providing controls documentation and architecture guidance for deploying Grafana observability in payment card data environments without creating compliance risks.
Grafana Labs has achieved CSA STAR Level 2 certification, providing third-party validated assurance of cloud security controls for Grafana Cloud, helping enterprise customers evaluate the platform security posture during procurement and vendor security assessments.
Grafana Labs is certified under ISO 27017, the cloud-specific security controls standard, ensuring Grafana Cloud implements additional safeguards appropriate for a multi-tenant cloud service provider handling sensitive engineering and infrastructure telemetry data.
Grafana Labs holds ISO 27018 certification covering protection of personally identifiable information in cloud environments, demonstrating that Grafana Cloud handles customer PII embedded in observability data such as usernames in log lines according to internationally accepted privacy controls.
Grafana Labs is committed to WCAG 2.1 AA accessibility standards for the Grafana dashboard interface, ensuring that platform and SRE engineers with disabilities can access observability dashboards, alerts, and explore workflows with appropriate screen reader and keyboard navigation support.