How your trust story reads from the public web
vs. Amplitude, Mixpanel, Heap
One in a series benchmarking how funded B2B SaaS companies present trust to enterprise buyers. Everything below is publicly observable — the same view an enterprise buyer's procurement and InfoSec reviewers get. This is not a security assessment; it says nothing about PostHog's actual security.
This edition documents an arrival gap rather than a depth gap; PostHog was not asked and is not being pitched.
The short version
PostHog publishes the deepest trust surface in this set — the SOC 2 Type II report is an ungated public PDF, the DPA's full text is a page, and subprocessors are named with locations. What it doesn't publish is a path: the posthog.com homepage carries no security, trust, privacy, or terms link, while all three competitors link their trust surfaces from the front page.
Before a questionnaire is ever sent, a reviewer does a public first pass. Replaying it for PostHog, on 2026-09-02:
At this point the reviewer has formed a first impression of PostHog as a vendor — before anyone at PostHog knows the review has started.
All cells observed 2026-09-02, public web only. Published / Partial / Not found = what a logged-out visitor can reach; it says nothing about what exists internally.
| Observable artifact | PostHog | Amplitude | Mixpanel | Heap |
|---|---|---|---|---|
| Public trust/security page | Publishedtrust.posthog.com plus a public handbook security chapter (posthog.com/handbook/company/security); neither is linked from the posthog.com homepage | Publishedamplitude.com/security-and-privacy, homepage-linked; trust portal at trust.amplitude.com | Publishedmixpanel.com/legal/security-overview, homepage-linked; trust center at trust.mixpanel.com | Publishedheap.io/platform/security and heap.io/trust-center, both homepage-linked; the portal is the parent Contentsquare's |
| SOC 2 visibility & report path | PublishedType II stated (posthog.com/docs/privacy/soc2); the report is an ungated public PDF, controls through 2026-05-31 (posthog.com/security/soc2-report-2026.pdf) | PublishedSOC 2 Type II report (2025–2026), SOC 1 Type II, and ISO 27001/27017/27018 listed on trust.amplitude.com; reports behind a self-serve access request | PublishedSOC 2 Type II, ISO 27001, and ISO 27701 stated (mixpanel.com/legal/security-overview); reports via trust.mixpanel.com | PublishedISO 27001, 27701, 27017 & 27018 stated (heap.io/platform/security); SOC 2 Type II shown on the parent-company portal behind a self-serve gate |
| Security answers available publicly | topics (trust.posthog.com, posthog.com/docs, posthog.com/subprocessors, posthog.com/dpa) | topics (trust.amplitude.com, amplitude.com/security-and-privacy, amplitude.com/pricing) | topics (mixpanel.com/legal/security-overview, mixpanel.com/legal/mixpanel-security-questionnaire, mixpanel.com/pricing) | topics (heap.io/platform/security, trust.contentsquare.com, heap.io/pricing) |
| Subprocessor list & DPA | Publishedfive subprocessors named with processing locations (posthog.com/subprocessors); full DPA text readable at posthog.com/dpa, countersigned copy generated in-app | Publishednine subprocessors named with locations and purposes; DPA an open link (trust.amplitude.com) | Publishedmixpanel.com/legal/sub-processors and mixpanel.com/legal/dpa | Publishedparent-company subprocessor list (contentsquare.com/privacy-center/subprocessors) and a public DPA on the trust portal |
| Enterprise signals on pricing page | Partiala Platform packages line names SSO, audit logs, custom roles, and project permissions; no SLA, HIPAA/BAA, or attestation named (posthog.com/pricing) | Published"SSO & Project Permissions" on the Growth tier; SCIM, data access controls, and an EU data center on higher tiers (amplitude.com/pricing) | PublishedSAML/SSO, audit logs, HIPAA tools, US/EU data residency, and advanced permissions named on Enterprise (mixpanel.com/pricing) | PublishedSSO on every tier; audit logs, SCIM, custom permissions, and region-specific storage on Premier (heap.io/pricing) |
| Column summary | 3/4 published · 18/20 topics | 4/4 published · 19/20 topics | 4/4 published · 17/20 topics | 4/4 published · 15/20 topics |
An unusually complete set: all four companies publish a trust page, an attestation, a subprocessor list, and a DPA. Amplitude starts a reviewer at 19/20 publicly answerable topics, the strongest here; PostHog's 18/20 includes the only ungated attestation report; Heap alone names SSO on every pricing tier. What separates PostHog is arrival, not depth — the other three link their trust surfaces from the homepage.
Exhibit
SOC 2 Type 2 · report published as an ungated PDF
Docs · Privacy compliance · SOC 2
“PostHog is certified as SOC 2 Type 2 compliant, following an external audit.”
The audited document itself — not a badge — is a public PDF. No other company in this set publishes theirs without an access gate.
Recreated from posthog.com/docs/privacy/soc2 as observed 2026-09-02; the linked report at posthog.com/security/soc2-report-2026.pdf loads without a gate.
Nothing in this section needs a citation; it is the mechanics of the review itself. Every topic a reviewer can't answer from the public web becomes a questionnaire question: sent by email, routed to whoever holds the answer, written up, sent back, read. Each round-trip adds days, and the days accumulate while the deal sits in review. On today's table, PostHog starts with 18/20 topics answerable self-serve; Amplitude starts at 19/20 — the difference is round-trips.
Topic-by-topic (public web only):
Publicly answerable (18): encryption at rest and in transit (control items on trust.posthog.com); SSO/SAML (posthog.com/docs/settings/sso — GitHub, GitLab, Google, custom SAML); subprocessor list (posthog.com/subprocessors — five vendors with locations; AI subprocessors appear when those features are enabled); data residency (US, or EU hosted in Germany — posthog.com/privacy); DPA (posthog.com/dpa); access control; backups; incident response; vulnerability management (responsible disclosure; Wiz named for vulnerability detection); employee security training; BC/DR; vendor risk management (third-party dependence items on the trust center); data retention/deletion (posthog.com/docs/privacy/data-storage); change management; logging/monitoring (audit logging); physical/hosting detail (AWS, US or Germany); compliance report access path (the public PDF, with the rest behind the trust center's self-serve gate).
Not publicly answerable (2): pentest cadence (a pentest report sits behind the trust center's access gate; no cadence stated) and uptime SLA (no stated uptime commitment found).
Reads well: three things in particular. The report PDF is public — no other company in this set does that. The DPA is readable as a page rather than a request flow. And the security chapter lives in the company handbook, written as working documentation rather than marketing copy. The transparency is real; only the wayfinding is not.
Which topics counted toward each company's publicly answerable score in the table above.