{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"infracost","name":"Infracost","domain":"infracost.io","category":"Developer tools","one_liner":"Shift FinOps Left: Proactively Find & Fix Cloud Cost Issues","trust_center_url":"https://security.infracost.io/","security_page_url":null,"url":"https://certreports.com/vendors/infracost/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/infracost/soc-2","evidence":[{"source_type":"trust_center","source_name":"Infracost trust centre (Vanta)","url":"https://security.infracost.io/","fetched_at":"2026-09-18 23:20:25.206202+00","content_hash":"d7b578fcbab9f61474799ffb28381890fb18d5a8f86aa9b29bd1e34714e042de","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/infracost/gdpr","evidence":[{"source_type":"trust_center","source_name":"Infracost trust centre (Vanta)","url":"https://security.infracost.io/","fetched_at":"2026-09-18 23:20:25.206202+00","content_hash":"d7b578fcbab9f61474799ffb28381890fb18d5a8f86aa9b29bd1e34714e042de","wayback_url":null,"quote":"GDPR","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"privacy","url":"https://www.infracost.io/docs/privacy-policy/","availability":"public","detail":null,"as_of":"2026-09-18"},{"kind":"subprocessors","url":"https://security.infracost.io/","availability":"public","detail":"18 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Amazon Web Services","domain":"amazon.com","purpose":"Production infrastructure","location":"US East","vendor_url":"https://certreports.com/vendors/amazon/security"},{"name":"Anthropic","domain":"anthropic.com","purpose":"AI-powered capabilities within the product, as well as limited internal use to support debugging, investigation, and improvement of system behaviour.","location":"US","vendor_url":null},{"name":"Auth0","domain":"auth0.com","purpose":"Authentication of users","location":"US ","vendor_url":null},{"name":"Clearbit","domain":"clearbit.com","purpose":"Customer Relation Management","location":null,"vendor_url":null},{"name":"Close","domain":"close.com","purpose":"Customer Relationship Management","location":"US","vendor_url":"https://certreports.com/vendors/close/security"},{"name":"Common Room","domain":"commonroom.io","purpose":"Customer engagement and product analytics, helping us understand usage patterns and improve customer experience.","location":"US","vendor_url":null},{"name":"Google Workspace","domain":"google.com","purpose":"Workspaces including email","location":"US","vendor_url":null},{"name":"Incident.io","domain":"incident.io","purpose":"Incident management, used internally to detect, manage, and resolve operational incidents affecting our platform.","location":"US & EU","vendor_url":null},{"name":"LaunchDarkly","domain":"launchdarkly.com","purpose":"Feature flagging, enabling controlled rollout and management of product features.","location":"US","vendor_url":"https://certreports.com/vendors/launchdarkly/security"},{"name":"Linear","domain":"linear.app","purpose":"Collaboration","location":"US","vendor_url":null},{"name":"Mixpanel","domain":"mixpanel.com","purpose":"Product analytics","location":null,"vendor_url":"https://certreports.com/vendors/mixpanel/security"},{"name":"Notion","domain":"notion.so","purpose":"Document management","location":"US","vendor_url":"https://certreports.com/vendors/notion/security"},{"name":"Postmark","domain":"postmarkapp.com","purpose":"Sending user emails","location":"US","vendor_url":null},{"name":"Pylon","domain":"usepylon.com","purpose":"Customer support","location":"US","vendor_url":"https://certreports.com/vendors/pylon-usepylon/security"},{"name":"Retool","domain":"retool.com","purpose":"Product analytics","location":null,"vendor_url":"https://certreports.com/vendors/retool/security"},{"name":"Segment","domain":"segment.com","purpose":"Product analytics","location":"US","vendor_url":"https://certreports.com/vendors/segment/security"},{"name":"Sentry","domain":"sentry.io","purpose":"Error analytics","location":null,"vendor_url":null},{"name":"Stripe","domain":"stripe.com","purpose":"Payment processor","location":null,"vendor_url":"https://certreports.com/vendors/stripe/security"}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-20T07:02:41.613Z"}