Compliance frameworks, security audits, and quality certifications this company maintains.
Sentry maintains SOC 2 Type II certification with annual third-party audits covering the security, availability, and confidentiality of error event data, stack traces, session replays, and profiling data processed on behalf of its 100,000+ customer organizations.
Sentry holds ISO 27001 certification, demonstrating that its information security management system meets international standards for protecting customer application error data, source maps, and session recording content stored on the Sentry platform.
Sentry complies with GDPR for European customers, offering data processing agreements, EU data residency options on Sentry Business and Enterprise plans, and configurable PII scrubbing rules that prevent personal data from appearing in error event payloads and session replays.
Sentry honors CCPA rights for California residents, providing mechanisms for data deletion requests, opt-out of data sale, and clear disclosure of what personal data is collected through Sentry SDK integrations on behalf of its customers.
Sentry supports HIPAA compliance for healthcare software teams through Business Associate Agreements on Enterprise plans, combined with configurable data scrubbing rules that prevent protected health information from being captured in error events, breadcrumbs, or session replays.
Sentry helps payment application teams meet PCI DSS requirements by providing SDK-level data scrubbing configuration that prevents payment card numbers and authentication credentials from appearing in captured error payloads or performance traces sent to the Sentry platform.
Sentry maintains CSA STAR Level 1 certification, publishing its cloud security controls and practices through the Cloud Security Alliance registry to give enterprise customers transparency into how application monitoring data is secured in the Sentry cloud infrastructure.
Sentry meets WCAG 2.1 AA accessibility guidelines across the Sentry web application, ensuring that developers with disabilities can fully access the error monitoring dashboard, issue details, session replay viewer, and performance tracing interface.
Security
Penetration Testing
CompliantSentry undergoes annual third-party penetration testing of its web application and API infrastructure, with findings triaged, remediated, and reviewed by the security team before enterprise customer audit cycles and as part of ongoing SOC 2 audit evidence.
Sentry participates in cross-border data transfer frameworks ensuring that application error data, stack traces, and session recording content transferred between the US and EU is handled in compliance with applicable privacy regulations under standard contractual clauses.