Vannus records that this vendor names one model provider in its own documentation. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.
Multi-source observability dashboard — visualises metrics, logs and traces from Prometheus, Jaeger, and OpenTelemetry, creating the literal mirror that forces architects to see the operational reflection of their systems
The Assistant uses Anthropic's Claude models, either through Anthropic directly, Google's Vertex AI platform, or Amazon Bedrock.
Not yet assessed. We publish a sovereignty position only where the vendor documents one — we do not infer it from a domain or a company name.
Grafana publishes a list of the other companies it uses to process customer data. It names 8 of them, each shown below with the location the vendor lists it under, in the vendor’s own words.
Grafana marks some of those entries and qualifies them below the table. Its words, kept with the entries because the qualification is part of the answer:
* Additional regions such as EU are available. Customers may select other regions subject to availability.
Taken together those entries name at least USA. That is what our place list could match in the vendor’s own words above, so treat it as a floor rather than the whole of it — the entries themselves are the record.
These are other companies, not Grafana. Where a sub-processor is listed as operating is a fact about that company. It is not a statement about where Grafana keeps your data, which Vannus publishes separately and only from a document in which the vendor says so.
Read from grafana.com on 2026-09-16. Every entry above is a verbatim span of that page.
This is the vendor’s own disclosure, reproduced. Vannus has not audited what any of these companies do with your data, and a list can change without notice. Treat it as a starting point for your own review, not a legal determination, and take advice on anything that matters.
Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →