Announcing SOC 2 and our commitment to privacy and security
Today we are thrilled to announce that bitdrift has partnered with Assurance Lab to achieve the SOC 2 type I compliance certification. Customers can now rest easy that their telemetry data is in good hands and governed by audited industry best practices. In this post we will discuss why achieving SOC 2 is such an important milestone, and also how security and privacy are a core part of the bitdrift DNA.

Bitdrift flips observability on its head and is uniquely powerful and cost effective: we send no data by default, and instead use sophisticated local storage coupled with a real-time control plane to send only the data that is needed to understand customer experiences, and nothing more, yielding unmatched observability ROI.
While we think both the capabilities and cost profile of our mobile observability offering are unparalleled, we understand how critical security and privacy are to our customers: telemetry directly from mobile devices includes PII of the most privacy sensitive nature: photos, locations, credit card numbers, search history, and so on. The systems that store and process this data must be built from the ground up with privacy and security a primary goal.
aim to achieve SOC 2 type II certification in the next 6-9 months. Update: We got our SOC 2 Type II certification, more information here.
Achieving SOC 2 demonstrates our long term commitment to security and compliance and is a requirement for bitdrift usage at any large company.
 bitdrift was founded on the belief that privacy and security are a critical foundation of everything that we build and how we operate our business. This is especially critical for mobile observability where the amount of potential PII is staggering. Apart from our investment in foundational privacy and security controls via our SOC 2 compliance program, we have also built privacy and security into the Capture product as a first class concern. Some examples include:
bitdrift was founded on the belief that privacy and security are a critical foundation of everything that we build and how we operate our business. This is especially critical for mobile observability where the amount of potential PII is staggering. Apart from our investment in foundational privacy and security controls via our SOC 2 compliance program, we have also built privacy and security into the Capture product as a first class concern. Some examples include:
SOC 2 certification
SOC 2 is an industry standard compliance program aimed at documenting and auditing a wide range of internal controls that ultimately impact the security, availability, confidentiality, processing integrity, and privacy of customer data. We have invested significant engineering resources making sure that we adhere to the rigorous standards set forth by the specification. While we are announcing SOC 2 type I today, we are committing to a continuous auditing program andPrivacy and security focused observability

- The capture SDK and SaaS has been very carefully designed and audited to not collect any PII directly. (Obviously customers can manually collect telemetry with PII in it if they choose.)
- Our novel session replay implementation is both extremely efficient and also designed from the ground up to be privacy conscious and free of PII. The majority of session replay solutions out there capture pixel perfect screen representations which mean that they can rarely be deployed at scale in production due to both performance and privacy concerns. The bitdrift Capture session replay implementation can be worry free deployed at scale!
