Vannus / Catalog / Sentry

Sentry

Vannus records that this vendor routes across several model providers — not captured by one. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

Determination
Contracts with Functional Software, Inc. (United States) — within reach of US legal process.
sentry.io · read 2026-09-16
read from terms of service

Error tracking and performance monitoring for applications

devops, monitoring, observability
What the vendor's own documentation says
We built it to flexibly adopt the best frontier models from OpenAI, Anthropic, Google, and others.
blog.sentry.io ↗ Vendor-sourcedQuote re-checked 14 Sep 2026
Who controls it
US corporate controlYes — a US parent or US contracting entity is on the public record · clause re-checked 17 Sep 2026
Contracting entityFunctional Software, Inc. d/b/a Sentry
Governing lawthe laws of the State of California and the United States without regard to conflicts of laws provisions
Trains on your dataNo — on the vendor's default plan

Training and retention posture varies by plan. What we publish above describes the vendor’s default plan; enterprise, team and API agreements frequently differ, often materially, and a contract can override the published default entirely. Check your own plan and contract before relying on this row.

This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This describes who controls the vendor. A tool can score modestly on one and strongly on the other, and many do.

On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.

Signals on file
Zero data retention
Yes — states it retains no prompt data

The vendor's published or catalog-recorded posture — the concrete facts this grade is built from. A full audit verifies each against the vendor's current documentation.

Who else handles your data

Sentry publishes a list of the other companies it uses to process customer data. It names 8 of them, each shown below with the location the vendor lists it under, in the vendor’s own words.

Amazon Web Services, Inc. 410 Terry Avenue North Seattle, WA 98109 United States · European Union United StatesAnthropic, PBC 548 Market St San Francisco, CA 94104 United States · United StatesCloudflare, Inc. 101 Townsend St San Francisco, CA 94107 United States · European Union United StatesGoogle LLC (Google Cloud Platform) 1600 Amphitheatre Parkway Mountain View, CA 94043 United States · European Union United StatesIntercom, Inc. 55 2nd St, 4th Fl San Francisco, CA 94105 United States · United StatesOpenAI, L.L.C. 3180 18th St. San Francisco, CA 94110 United States · United StatesSinch Email (Mailgun) 112 E Pecan St, #1135 San Antonio, TX 78205 United States · European UnionTwilio Inc. (SendGrid) 101 Spear Street, First Floor San Francisco, CA 94105 United States · United States

Taken together those entries name at least European Union, United States. That is what our place list could match in the vendor’s own words above, so treat it as a floor rather than the whole of it — the entries themselves are the record.

These are other companies, not Sentry. Where a sub-processor is listed as operating is a fact about that company. It is not a statement about where Sentry keeps your data, which Vannus publishes separately and only from a document in which the vendor says so.

Read from sentry.io on 2026-09-16. Every entry above is a verbatim span of that page.

This is the vendor’s own disclosure, reproduced. Vannus has not audited what any of these companies do with your data, and a list can change without notice. Treat it as a starting point for your own review, not a legal determination, and take advice on anything that matters.

Compliance the vendor states
SOC2GDPR

Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.

How this grade is set

Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit Sentry ↗ Grade your whole stack →