Skip to main content
Skip to main content

Datadog Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about Datadog before Datadog sends a questionnaire or a security document.

Datadog's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Datadog — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Datadog's own trust page.

FedRAMP Certified — Class C (Moderate) Checked August 2026.

Datadog for Government is FedRAMP Certified at Class C (Moderate) via the Agency path (package FR2023864279A).

Risk
Tier 3Moderate Risk
Evidence confidence
100%
26 of 27 sources returned data
Questionnaire
104 / 133 answered
78% from public evidence
Last assessed
Aug 27, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 16.1 years🟢Infrastructure: 2 open ports, 0 CVEs
FedRAMP Status
Datadog is listed on the FedRAMP Marketplace — Independently verified (checked August 2026).
SOC 2 Status
Datadog — SOC 2: Vendor attested — trust page. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
Datadog returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned Datadog a Moderate Risk tier across 27 intelligence sources, 26 of which returned usable evidence (evidence confidence 100%).

27 sources queried, 26 returning usable evidence. The Datadog assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest Datadog Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

104 questions answered before Datadog responds.

ThirdProof used public evidence to pre-fill 78% of a 133-question vendor security questionnaire — without waiting for Datadog. The remaining 29 are listed as open, so the follow-up you send is short and specific.

Q39

Are you PCI DSS compliant? At what level?

Datadog is a certified PCI Level 1 Service Provider and complies with PCI v4.0.

Public evidencehigh confidence

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: Vendor attested — trust page

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

Datadog is GDPR compliant and provides a Data Processing Addendum (DPA) that includes sections on international data transfers with European Commission-approved Standard Contractual Clauses.

Public evidencehigh confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

Datadog is HIPAA compliant and will sign a Business Associate Agreement (BAA) with customers that transmit protected health information.

Public evidencehigh confidence

Q23

Is data encrypted at rest? What encryption standard is used (e.g., AES-256)?

Datadog uses symmetric encryption at rest with AES-256 standard for indexed logs.

Public evidencehigh confidence

+ 99 additional evidence-backed answers

Get the Complete Datadog Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before Datadog sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • FedRAMP — independently verified
  • No Sanctions Matches Found
  • FedRAMP Authorization Independently Verified
  • FedRAMP Authorization Confirmed via Registry
  • No SEC Enforcement Filings Found
  • Legal Entity Actively Registered

Still requires vendor confirmation

  • Current SOC 2 report and its audit scope
  • Data Security — 6 of 14 questions need vendor input
  • Access Control — 3 of 12 questions need vendor input
  • Vulnerability Management — 3 of 8 questions need vendor input
  • Physical Security — 3 of 4 questions need vendor input

Reviewing Datadog for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for Datadog

Datadog is a mature, enterprise-grade cloud monitoring and observability platform with a Tier 3 (Moderate Risk) rating.

Area Requiring Attention

The vendor demonstrates strong compliance credentials, including FedRAMP authorization at the LI-SaaS level (authorized since May 2020), PCI DSS Level 1 certification, HIPAA compliance with BAA support, GDPR and CCPA compliance, and 99.8% uptime SLA. The platform operates with a tightly controlled infrastructure footprint (2 open ports: 80, 443) and maintains clean domain reputation across threat intelligence databases.

The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.

Independence Statement

All evidence in this assessment was independently sourced from external registries, threat intelligence databases, public trust pages, and archival media sources without vendor participation.

Investigation Findings

3 findings identified for Datadog

1 high1 medium1 low
high

Significant adverse media in historical archives

Three archived news articles from 2026 document significant security incidents involving Datadog infrastructure. The Claude Code hijacking via Sentry article (VentureBeat, June 2026) and two Hackerbot-Claw articles (Hackread, CyberSecurityNews, March 2026) describe active attacks targeting Datadog GitHub repositories via CI/CD misconfiguration. …

medium

AI training data practices unclear

Datadog's [AI data usage policy page](https://www.datadoghq.com/legal/service-terms/) exists but does not clearly commit to either training on customer data, prohibiting training, or providing an opt-out mechanism. This ambiguity is significant for organizations concerned about data use in generative AI model training and creates compliance uncertainty.

low

Threat intelligence pulses detected

Datadog's domain appears in 22 threat intelligence (OTX) pulses. For large infrastructure and SaaS vendors, high pulse counts are expected because threat actors commonly impersonate or target these platforms in phishing and attack campaigns. …

Security Strengths

Evidence that positively supports Datadog's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

No Sanctions Matches Found

Sanctions & Watchlist Screening

FedRAMP Authorization Independently Verified

Trust & Compliance Page Scan

FedRAMP Authorization Confirmed via Registry

Certification Registry Verification

No SEC Enforcement Filings Found

SEC Filing Search

Legal Entity Actively Registered

Business Registration

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

Datadog complete vendor assessment

Tier 3
Moderate Risk
104 / 133
questionnaire answers
27
sources checked
Aug 27, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 27, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

Datadog Compliance and Certification Status

Datadog claims SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, and CSA STAR certifications. Datadog for Government is FedRAMP Certified at Class C (Moderate), independently verifiable on the FedRAMP Marketplace. ThirdProof's assessment cross-references certification attestations on Datadog's trust page with the FedRAMP Marketplace. Organizations evaluating Datadog should confirm that the specific services they use fall within scope — FedRAMP authorization covers the Government deployment, not the commercial platform.

Datadog Security Posture

ThirdProof investigated Datadog across 27 intelligence sources. Sanctions screening returned clear with no matches found. Domain reputation is clean across 94 security engines with an A+ SSL/TLS grade. No adverse media, enforcement actions, or malware indicators were detected. The 15-year domain history and publicly traded status (NASDAQ: DDOG) provide additional transparency into Datadog's operations and security investments.

Frequently asked about Datadog

Does Datadog have SOC 2 Type II?+
Datadog states that it maintains SOC 2 on its trust page. Because SOC 2 reports are generally confidential and there is no public SOC 2 registry, ThirdProof classifies this as vendor-attested until the current report and its scope have been reviewed. Request the report directly to confirm the audit period and which systems are in scope.
Is Datadog on the OFAC sanctions list?+
Datadog returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is Datadog's vendor risk tier?+
ThirdProof assigned Datadog a risk tier of Moderate Risk as of August 2026, with an evidence confidence of 100% across 27 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning Datadog.
Has Datadog had any data breaches or security incidents?+
ThirdProof's assessment as of August 2026 records 1 incident-related finding for Datadog, of which 1 is rated high severity or above. The most severe concerns significant adverse media in historical archives. Each finding states whether the incident affected Datadog's own systems, a customer's environment, or a third party — a distinction that changes what you should ask about — and links to the source it was drawn from. The complete assessment carries all of them with their evidence.
Is Datadog PCI DSS compliant?+
Datadog is a certified PCI Level 1 Service Provider and complies with PCI v4.0. ThirdProof records this from Datadog's published compliance evidence; request the current Attestation of Compliance to confirm the scope that applies to your integration.
Does Datadog support HIPAA and sign BAAs?+
Datadog is HIPAA compliant and will sign a Business Associate Agreement (BAA) with customers that transmit protected health information. If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a Datadog security questionnaire?+
Yes. ThirdProof answered 104 of 133 questions (78%) about Datadog from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 29 are listed as open, so the follow-up you send Datadog is short and specific.
What evidence should I request from Datadog?+
Public evidence settles a large part of the review, so the request you send should be short. Ask Datadog for the current SOC 2 report and, where applicable, a bridge letter covering the period since the report date; the audit scope — which systems and services the report actually covers; written answers on data security, access control, vulnerability management; contractual commitments, cyber insurance, and the current subprocessor list. Everything ThirdProof could already establish is recorded with its source, so you are not asking Datadog to re-confirm what is already documented.

If Datadog is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Datadog assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required