Statsig
Security and trust center evidence
Statsig is your modern product development platform, with an integrated toolkit for experimentation, feature management, product analytics
Summary
Statsig has 7 vendor-stated rows in the CertReports index, last verified 21 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 Type II on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 21 Sep 2026, CertReports holds 7 vendor-stated rows for Statsig, drawn from custom. Statsig states on its trust centre that it holds a SOC 2 Type II report, a data processing agreement, an ISO/IEC 27001 certificate, a SOC 1 Type II report, an ISO/IEC 27017 certificate, an ISO/IEC 27018 certificate and an CCPA / CPRA privacy notice, captured 21 Sep 2026; these are vendor statements, not independent confirmations. No public evidence was found for HIPAA, PCI DSS and FedRAMP as of 21 Sep 2026; that is a gap in the public record, not a finding of non-coverage, and the vendor can supply it under NDA.
- SOC 2: Vendor states SOC 2 Type II on its trust centre, vendor-stated as of 21 Sep 2026
- GDPR: Vendor states GDPR on its trust centre, vendor-stated as of 21 Sep 2026
Facts only, each dated; nothing here is inferred, scored or advised.
Among developer tools vendors
0verified rows
Category median 0, across 196 indexed developer tools vendors. Statsig has no registry-verified row yet, like 69 percent of them; its evidence is vendor-stated or reported.
Compare with similar vendors
Pick your own comparisonCompliance grid
SOC 2Vendor-statedVendor states SOC 2 Type II on its trust centre
as of 21 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 21 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO 27001 on its trust centre
as of 21 Sep 20261 source
SOC 1Vendor-statedVendor states SOC 1 Type II on its trust centre
as of 21 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO 27017 on its trust centre
as of 21 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO 27018 on its trust centre
as of 21 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 21 Sep 20261 source
Legal artefacts
Subprocessors (9)
- ACamazonwebservices.comCloud hosting and infrastructure provider; generative AI technology used to enhance Amplitude's AI features (AWS Bedrock). · United States, Germany
- DatadogLogging and operational monitoring. · United States
FivetranCloud-based data movement platform. · United States, Germany
GoogleGenerative AI technology, delivered via Google Vertex AI, used to enhance Amplitude’s AI features; cloud hosting and infrastructure provider for the Statsig-branded Amplitude Services (US only). · United States, EU
MicrosoftCloud service Provider for the Statsig-branded Amplitude Services. · United States
MongoDBDatabase provider for the Statsig-branded Amplitude Services. · United States
OpenAIGenerative AI technology used to enhance Amplitude’s AI features. · United States, EU
SnowflakeData warehousing services (if Customer has purchased an applicable add-on service or is using AI Feedback). · United States, Germany (for AI Feedback only)
WizSecurity vulnerability management and detection. · United States, Germany
Security profile
Displayed as a security profile from public statements, not as attestations, as of 21 Sep 2026.
Change history
- 22 Sep 2026First indexed by CertReports7 evidence rows across 7 frameworks entered the index.
Similar vendors with evidence
Related by product tags and the Developer tools category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.
GrowthBook
Developer tools
Open source feature flagging and A/B testing
Split
Developer tools
Split.io feature flags connects critical impact data and alerts you whether your software changes are making things better or
Laravel
Developer tools
Laravel is a framework for building modern web apps and AI
Nango
Developer tools
A single API for all your integrations
Evidence against regulations
All regulations for StatsigHow much of each regulation’s vendor requirements Statsig’s public evidence reaches.
Reviewing a vendor on public evidence
All articlesSOC 2 Type I vs Type II: what each one proves to a buyer
Solomon Amos · 14 Sep 2026 · 10 min read