Q39
Are you PCI DSS compliant? At what level?
Datadog is a certified PCI Level 1 Service Provider and complies with PCI v4.0.
ThirdProof independently checks public intelligence sources to show what your team can verify about Datadog before Datadog sends a questionnaire or a security document.
Datadog's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Datadog — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Datadog's own trust page.
✓ FedRAMP Certified — Class C (Moderate) Checked August 2026.
Datadog for Government is FedRAMP Certified at Class C (Moderate) via the Agency path (package FR2023864279A).
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 26 returning usable evidence. The Datadog assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Datadog Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 78% of a 133-question vendor security questionnaire — without waiting for Datadog. The remaining 29 are listed as open, so the follow-up you send is short and specific.
Q39
Datadog is a certified PCI Level 1 Service Provider and complies with PCI v4.0.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
Datadog is GDPR compliant and provides a Data Processing Addendum (DPA) that includes sections on international data transfers with European Commission-approved Standard Contractual Clauses.
Q40
Datadog is HIPAA compliant and will sign a Business Associate Agreement (BAA) with customers that transmit protected health information.
Q23
Datadog uses symmetric encryption at rest with AES-256 standard for indexed logs.
+ 99 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Datadog for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Datadog
Datadog is a mature, enterprise-grade cloud monitoring and observability platform with a Tier 3 (Moderate Risk) rating.
The vendor demonstrates strong compliance credentials, including FedRAMP authorization at the LI-SaaS level (authorized since May 2020), PCI DSS Level 1 certification, HIPAA compliance with BAA support, GDPR and CCPA compliance, and 99.8% uptime SLA. The platform operates with a tightly controlled infrastructure footprint (2 open ports: 80, 443) and maintains clean domain reputation across threat intelligence databases.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this assessment was independently sourced from external registries, threat intelligence databases, public trust pages, and archival media sources without vendor participation.
3 findings identified for Datadog
Three archived news articles from 2026 document significant security incidents involving Datadog infrastructure. The Claude Code hijacking via Sentry article (VentureBeat, June 2026) and two Hackerbot-Claw articles (Hackread, CyberSecurityNews, March 2026) describe active attacks targeting Datadog GitHub repositories via CI/CD misconfiguration. …
Datadog's [AI data usage policy page](https://www.datadoghq.com/legal/service-terms/) exists but does not clearly commit to either training on customer data, prohibiting training, or providing an opt-out mechanism. This ambiguity is significant for organizations concerned about data use in generative AI model training and creates compliance uncertainty.
Datadog's domain appears in 22 threat intelligence (OTX) pulses. For large infrastructure and SaaS vendors, high pulse counts are expected because threat actors commonly impersonate or target these platforms in phishing and attack campaigns. …
Evidence that positively supports Datadog's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Datadog complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Datadog claims SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, and CSA STAR certifications. Datadog for Government is FedRAMP Certified at Class C (Moderate), independently verifiable on the FedRAMP Marketplace. ThirdProof's assessment cross-references certification attestations on Datadog's trust page with the FedRAMP Marketplace. Organizations evaluating Datadog should confirm that the specific services they use fall within scope — FedRAMP authorization covers the Government deployment, not the commercial platform.
ThirdProof investigated Datadog across 27 intelligence sources. Sanctions screening returned clear with no matches found. Domain reputation is clean across 94 security engines with an A+ SSL/TLS grade. No adverse media, enforcement actions, or malware indicators were detected. The 15-year domain history and publicly traded status (NASDAQ: DDOG) provide additional transparency into Datadog's operations and security investments.
Represent Datadog? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Datadog assessment above is already written; ask for it and it lands in your inbox.