Security & compliance
Protect ingest, redact sensitive fields, and handle data subject requests.
Project security settings
Admins and owners open Settings → Security for each project:
- Ingest IP allowlist — restrict which IPs may POST logs with a valid token
- Field redaction — strip sensitive metadata keys and card/SSN patterns at ingest
- Custom PII regex — per-project patterns applied to messages and metadata values
- GDPR erasure — delete logs matching a metadata subject id (audit logged)
API token scopes
Create ingest-only, read-only, or full-access tokens under Settings → API keys. Revoke individual tokens without rotating the primary project token.
Account sessions
Signed-in users manage active sessions at Dashboard → Account.
Trust center
Public overview: subprocessors, practices, and disclosure policy at /security and responsible disclosure.