Prevents falling behindOff-the-shelf productEstablished, AI retrofitted

Sentry

Functional Software, Inc. d/b/a Sentry, United States ·sentry.io· As of: 2026-08-25

Receives exceptions and timing measurements from a running application, groups alike incidents into a single entry and shows the line of code together with the change that last touched it, so an outage surfaces inside the team before a customer reports it.

Work through this tool with an AI

Our verdict

Error monitoring is bought basic equipment. Every competitor has it, everyone gets it at the same price, and so no edge comes out of it. It becomes noticeable in its absence. Leave it out and you learn about the outage through support, then argue about a timestamp somebody read off a screenshot. What the tool actually delivers is the grouping: two hundred thousand events become forty issues, each with frequency, affected users and the change that triggered it. That grouping is the real work, and it is also where a self-build breaks. The AI layer on top changes nothing about the classification. It reads the same stack trace faster than a person reads it, and it costs more per head than the plan underneath.

Evidence:As of 2024-05-29Data processing addendum version 5.1.0 of 29 May 2024: Functional Software, Inc. as processor, effectiveness through electronic acceptance, express prohibition on transferring special categories of personal data, application to Sentry and Codecov, destruction after the term expires without a stated period, audit rights once in twelve months at the customer's cost, and Schedule 3 with the Data Privacy Framework, standard contractual clauses 2021/914 and UK addendum B1.0Open sourceAs of 2026-06-01Sub-processor list 2.3.0: eight recipients with address, processing country and purpose, among them Anthropic, PBC and OpenAI, L.L.C. with the United States alone for AI and model services, plus the three affiliates in Vienna, Toronto and SchipholOpen sourceAs of 2025-10-29Privacy policy of 29 October 2025: self-certification of Functional Software, Inc. under the EU-US Data Privacy Framework including the UK and Swiss versions, plus the express statement that this policy does not apply to data submitted to the ServiceOpen sourceAs of 2026-08-25Overview of the legal documents with their version dates: healthcare amendment 15 January 2026, privacy policy 29 October 2025, data processing addendum 29 May 2024, terms of service 12 February 2024Open sourceAs of 2026-08-25Security page: operation on Google Cloud Platform in a multi-tenant setup, hourly encrypted backups in several regions, backups dropping ninety days after creation, event data becoming inaccessible within 24 hours of an account deletion, an annual penetration test against an isolated clone, the attestations SOC 2 Type 1, SOC 2 Type 2, ISO 27001 and the US health law attestation, and the scope of the audit log with event type, person, timestamp and IP addressOpen sourceAs of 2026-08-25Trust page: references to the AI privacy principles, the Seer privacy overview and the self-certification for cross-border transfers, plus the note that the SOC 2 report and ISO 27001 certificate are available through your own account or on request, while only the cloud security questionnaire can be downloaded freely; no statement on the AI regulation appears thereOpen sourceAs of 2026-08-25Principles on the use of service data: customer data trains no model without permission, a deletion also takes effect inside the models, and the release for product improvement is voluntary and sits in the settings under legal and compliance; the page carries no dateOpen sourceAs of 2026-08-25Privacy and security of the AI features: what gets processed are error messages, stack traces, spans, logs, interactions in the interface, profiles and source code from linked repositories; the language models run inside the vendor's production infrastructure without access by the underlying model providers, and the AI features can be switched off entirely for the organisationOpen sourceAs of 2026-08-25Storage location: a choice between the European Union with Frankfurt and the United States with Iowa, the address de.sentry.io for the EU region, no change of storage location for an existing running SaaS organisation, and the exceptions that sit outside the region regardless of the choice: user accounts and authentication, integration access tokens, organisation settings, the audit log and material shared in support interactionsOpen sourceAs of 2024-04-16General availability of the Germany storage location for all organisations including those on the free Developer planOpen sourceAs of 2026-08-25Retention periods per plan and data category: thirty days throughout on Developer, ninety days for errors, session replays and attachments on Team and Business, thirty days for spans, profiles and logs, plus thirteen months sampled on Business and Enterprise; the period is fixed when the data is ingestedOpen sourceAs of 2026-08-25Pricing page: Developer free with one user and 5,000 errors, Team 26 US dollars and Business 80 US dollars a month billed annually with 50,000 errors in the quota each, Enterprise by quote, plus the usage tiers per error from 0.0003625 down to 0.00015 US dollars and the assignment of SAML2 and SCIM to the Business planOpen sourceAs of 2026-08-25Seer pricing since January 2026: 40 US dollars per active contributor a month on Team and Business, 1.00 US dollar per fix run on a usage basis, and for existing subscribers before that 20 US dollars per account plus 25 US dollars of creditOpen sourceAs of 2026-08-25SAML2 sign-in and SCIM provisioning require the Business or Enterprise plan, while Google and GitHub are available from Team upwardsOpen sourceAs of 2026-08-25Relay as an upstream service that strips personal fields centrally before transmission, in managed mode from the Business plan upwardsOpen sourceAs of 2026-08-25Self-hosting under the Functional Source License converting to Apache 2.0 after two years, without guarantees and without committed support, at least four cores and 16 GB of memory with 32 GB recommended, without Seer and without a choice of storage locationOpen sourceAs of 2022-05-04The Series E round of 90 million US dollars co-led by BOND and Accel with New Enterprise Associates and K5 Global, and the valuation and total by the company's own accountOpen sourceAs of 2022-11-30Acquisition of Codecov with its own press releaseOpen sourceAs of 2025-05-06Acquisition of Emerge Tools together with the company's figures of four million developers and 130,000 organisations at that pointOpen sourceAs of 2025-09-23Announcement of the agent's review of change requests together with the company's figure of 140,000 organisations at that pointOpen sourceAs of 2026-08-25The company's figures of 200,000 organisations across 146 countries, more than 200 employees in four locations, over 190 billion events a day and 217 million US dollars from six roundsOpen source

Who it fits

Solo

suitable

The free plan carries the purpose. On 25 August 2026 the vendor puts it at one user, unlimited projects, 5,000 errors, 5 GB of logs, five million spans and fifty session replays a month. The limit that bites first is the thirty-day retention. An error that shows up once a quarter has no history left the second time round.

Mid-market

suitable

This is where the use case sits, and the bill stays small as long as the AI layer stays off. Team costs 26 US dollars a month billed annually, Business 80, both with unlimited users. Add Seer and you pay 40 US dollars per active contributor a month. With twelve developers that add-on comes to 480 US dollars and exceeds the base plan sixfold. The second point is sign-in: anyone wanting to authenticate through their own directory service needs Business.

Enterprise

suitable with caveats

The functionality holds up; procurement trips over three points. SAML2 sign-in and SCIM user provisioning start at Business, and so does Relay in managed mode, meaning the service placed in your own network that strips personal fields before transmission. Second, one decision falls before all others: the region is chosen when the organisation is created and cannot be changed afterwards for a running SaaS organisation, with the vendor pointing to a new organisation instead. Third, the public documentation gives neither a retention period nor a plan requirement for the audit log, although the log exists and although procurement asks about exactly that.

Buy, switch or build

Off-the-shelf

Datadog, the vendor with the frame agreement

Datadog, New Relic and Dynatrace answer the same question as part of a larger platform that brings infrastructure, logs and tracing with it. Corporates stay with them for a reason that has little to do with the interface: the frame agreement is in place, the contact is named, the response time is committed, and procurement does not have to vet a second vendor for a single signal type. On top comes the viability check, which for a listed company rests on published figures rather than on a press release from 2022. This is paid for with a price structure of seats, hosts and ingested volume that justifies a cost centre of its own, and with an entry point you cannot learn without a conversation. For a team that only wants to know which exception occurs how often, that is the more expensive route to the same answer.

AI-native

The coding assistant that reads the stack trace itself

There is no AI-native counterpart to the collection layer, though there is one to the analysis. Claude Code and Cursor from this catalogue take a stack trace and a repository and return a change, and the vendor itself ships an MCP server through which an assistant pulls the issue directly. The price difference is quantified: Seer costs 40 US dollars per contributor a month, while the assistant's subscription already runs in many teams and handles the work alongside. What gets given up is the layer underneath, meaning collection, grouping and alerting. An assistant needs somebody to put the issue in front of it, and that somebody is missing at three in the morning. The combination therefore rarely makes sense as a replacement and often as a division of labour: the finished product collects and groups, the assistant writes the fix.

Build it yourself

OpenTelemetry at the edge, Postgres behind it, self-hosting as a third option

Two routes are open, and both are cheaper in price than in maintenance. The first collects for itself: the application delivers through OpenTelemetry to a worker on Cloudflare Pages from this catalogue, Supabase holds the events in Postgres, n8n distributes the alert, and the interface is built with Claude Code in a few days. Reckoned at a 1,200 euro day rate and twelve person-days that comes to roughly 14,400 euros once, against 312 US dollars a year for the Team plan. The second route takes the tool itself: Sentry is available under the Functional Source License, which converts to Apache 2.0 after two years, and runs in your own data centre from four cores and 16 GB of memory, with 32 GB recommended. The vendor gives no guarantees, no support and no scaling guidance for it; Seer and the storage location choice are missing entirely when self-hosted, though the latter is solved in your own house in any case. Building it yourself breaks at three points. Grouping is the first: turning two hundred thousand events into forty issues while keeping the identifier stable when a line number shifts is the actual product. The second is resolving minified stack traces, which requires source maps from the web build and symbol files from the mobile applications to be collected and held for months. The third is readiness: an alert at three in the morning helps nobody if the collector is itself the service that just went down.

Our advice

  • Solo: Take it: the free plan carries the purpose in full.
  • Mid-market: Buy it, but switch the AI layer on only after a per-head calculation.
  • Enterprise: Settle region and plan before the first event, then talk about volumes.

Who is behind it

Staying power: Established

Sentry started as an open-source project and has been run as a product for more than ten years by the company's own account. What counts for the classification are the hard points: a dated round from 2022, two documented acquisitions, an EU sister company with its own address in Vienna, and legal documents that are still maintained. Every figure on organisations, events and headcount comes from the company itself and stands here as such.

  • Legal entity and EU sister company: Functional Software, Inc. d/b/a Sentry, United States, as contracting party; listed as affiliates on the sub-processor list: Functional Software GmbH (limited company), Jakov-Lind-Strasse 5/4. OG, 1020 Vienna, plus Sentry Software Canada Inc. in Toronto and Sentry Software Netherlands B.V. in SchipholAs of 2026-06-01Sub-processor list 2.3.0: eight recipients with address, processing country and purpose, among them Anthropic, PBC and OpenAI, L.L.C. with the United States alone for AI and model services, plus the three affiliates in Vienna, Toronto and SchipholOpen source · As of 2026-06-01
  • Last reported equity round: 90 million US dollars Series E announced on 4 May 2022, co-led by BOND and Accel with New Enterprise Associates and K5 Global; the valuation of more than 3 billion US dollars and the total of 217 million US dollars are the company's own figuresAs of 2022-05-04The Series E round of 90 million US dollars co-led by BOND and Accel with New Enterprise Associates and K5 Global, and the valuation and total by the company's own accountOpen source · As of 2022-05-04
  • Acquisitions with their own press release: Codecov on 30 November 2022, Emerge Tools on 6 May 2025; the data processing addendum has expressly covered both offerings since thenAs of 2022-11-30Acquisition of Codecov with its own press releaseOpen source · As of 2022-11-30
  • Maintenance state of the legal documents: Sub-processor list version 2.3.0 of 1 June 2026, healthcare amendment of 15 January 2026, privacy policy of 29 October 2025, data processing addendum version 5.1.0 of 29 May 2024, terms of service of 12 February 2024As of 2026-08-25Overview of the legal documents with their version dates: healthcare amendment 15 January 2026, privacy policy 29 October 2025, data processing addendum 29 May 2024, terms of service 12 February 2024Open source · As of 2026-08-25
  • Size figures over time: By the company's own account 130,000 organisations on 6 May 2025, 140,000 on 23 September 2025 and 200,000 organisations across 146 countries on 25 August 2026, plus more than 200 employees in four locations and over 190 billion events processed a dayAs of 2026-08-25The company's figures of 200,000 organisations across 146 countries, more than 200 employees in four locations, over 190 billion events a day and 217 million US dollars from six roundsOpen source · As of 2026-08-25
  • Ongoing development: The public changelog lists six entries for August 2026, the most recent dated 13 August 2026; the series runs back without a gap to March 2023As of 2026-08-25sentry.io/changelogOpen source · As of 2026-08-25

Cost of leaving: Moderate

The connection is interchangeable, the analysis is not. Feed the data in through OpenTelemetry and you swap the destination while the measurement points stay in the code. Use the vendor's own kits and you swap a dependency in every service. Either way it is days of work. What the move leaves behind are the rules grown over years: the grouping of alike exceptions into one issue, the ownership rules per directory, the alert thresholds, the filters against noise from browser extensions, and the rules that strip personal fields before sending. Those rules carry data protection decisions and get rewritten by hand in the new tool. The history itself weighs less here than elsewhere, because retention runs to thirty or ninety days in any case. One peculiarity comes on top, and it hits those who stay as well: changing region requires a new organisation, and with it the collection of issues starts from zero.

Regulation and data

How to read the traffic lightHow to read the traffic lightThe traffic light rates how well a point is evidenced, not how good the tool is. It draws only on the value, note and source held in the profile. Where a statement is missing, it rates the absence, not a guess. A well-reasoned "unclear" on a point that matters little for this tool is yellow. A missing source on a point that decides whether you can use it at all is red.documented, no condition attacheddocumented, tied to a conditiondocumented, but unfavourableopen on a point that decides usability
Data processing agreementScale for this point: Data processing agreementdocumented, no condition attached: Auftragsverarbeitungsvertrag öffentlich abrufbar und ohne weitere Bedingung Bestandteil des Vertrags; oder er entfällt nachvollziehbar begründet, weil kein Anbieter Kundendaten verarbeitet.documented, tied to a condition: Vertrag existiert, ist aber an einen Tarif gebunden, nur nach Anfrage einsehbar oder allein in den Nutzungsbedingungen geregelt statt als eigenes Dokument.documented, but unfavourable: Kein Auftragsverarbeitungsvertrag im üblichen Sinn: entweder weil der Anbieter für das Kerngeschäft eigenständig Verantwortlicher ist und stattdessen eine andere Konstruktion gilt, oder weil öffentlich offen bleibt, ob überhaupt einer angeboten wird.open on a point that decides usability: Weder ein Vertrag noch ein dokumentierter Weg zu einem Vertrag; der Einkauf hätte nichts, worauf er sich stützen kann.documented, tied to a conditionfull text publicly readable, effective only through a separate electronic acceptanceAs of 2024-05-29Data processing addendum version 5.1.0 of 29 May 2024: Functional Software, Inc. as processor, effectiveness through electronic acceptance, express prohibition on transferring special categories of personal data, application to Sentry and Codecov, destruction after the term expires without a stated period, audit rights once in twelve months at the customer's cost, and Schedule 3 with the Data Privacy Framework, standard contractual clauses 2021/914 and UK addendum B1.0Open sourceThe agreement in version 5.1.0 of 29 May 2024 sits on the page without a login, together with every prior version back to 2018. It is entered into between Functional Software, Inc. and the party that electronically accepts it, and the vendor points to a separate instruction for doing so. For the file that means reading is not enough; the step inside the account belongs to it. Two points deserve a legal department's marker. First, the agreement expressly prohibits transferring special categories of personal data and records that the vendor's obligations do not apply to such data, while a stack trace carries along whatever happened to be in memory. Second, the same agreement covers Sentry and Codecov together.As of 2024-05-29
Storage locationScale for this point: Storage locationdocumented, no condition attached: EU-Speicherort ohne Zusatzkosten und ohne Tarifbindung, oder der Ort ist vollständig selbst bestimmbar, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: EU-Speicherort möglich, aber an einen Tarif, einen gesondert zu aktivierenden Zusatz oder einen Umzug in eine getrennte Umgebung gebunden; oder die EU-Region ist nicht die Voreinstellung.documented, but unfavourable: Kein EU-Speicherort, der Ort ist aber eindeutig benannt, sodass die Folgen bewertbar sind.open on a point that decides usability: Der Speicherort ist öffentlich nicht benannt oder vom Kunden nicht steuerbar, sodass sich die Verarbeitung nicht verorten lässt.documented, tied to a conditionEU in Frankfurt or US in Iowa, chosen once when the organisation is createdAs of 2026-08-25Storage location: a choice between the European Union with Frankfurt and the United States with Iowa, the address de.sentry.io for the EU region, no change of storage location for an existing running SaaS organisation, and the exceptions that sit outside the region regardless of the choice: user accounts and authentication, integration access tokens, organisation settings, the audit log and material shared in support interactionsOpen sourceThe EU region has been generally available since 16 April 2024, is offered on every plan including the free one and costs nothing extra; the address for ingestion is then de.sentry.io. It is not the default, and the choice falls when the organisation is created. After that it is closed: for an existing running SaaS organisation the storage location can no longer be changed, and the vendor names creating a new organisation as the only route. Four things leave the chosen region regardless of that decision, and three of them come up in every audit: user accounts along with authentication, the access tokens of the integrations, the organisation settings and the audit log. Attach documents to a support ticket and they are stored in the United States, per the vendor.As of 2026-08-25
SubprocessorsScale for this point: Subprocessorsdocumented, no condition attached: Vollständige öffentliche Liste der Unterauftragnehmer mit Zweck und Land; oder es gibt keine, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: Liste existiert und ist benannt, aber nur nach Anfrage oder nach Zugang zu einem Vertrauensportal einsehbar, oder sie nennt Zweck und Land nicht vollständig.documented, but unfavourable: Keine geführte Liste; namentlich stehen nur einzelne Dienste in der Datenschutzerklärung, überwiegend solche der eigenen Website.open on a point that decides usability: Weder eine Liste noch eine Nennung der Verarbeiter des Produkts, und kein dokumentierter Weg, sie zu erfahren.documented, no condition attachedcomplete public list with address, country and purpose, plus a change feedAs of 2026-06-01Sub-processor list 2.3.0: eight recipients with address, processing country and purpose, among them Anthropic, PBC and OpenAI, L.L.C. with the United States alone for AI and model services, plus the three affiliates in Vienna, Toronto and SchipholOpen sourceThe list in version 2.3.0 of 1 June 2026 names eight recipients with full address, processing country and purpose, plus three affiliates. For infrastructure, Amazon Web Services, Google Cloud Platform and Cloudflare each appear with the European Union and the United States. Separately stand two entries that trigger the real question in procurement: Anthropic, PBC and OpenAI, L.L.C., both with the United States alone and both with the purpose of AI and model services. Delivery and support run through Sinch with the European Union and through Twilio and Intercom with the United States. Changes can be followed through a feed; the page names no objection procedure with a deadline.As of 2026-06-01
Third-country transferScale for this point: Third-country transferdocumented, no condition attached: Keine Übermittlung in ein Drittland, oder die Übermittlung findet statt und die Grundlage ist benannt und im Vertrag verankert, etwa Standardvertragsklauseln, Angemessenheitsbeschluss oder EU-US-Datenschutzrahmen.documented, tied to a condition: Übermittlung findet statt, eine Grundlage ist genannt, aber ohne Zuordnung, welcher Empfänger auf welcher Grundlage arbeitet.documented, but unfavourable: Übermittlung findet statt und die eigenen Unterlagen widersprechen sich, oder die genannte Grundlage bezieht sich erkennbar nur auf einen Randbereich wie die Marketing-Website.open on a point that decides usability: Übermittlung findet erkennbar statt und eine Grundlage wird nirgends genannt.documented, no condition attachedEU-US Data Privacy Framework as the basis, standard contractual clauses as the fallback, both in the contractAs of 2024-05-29Data processing addendum version 5.1.0 of 29 May 2024: Functional Software, Inc. as processor, effectiveness through electronic acceptance, express prohibition on transferring special categories of personal data, application to Sentry and Codecov, destruction after the term expires without a stated period, audit rights once in twelve months at the customer's cost, and Schedule 3 with the Data Privacy Framework, standard contractual clauses 2021/914 and UK addendum B1.0Open sourceSchedule 3 of the data processing addendum handles transfers in two steps. First comes self-certification under the EU-US Data Privacy Framework together with the UK extension and the Swiss version, coupled with a duty to give notice should the certification end. Should the framework fall away or not apply to a transfer, the standard contractual clauses under decision 2021/914 of 4 June 2021 take its place, supplemented for the United Kingdom by the addendum in version B1.0. The same schedule names a commitment that goes beyond the standard text: the vendor gives notice when it can no longer comply with the clauses, without having to identify the specific provision. Which of the eight recipients operates on which of the two bases is not assigned individually in the public documents.As of 2024-05-29
Training on customer dataScale for this point: Training on customer datadocumented, no condition attached: Vertraglich oder in der Datenschutzerklärung ausdrücklich ausgeschlossen, mit Erstreckung auf die eingesetzten Modellanbieter; oder es gibt keine Datenübertragung an einen Anbieter.documented, tied to a condition: Ausschluss ab einem bestimmten Tarif, oder die Zusage steht nur auf einer Dokumentationsseite statt im Vertrag, oder die Frage stellt sich für das Werkzeug sachlich kaum und der Anbieter schweigt dazu.documented, but unfavourable: Nutzung ist die Voreinstellung und nur ein Widerspruch beendet sie; oder der Anbieter trainiert eigene Modelle auf bereinigten Kundendaten.open on a point that decides usability: Keine Aussage, obwohl das Werkzeug KI-Funktionen auf Kundeninhalten betreibt.documented, tied to a conditiontraining excluded by default, with the commitment sitting in the documentation rather than in the contractAs of 2026-08-25Principles on the use of service data: customer data trains no model without permission, a deletion also takes effect inside the models, and the release for product improvement is voluntary and sits in the settings under legal and compliance; the page carries no dateOpen sourceThe finding comes from laying three documents side by side, and it is the most valuable one in this profile. The documentation undertakes that customer data trains no model without permission, that a deletion also takes effect inside the models, and that the language models run within the vendor's own production infrastructure without the underlying model providers having access; a release for product improvement is possible and expressly voluntary. Those pages carry no date. The data processing addendum of 29 May 2024 and the privacy policy of 29 October 2025, by contrast, contain not a single occurrence of training, model or artificial intelligence, checked across the full text of both documents on 25 August 2026. At the same time the sub-processor list of 1 June 2026 carries Anthropic and OpenAI with the United States as their processing country. So the commitment exists; it simply sits where the vendor can change it without amending the contract. Anyone needing it for the file negotiates it into the main agreement.As of 2026-08-25
Retention and deletionScale for this point: Retention and deletiondocumented, no condition attached: Löschfristen nach Vertragsende beziffert und die Löschung oder Rückgabe zugesagt; oder die Fristen bestimmt der Betreiber selbst, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: Löschung ist zugesagt, die Fristen sind aber nur teilweise beziffert, oder Sicherungskopien sind ausdrücklich ausgenommen.documented, but unfavourable: Nur der Grundsatz der Erforderlichkeit ohne jede Frist nach Vertragsende, oder Fristen sind allein für Randbereiche wie Website-Protokolle genannt.open on a point that decides usability: Keine Aussage zu Aufbewahrung und Löschung.documented, tied to a conditiondeletion after the end of the contract promised without a period, live retention quantified per planAs of 2026-08-25Retention periods per plan and data category: thirty days throughout on Developer, ninety days for errors, session replays and attachments on Team and Business, thirty days for spans, profiles and logs, plus thirteen months sampled on Business and Enterprise; the period is fixed when the data is ingestedOpen sourceSection 5 of the data processing addendum undertakes to destroy personal data once the term expires and reserves legal duties; anyone still needing something has to export it beforehand. No period is stated there. Live retention is quantified: thirty days for every data category on the free plan, ninety days for errors, session replays and attachments on Team and Business, thirty days for spans, profiles and logs, plus thirteen months sampled on Business. The period is fixed at the moment data is ingested, so a change of plan works only going forward. After an account is deleted, event data becomes inaccessible within 24 hours, and backups drop out ninety days after they were created.As of 2026-08-25
CertificationsScale for this point: Certificationsdocumented, no condition attached: Mehrere anerkannte Nachweise, benannt mit Norm, Fassung und Geltungsbereich, und bezogen auf den Anbieter selbst.documented, tied to a condition: Ein anerkannter Nachweis für den Anbieter belegt, der Bericht aber nur auf Anfrage, oder der Nachweis hängt an einem Tarif, oder der Geltungsbereich bleibt teilweise offen.documented, but unfavourable: Nur pauschale Nennung ohne Norm-Fassung und Geltungsbereich, oder bloße Selbstauskunft, oder die Nachweise gehören dem Infrastrukturanbieter statt dem Anbieter, oder der Prüfzeitraum ist erkennbar veraltet, oder die eigenen Angaben widersprechen sich.open on a point that decides usability: Kein Nachweis genannt und keine Sicherheits- oder Vertrauensseite vorhanden.documented, tied to a conditionSOC 2 Type 1 and Type 2, ISO 27001 and a healthcare attestation, reports on request onlyAs of 2026-08-25Security page: operation on Google Cloud Platform in a multi-tenant setup, hourly encrypted backups in several regions, backups dropping ninety days after creation, event data becoming inaccessible within 24 hours of an account deletion, an annual penetration test against an isolated clone, the attestations SOC 2 Type 1, SOC 2 Type 2, ISO 27001 and the US health law attestation, and the scope of the audit log with event type, person, timestamp and IP addressOpen sourceFour attestations are named on the security page and relate to the vendor itself: SOC 2 Type 1, SOC 2 Type 2, ISO 27001 and an attestation under the security rule of US health law. On top, an independent agency runs an annual penetration test against an isolated clone of the environment, with the summary going to customers. The only freely public item is the completed cloud security questionnaire. Report and certificate come through your own account or on request, and the vendor names neither the audit period nor the version of the standard nor the scope anywhere publicly. The contract additionally grants an audit by an internationally recognised auditor, at the customer's cost and at most once in twelve months.As of 2026-08-25
EU AI Act, Article 50Scale for this point: EU AI Act, Article 50documented, no condition attached: Der Anbieter macht eine belegte Aussage, die die eigene Pflicht trägt, etwa Modelldokumentation und Zertifizierung nach ISO/IEC 42001; oder das Werkzeug enthält nachvollziehbar begründet kein KI-System im Sinne der Verordnung.documented, tied to a condition: Der Anbieter äußert sich zur Verordnung oder ordnet die eigene Funktion ein, eine benannte Zusage zu den Transparenzpflichten aus Artikel 50 fehlt aber; oder das Werkzeug enthält kein KI-System, das gegenüber Menschen auftritt, und der Anbieter schweigt.documented, but unfavourable: Das Produkt enthält KI-Funktionen, der Anbieter schweigt dazu oder trägt ein Selbstetikett ohne Nachweis; die Kennzeichnung ist vom Betreiber aber selbst setzbar.open on a point that decides usability: KI spricht im Produkt unmittelbar mit Endkunden und der Anbieter sagt zu Artikel 50 nichts; die Kennzeichnung lässt sich ohne Zusage des Anbieters nicht sicher setzen.documented, but unfavourableno statement on the regulation, although the product generates text and code changesAs of 2026-08-25Trust page: references to the AI privacy principles, the Seer privacy overview and the self-certification for cross-border transfers, plus the note that the SOC 2 report and ISO 27001 certificate are available through your own account or on request, while only the cloud security questionnaire can be downloaded freely; no statement on the AI regulation appears thereOpen sourceWith Seer the vendor runs an agent that names root causes, proposes fixes and reviews change requests, since 23 September 2025 also as a check before release. On 25 August 2026 the security page, the trust page and the legal page say nothing about Regulation (EU) 2024/1689 or its amending Regulation (EU) 2026/1744, no certification under ISO/IEC 42001 is named anywhere, and the three pages on handling AI deal with data protection alone. The transparency duties under Article 50 have applied since 2 August 2026. Here they fall first on the operator, because the agent faces the company's own development team; the labelling can therefore be set without any action by the vendor, and the AI features can be switched off entirely in the organisation settings. Anyone carrying text generated by the agent into customer communication leaves that frame and bears the classification alone.As of 2026-08-25
Audit loggingScale for this point: Audit loggingdocumented, no condition attached: Nachvollziehbares Protokoll über Zugriffe und Änderungen in allen Tarifen enthalten, mit benannter Frist und Ausleitung in eigene Systeme; oder die Nachvollziehbarkeit liegt vollständig in eigener Hand, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: Protokoll vorhanden, aber an einen höheren Tarif oder einen kostenpflichtigen Zusatz gebunden, oder die Ausleitung fehlt in den unteren Stufen; Reichweite und Frist sind benannt.documented, but unfavourable: Protokolle sind nur anbieterseitig beschrieben, oder Reichweite und Frist bleiben offen, sodass sich Nachweispflichten nicht planen lassen.open on a point that decides usability: Öffentlich nicht belegt, ob der Kunde überhaupt ein auswertbares Protokoll erhält.documented, but unfavourableaudit log present and described, with retention period and plan requirement left open publiclyAs of 2026-08-25Security page: operation on Google Cloud Platform in a multi-tenant setup, hourly encrypted backups in several regions, backups dropping ninety days after creation, event data becoming inaccessible within 24 hours of an account deletion, an annual penetration test against an isolated clone, the attestations SOC 2 Type 1, SOC 2 Type 2, ISO 27001 and the US health law attestation, and the scope of the audit log with event type, person, timestamp and IP addressOpen sourceThe security page describes the log by scope: every action in the interface with event type, acting person, timestamp and IP address, with the invitation of a member and the creation of a project given as examples. That is where the public information ends. The documentation carries no page of its own for the audit log; the answer on retention sits in a help article behind a login, and the pricing page names the log in no plan row. For procurement that means scope is evidenced while retention and plan requirement come only after asking the vendor. One point from another source is certain and belongs in the same file: the audit log sits outside the chosen region, per the vendor.As of 2026-08-25

What it really costs

Entry price

The Developer plan is free and carries one user with 5,000 errors a month and thirty days of retention. Team costs 26 US dollars a month billed annually, Business 80, both with unlimited users and 50,000 errors in the base quota; Enterprise runs through a quote. Above the quota a usage price per error applies which falls with volume: 0.0003625 US dollars between 50,000 and 100,000, 0.0001875 up to ten million and 0.00015 above twenty million.As of 2026-08-25Pricing page: Developer free with one user and 5,000 errors, Team 26 US dollars and Business 80 US dollars a month billed annually with 50,000 errors in the quota each, Enterprise by quote, plus the usage tiers per error from 0.0003625 down to 0.00015 US dollars and the assignment of SAML2 and SCIM to the Business planOpen source

As of 2026-08-25

What gets expensive

The AI layer, and by a wide margin. Since January 2026 Seer has been billed at 40 US dollars per active contributor a month, the same on Team and Business, plus 1.00 US dollar for each fix run on a usage basis. A team of twenty developers therefore pays 800 US dollars a month for the agent and 80 for the plan underneath it. Anyone who started earlier paid 20 US dollars per account plus 25 US dollars of credit, and that difference is worth checking against your own invoice. The second threshold sits in administration: SAML2 sign-in, SCIM provisioning and Relay in managed mode all start at Business. The third point costs no money and still costs the most, because the region is chosen when the organisation is created and can afterwards be corrected only through a new organisation.

What it displaces

  • The error report emailed to a shared mailbox where the two hundredth repeat of the same exception disappears
  • A customer's message as the first news of an outage
  • The hunt through the server log for a timestamp somebody typed out from a screenshot

Interfaces

  • Software kits for web, mobile, server and games consoles, plus OpenTelemetry as an input
  • REST API and an MCP server through which a coding assistant pulls an issue together with its stack trace
  • Integration with GitHub and GitLab for ownership rules, suspect commits and the review of change requests
  • Sign-in via Google and GitHub from Team upwards, via SAML2 and user provisioning via SCIM from Business upwards
  • Relay as a service placed in your own network that strips personal fields before transmission, in managed mode from Business upwards
  • Self-hosting under the Functional Source License, without vendor guarantees, without Seer and without a choice of storage location

Matching methods

  • DORA Delivery DiagnosticThe time to restore after a failure and the change failure rate can only be asserted for as long as nobody records them, and this tool is the usual place where both figures come into being.
  • DORA AI Capabilities Model (Seven AI Capabilities)The agent inside the product amplifies existing delivery discipline rather than replacing a missing one, which shows immediately in the per-head price here: without ownership rules and alert thresholds, the team pays for an analysis nobody picks up.
  • Regulatory Density TestThe density of evidence duties decides whether directory sign-in, the audit log and upstream field scrubbing are add-ons or conditions of purchase, and that is exactly what the jump to the next plan hangs on here.

Alternatives

Sources

  1. 1.Data processing addendum version 5.1.0 of 29 May 2024: Functional Software, Inc. as processor, effectiveness through electronic acceptance, express prohibition on transferring special categories of personal data, application to Sentry and Codecov, destruction after the term expires without a stated period, audit rights once in twelve months at the customer's cost, and Schedule 3 with the Data Privacy Framework, standard contractual clauses 2021/914 and UK addendum B1.0 (opens in a new tab)sentry.io/legal/dpa · As of 2024-05-29
  2. 2.Sub-processor list 2.3.0: eight recipients with address, processing country and purpose, among them Anthropic, PBC and OpenAI, L.L.C. with the United States alone for AI and model services, plus the three affiliates in Vienna, Toronto and Schiphol (opens in a new tab)sentry.io/legal/subprocessors · As of 2026-06-01
  3. 3.Privacy policy of 29 October 2025: self-certification of Functional Software, Inc. under the EU-US Data Privacy Framework including the UK and Swiss versions, plus the express statement that this policy does not apply to data submitted to the Service (opens in a new tab)sentry.io/privacy · As of 2025-10-29
  4. 4.Overview of the legal documents with their version dates: healthcare amendment 15 January 2026, privacy policy 29 October 2025, data processing addendum 29 May 2024, terms of service 12 February 2024 (opens in a new tab)sentry.io/legal · As of 2026-08-25
  5. 5.Security page: operation on Google Cloud Platform in a multi-tenant setup, hourly encrypted backups in several regions, backups dropping ninety days after creation, event data becoming inaccessible within 24 hours of an account deletion, an annual penetration test against an isolated clone, the attestations SOC 2 Type 1, SOC 2 Type 2, ISO 27001 and the US health law attestation, and the scope of the audit log with event type, person, timestamp and IP address (opens in a new tab)sentry.io/security · As of 2026-08-25
  6. 6.Trust page: references to the AI privacy principles, the Seer privacy overview and the self-certification for cross-border transfers, plus the note that the SOC 2 report and ISO 27001 certificate are available through your own account or on request, while only the cloud security questionnaire can be downloaded freely; no statement on the AI regulation appears there (opens in a new tab)sentry.io/trust · As of 2026-08-25
  7. 7.Principles on the use of service data: customer data trains no model without permission, a deletion also takes effect inside the models, and the release for product improvement is voluntary and sits in the settings under legal and compliance; the page carries no date (opens in a new tab)docs.sentry.io/security-legal-pii/security/ai-ml-policy · As of 2026-08-25
  8. 8.Privacy and security of the AI features: what gets processed are error messages, stack traces, spans, logs, interactions in the interface, profiles and source code from linked repositories; the language models run inside the vendor's production infrastructure without access by the underlying model providers, and the AI features can be switched off entirely for the organisation (opens in a new tab)docs.sentry.io/product/ai-in-sentry/ai-privacy-and-security · As of 2026-08-25
  9. 9.Storage location: a choice between the European Union with Frankfurt and the United States with Iowa, the address de.sentry.io for the EU region, no change of storage location for an existing running SaaS organisation, and the exceptions that sit outside the region regardless of the choice: user accounts and authentication, integration access tokens, organisation settings, the audit log and material shared in support interactions (opens in a new tab)docs.sentry.io/organization/data-storage-location · As of 2026-08-25
  10. 10.General availability of the Germany storage location for all organisations including those on the free Developer plan (opens in a new tab)sentry.io/… · As of 2024-04-16
  11. 11.Retention periods per plan and data category: thirty days throughout on Developer, ninety days for errors, session replays and attachments on Team and Business, thirty days for spans, profiles and logs, plus thirteen months sampled on Business and Enterprise; the period is fixed when the data is ingested (opens in a new tab)docs.sentry.io/…/data-retention-periods · As of 2026-08-25
  12. 12.Pricing page: Developer free with one user and 5,000 errors, Team 26 US dollars and Business 80 US dollars a month billed annually with 50,000 errors in the quota each, Enterprise by quote, plus the usage tiers per error from 0.0003625 down to 0.00015 US dollars and the assignment of SAML2 and SCIM to the Business plan (opens in a new tab)sentry.io/pricing · As of 2026-08-25
  13. 13.Seer pricing since January 2026: 40 US dollars per active contributor a month on Team and Business, 1.00 US dollar per fix run on a usage basis, and for existing subscribers before that 20 US dollars per account plus 25 US dollars of credit (opens in a new tab)docs.sentry.io/pricing · As of 2026-08-25
  14. 14.SAML2 sign-in and SCIM provisioning require the Business or Enterprise plan, while Google and GitHub are available from Team upwards (opens in a new tab)docs.sentry.io/product/accounts/sso · As of 2026-08-25
  15. 15.Relay as an upstream service that strips personal fields centrally before transmission, in managed mode from the Business plan upwards (opens in a new tab)docs.sentry.io/product/relay/modes · As of 2026-08-25
  16. 16.Self-hosting under the Functional Source License converting to Apache 2.0 after two years, without guarantees and without committed support, at least four cores and 16 GB of memory with 32 GB recommended, without Seer and without a choice of storage location (opens in a new tab)develop.sentry.dev/self-hosted · As of 2026-08-25
  17. 17.The Series E round of 90 million US dollars co-led by BOND and Accel with New Enterprise Associates and K5 Global, and the valuation and total by the company's own account (opens in a new tab)sentry.io/… · As of 2022-05-04
  18. 18.Acquisition of Codecov with its own press release (opens in a new tab)sentry.io/about/press-releases/sentry-acquires-codecov · As of 2022-11-30
  19. 19.Acquisition of Emerge Tools together with the company's figures of four million developers and 130,000 organisations at that point (opens in a new tab)sentry.io/… · As of 2025-05-06
  20. 20.Announcement of the agent's review of change requests together with the company's figure of 140,000 organisations at that point (opens in a new tab)sentry.io/about/press-releases/sentry-announces-ai-code-review · As of 2025-09-23
  21. 21.The company's figures of 200,000 organisations across 146 countries, more than 200 employees in four locations, over 190 billion events a day and 217 million US dollars from six rounds (opens in a new tab)sentry.io/about · As of 2026-08-25
  22. 22.sentry.io/changelog (opens in a new tab)As of 2026-08-25

Last reviewed: 2026-08-25 by Dr. Oliver Gausmann, Convios GmbH

Details out of date? Let us know.