# Sifflet

Sifflet (siffletdata.com): subprocessors, data processing agreement, security documents and changes, as monitored by Third Party Index.

- Page: https://thirdpartyindex.com/vendors/sifflet
- Documents last verified: 2026-09-30
- Transparency rating: 89/100 (how much it publishes, not how secure it is)
- Cite as: Sifflet, Third Party Index, https://thirdpartyindex.com/vendors/sifflet (data CC BY 4.0)

## Documents

| Document | URL | Last verified | Last changed |
|---|---|---|---|
| Trust center | https://trust.siffletdata.com/ | 2026-09-30 | 2026-09-30 |
| Subprocessor list | https://trust.siffletdata.com/subprocessors | 2026-09-30 | 2026-09-30 |
| Data processing addendum | https://www.siffletdata.com/dpa | 2026-09-30 | 2026-09-30 |
| Privacy policy | https://www.siffletdata.com/privacy-policy | 2026-09-30 | 2026-09-30 |
| Terms | https://www.siffletdata.com/terms-of-use | 2026-09-30 | 2026-09-30 |
| Security page | https://docs.siffletdata.com/docs/security | 2026-09-30 | 2026-09-30 |
| Status page | https://docs.siffletdata.com/docs/sifflet-status | 2026-09-30 | 2026-09-30 |

## Subprocessors (9)

As its own list states them.

| Subprocessor | Purpose | Location | Listed since |
|---|---|---|---|
| [Amazon Web Services](https://thirdpartyindex.com/vendors/amazon-web-services.md) | Cloud provider; See  for details. \* \_Categories\_: application data, customer asset metadata, \*\*customer asset data\*\* \* \_Retention\_: duration of the contract | Customer's choice (EU or US) | 2026-09-30 |
| [Anthropic](https://thirdpartyindex.com/vendors/anthropic.md) | \*\*Optional:\*\* used when the AI chat feature is explicitly enabled. Customer data is not used to train AI models. \* \_Categories\_: customer asset metadata \* \_Retention\_: up to 30 days (abuse monitoring only); LLM inference | US | 2026-09-30 |
| [Google Cloud](https://thirdpartyindex.com/vendors/google-cloud.md) | \*\*Optional.\*\* Used if \[data sharing to BigQuery\[( is enabled. \* \_Categories\_: customer asset metadata \* \_Retention\_: duration of the contract; Cloud provider | EU | 2026-09-30 |
| [Grafana Cloud](https://thirdpartyindex.com/vendors/grafana.md) | Application logs can contain some asset metadata or application data, but asset data is never logged. \* \_Categories\_: application data, customer asset metadata \* \_Retention\_: up to 30 days; Observability | EU (Ireland) | 2026-09-30 |
| [Microsoft Azure](https://thirdpartyindex.com/vendors/microsoft.md) | \*\*Optional.\*\* Used when \[Private Link with Azure\]( is enabled.; Cloud provider | EU (no retention) | 2026-09-30 |
| [OpenAI](https://thirdpartyindex.com/vendors/openai.md) | \*\*Optional.\*\* Powers the following features (refer to the documentation for how to disable them): \* Automated incident description and root cause analysis \* Monitor recommendations \* Monitor creation from natural language, including text-to-SQL. Data is not used for training. Prompts sent to the OpenAI API may contain small samples of asset data to inform incident analysis. \* \_Categories\_: \*\*Customer asset data\*\* and metadata \* \_Retention\_: up to 30 days (abuse monitoring only); LLM inference | US | 2026-09-30 |
| [Pendo](https://thirdpartyindex.com/vendors/pendo.md) | Pendo data includes Sifflet user emails (but not any sensitive data, including asset data or credentials). \* \_Categories\_: application data \* \_Retention\_: up to 7 years; Product analytics | EU | 2026-09-30 |
| [Sentry](https://thirdpartyindex.com/vendors/sentry.md) | Error monitoring; Errors can contain some asset metadata or application data. \* \_Categories\_: application data, customer asset metadata \* \_Retention\_: up to 90 days | US | 2026-09-30 |
| [Snowflake](https://thirdpartyindex.com/vendors/snowflake.md) | \* \_Categories\_: application data, customer asset metadata \* \_Retention\_: duration of the contract; Data warehouse | Europe (UK) | 2026-09-30 |

Read from ([evidence](https://thirdpartyindex.com/evidence/25417)). CSV: https://thirdpartyindex.com/vendors/sifflet/subprocessors.csv

## Compliance

As its trust center lists them.

- Audited: SOC 2 Type II, ISO/IEC 27001 ([evidence](https://thirdpartyindex.com/evidence/25407))
- Claimed: GDPR, CCPA/CPRA ([evidence](https://thirdpartyindex.com/evidence/25407))

## Listed as a subprocessor by (0)

No tracked vendor lists it.

---

Third Party Index (https://thirdpartyindex.com) monitors vendors' public security and privacy documents and keeps each version as evidence. Data CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/); vendors' own documents are theirs. API: https://thirdpartyindex.com/api
