Third Party Index

Grafana

grafana.com

Transparency

Exemplary

Breakdown
Subprocessor list30 / 30
Processing locations8 / 8
Purposes7 / 7
Data processing addendum12 / 12
Trust center8 / 8
Privacy policy6 / 6
security.txtnot found0 / 6
Security page5 / 5
Status page5 / 5
Vulnerability disclosure5 / 5
Pages still reachable8 / 8
Total94 / 100

Only documents we can retrieve count: a page behind a login or a broken link scores nothing.

Badge

Grafana transparency rating

For Grafana's own site; it updates with the rating.

<a href="https://thirdpartyindex.com/vendors/grafana"><img src="https://thirdpartyindex.com/badge/grafana.svg" alt="Grafana transparency rating on Third Party Index" height="20"></a>
[![Grafana transparency rating on Third Party Index](https://thirdpartyindex.com/badge/grafana.svg)](https://thirdpartyindex.com/vendors/grafana)

Documents

DocumentVerifiedChangedEvidence
Trust center safebase snapshot
Subprocessor list snapshot
Data processing addendum snapshot
Privacy policy snapshot
Terms snapshot
Security page snapshot
Status page statuspage snapshot
Security advisories snapshot

Subprocessors

8 third parties. CSV · Atom

NamePurposeLocationListed since
AlphaAI Technologies (Tavily) Optional: AI featureUSA (Default)
Alphabet Inc., Google (GCP)1600 Amphitheatre Parkway Mountain View, CA 94043 Infrastructure, Cloud Service Provider, Optional: AI featureUSA (Default)*
Amazon.com Inc. (AWS)410 Terry Ave N, Seattle, WA 98109-5210 Infrastructure, Cloud Service Provider, Optional: AI featureUSA (Default)*
Anthropic548 Market St, PMB 90375, San Francisco, CA 94104 Optional: AI featureUSA (Default)
Microsoft Corporation (Azure)One Microsoft Way, Redmond, WA 98052-6399 Infrastructure, Cloud Service ProviderUSA (Default)*
OpenAI3180 18th St., San Francisco, CA 94101 Optional: AI featureUSA (Default)
Palantir Technologies Inc.100 Hamilton Ave. Suite 300 Palo Alto, CA 94301 For customers using Grafana’s Federal Cloud offeringUSA (Default)
Twilio Inc. (Sendgrid)375 Beale St Suite 300 San Francisco, CA 94105 Email, Alerting for SaaSUSA (Default)

Listed as a subprocessor by (21)

Purposes as each company states them.

Security record

What public security catalogs list for Grafana, in their words.

Known exploited vulnerabilities

2 vulnerabilities in Grafana's software that CISA lists as exploited in the wild.

CVEProductVulnerabilityListed
CVE-2021-43798GrafanaGrafana Path Traversal Vulnerability evidence
CVE-2021-39226GrafanaGrafana Authentication Bypass Vulnerability evidence

Source: CISA Known Exploited Vulnerabilities catalog.

Changes

None since tracking began.