Or browse the quick start

Security & compliance

Protect ingest, redact sensitive fields, and handle data subject requests.

Project security settings

Admins and owners open Settings → Security for each project:

  • Ingest IP allowlist — restrict which IPs may POST logs with a valid token
  • Field redaction — strip sensitive metadata keys and card/SSN patterns at ingest
  • Custom PII regex — per-project patterns applied to messages and metadata values
  • GDPR erasure — delete logs matching a metadata subject id (audit logged)

API token scopes

Create ingest-only, read-only, or full-access tokens under Settings → API keys. Revoke individual tokens without rotating the primary project token.

Account sessions

Signed-in users manage active sessions at Dashboard → Account.

Trust center

Public overview: subprocessors, practices, and disclosure policy at /security and responsible disclosure.