PostHog security review: SOC 2, AI training & subprocessors

What PostHog publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.

Transparency score
90/100
SOC 2
SOC 2 Type II
ISO 27001
Not mentioned
Trains AI on your data?
See quotes
Subprocessors
List published

"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.

Does PostHog train AI on your data?

Statements differ between pages

PostHog's own words (posthog.com/privacy):

PostHog will not permit third parties to use Customer Content to train their machine learning models; any use of Customer Content for Product and Model Development will be solely for PostHog's own products, services, and internal models.

Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.

Other statements we found
Product and model development Where Customer Content (meaning any software, information, content, data, or related materials provided by or on behalf of Customer or made available through use of PostHog's products or services ("Customer Content")) is submitted to PostHog or th…
posthog.com/privacy
We won't share your data with outside companies to train their models – anything we use stays internal to PostHog.
posthog.com/privacy

Different pages say different things. This is often a split between business plans and free or consumer plans. Read each quote for the plan you would use.

Certifications PostHog claims

Certification or reportMentioned on
SOC 2 Type IIposthog.com/handbook/company/security
HIPAAposthog.com/dpa

Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.

A certification on a website is a claim. For anything sensitive, ask PostHog for the SOC 2 report or ISO certificate.

PostHog subprocessors

PostHog publishes its subprocessor list at posthog.com/subprocessors, but it couldn't be read automatically. Open it directly.

Security features mentioned

SSO / SAMLMentioned
SCIM provisioningNot found
Multi-factor authenticationMentioned
Encryption at restNot found
Encryption in transitMentioned
Penetration testingMentioned
Bug bounty / disclosure programMentioned
Audit logsNot found
Data residencyMentioned EU, United States, Germany
security.txt contactmailto:security-reports@posthog.com

Key documents

Trust / security centerposthog.com/handbook/company/security
Privacy policyposthog.com/privacy
Subprocessor listposthog.com/subprocessors
Data processing agreement (DPA)posthog.com/dpa
AI policyNot found
TermsNot found
Status pageNot found

How this score is worked out

CheckPointsResult
Security or trust page15Yes
Certifications listed20Yes
Privacy policy10Yes
Subprocessor list15Yes
DPA available10Yes
AI training policy stated15Yes
security.txt contact5Yes
Status page10No

The score measures how much of a standard security review our reader could answer from PostHog's public pages. It is not a rating of how secure PostHog is, and a "No" can mean the document exists where our reader couldn't see it.

Check another vendor

Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.

Other Developer & data vendors

Airbyte · Algolia · Amplitude · Auth0 · CircleCI · Clerk · Cloudflare · Confluent · Databricks · Datadog · DigitalOcean · Fastly

Source: PostHog's own public website (5 pages read on October 10, 2026). Stormap is not affiliated with PostHog. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.