GRANWORTH Benchmarked 2026-09-02 · Public web only
THE GRANWORTH INDEX Enterprise Trust Benchmark · 2026-09-02 edition

How your trust story reads from the public web

PostHog

vs. Amplitude, Mixpanel, Heap

One in a series benchmarking how funded B2B SaaS companies present trust to enterprise buyers. Everything below is publicly observable — the same view an enterprise buyer's procurement and InfoSec reviewers get. This is not a security assessment; it says nothing about PostHog's actual security.

This edition documents an arrival gap rather than a depth gap; PostHog was not asked and is not being pitched.

The short version

PostHog publishes the deepest trust surface in this set — the SOC 2 Type II report is an ungated public PDF, the DPA's full text is a page, and subprocessors are named with locations. What it doesn't publish is a path: the posthog.com homepage carries no security, trust, privacy, or terms link, while all three competitors link their trust surfaces from the front page.

What an enterprise security reviewer sees in the first 5 minutes

Before a questionnaire is ever sent, a reviewer does a public first pass. Replaying it for PostHog, on 2026-09-02:

  1. Search "PostHog security" / "PostHog trust center": owned results lead — posthog.com/docs/privacy and its SOC 2 page, the handbook's security chapter, and trust.posthog.com. A reviewer who searches, finds.
  2. Site footer/nav: no security, trust, privacy, or terms link anywhere on the posthog.com homepage; the footer links the company handbook and a merch store (posthog.com).
  3. Attestation path: SOC 2 Type II stated at posthog.com/docs/privacy/soc2; the current report (controls through 2026-05-31) is a public PDF (posthog.com/security/soc2-report-2026.pdf). No form, no gate. All three competitors gate theirs.
  4. Standard questionnaire topics answerable publicly: 18/20 — encryption, subprocessors, DPA, data residency, and the report path among them; pentest cadence and uptime SLA are the two not publicly answerable (topic-by-topic list below).
  5. Pricing page: a Platform packages line names SSO, audit logs, custom roles, and project permissions (posthog.com/pricing); no SLA, HIPAA/BAA, or attestation named anywhere on the page.

At this point the reviewer has formed a first impression of PostHog as a vendor — before anyone at PostHog knows the review has started.

Side by side

All cells observed 2026-09-02, public web only. Published / Partial / Not found = what a logged-out visitor can reach; it says nothing about what exists internally.

Observable trust artifacts, PostHog compared with Amplitude, Mixpanel, Heap
Observable artifact PostHog Amplitude Mixpanel Heap
Public trust/security page Publishedtrust.posthog.com plus a public handbook security chapter (posthog.com/handbook/company/security); neither is linked from the posthog.com homepage Publishedamplitude.com/security-and-privacy, homepage-linked; trust portal at trust.amplitude.com Publishedmixpanel.com/legal/security-overview, homepage-linked; trust center at trust.mixpanel.com Publishedheap.io/platform/security and heap.io/trust-center, both homepage-linked; the portal is the parent Contentsquare's
SOC 2 visibility & report path PublishedType II stated (posthog.com/docs/privacy/soc2); the report is an ungated public PDF, controls through 2026-05-31 (posthog.com/security/soc2-report-2026.pdf) PublishedSOC 2 Type II report (2025–2026), SOC 1 Type II, and ISO 27001/27017/27018 listed on trust.amplitude.com; reports behind a self-serve access request PublishedSOC 2 Type II, ISO 27001, and ISO 27701 stated (mixpanel.com/legal/security-overview); reports via trust.mixpanel.com PublishedISO 27001, 27701, 27017 & 27018 stated (heap.io/platform/security); SOC 2 Type II shown on the parent-company portal behind a self-serve gate
Security answers available publicly topics (trust.posthog.com, posthog.com/docs, posthog.com/subprocessors, posthog.com/dpa) topics (trust.amplitude.com, amplitude.com/security-and-privacy, amplitude.com/pricing) topics (mixpanel.com/legal/security-overview, mixpanel.com/legal/mixpanel-security-questionnaire, mixpanel.com/pricing) topics (heap.io/platform/security, trust.contentsquare.com, heap.io/pricing)
Subprocessor list & DPA Publishedfive subprocessors named with processing locations (posthog.com/subprocessors); full DPA text readable at posthog.com/dpa, countersigned copy generated in-app Publishednine subprocessors named with locations and purposes; DPA an open link (trust.amplitude.com) Publishedmixpanel.com/legal/sub-processors and mixpanel.com/legal/dpa Publishedparent-company subprocessor list (contentsquare.com/privacy-center/subprocessors) and a public DPA on the trust portal
Enterprise signals on pricing page Partiala Platform packages line names SSO, audit logs, custom roles, and project permissions; no SLA, HIPAA/BAA, or attestation named (posthog.com/pricing) Published"SSO & Project Permissions" on the Growth tier; SCIM, data access controls, and an EU data center on higher tiers (amplitude.com/pricing) PublishedSAML/SSO, audit logs, HIPAA tools, US/EU data residency, and advanced permissions named on Enterprise (mixpanel.com/pricing) PublishedSSO on every tier; audit logs, SCIM, custom permissions, and region-specific storage on Premier (heap.io/pricing)
Column summary 3/4 published · 18/20 topics 4/4 published · 19/20 topics 4/4 published · 17/20 topics 4/4 published · 15/20 topics

An unusually complete set: all four companies publish a trust page, an attestation, a subprocessor list, and a DPA. Amplitude starts a reviewer at 19/20 publicly answerable topics, the strongest here; PostHog's 18/20 includes the only ungated attestation report; Heap alone names SSO on every pricing tier. What separates PostHog is arrival, not depth — the other three link their trust surfaces from the homepage.

Exhibit

SOC 2 Type 2 · report published as an ungated PDF

Docs · Privacy compliance · SOC 2

“PostHog is certified as SOC 2 Type 2 compliant, following an external audit.”

The audited document itself — not a badge — is a public PDF. No other company in this set publishes theirs without an access gate.

Recreated from posthog.com/docs/privacy/soc2 as observed 2026-09-02; the linked report at posthog.com/security/soc2-report-2026.pdf loads without a gate.

What this costs in a security review

Nothing in this section needs a citation; it is the mechanics of the review itself. Every topic a reviewer can't answer from the public web becomes a questionnaire question: sent by email, routed to whoever holds the answer, written up, sent back, read. Each round-trip adds days, and the days accumulate while the deal sits in review. On today's table, PostHog starts with 18/20 topics answerable self-serve; Amplitude starts at 19/20 — the difference is round-trips.

Full findings

Topic-by-topic (public web only):

Publicly answerable (18): encryption at rest and in transit (control items on trust.posthog.com); SSO/SAML (posthog.com/docs/settings/sso — GitHub, GitLab, Google, custom SAML); subprocessor list (posthog.com/subprocessors — five vendors with locations; AI subprocessors appear when those features are enabled); data residency (US, or EU hosted in Germany — posthog.com/privacy); DPA (posthog.com/dpa); access control; backups; incident response; vulnerability management (responsible disclosure; Wiz named for vulnerability detection); employee security training; BC/DR; vendor risk management (third-party dependence items on the trust center); data retention/deletion (posthog.com/docs/privacy/data-storage); change management; logging/monitoring (audit logging); physical/hosting detail (AWS, US or Germany); compliance report access path (the public PDF, with the rest behind the trust center's self-serve gate).

Not publicly answerable (2): pentest cadence (a pentest report sits behind the trust center's access gate; no cadence stated) and uptime SLA (no stated uptime commitment found).

Reads well: three things in particular. The report PDF is public — no other company in this set does that. The DPA is readable as a page rather than a request flow. And the security chapter lives in the company handbook, written as working documentation rather than marketing copy. The transparency is real; only the wayfinding is not.

Appendix — topic ledger

Which topics counted toward each company's publicly answerable score in the table above.

PostHog 18/20
encryption at rest · encryption in transit · SSO/SAML · subprocessor list · data residency · DPA · access control · backups · incident response · vulnerability management · employee security training · BC/DR · vendor risk management · data retention/deletion · change management · logging/monitoring · physical/hosting security detail · compliance report access path
Amplitude 19/20
encryption at rest · encryption in transit · SSO/SAML · subprocessor list · data residency · pentest cadence · DPA · access control · backups · incident response · vulnerability management · employee security training · BC/DR · vendor risk management · data retention/deletion · change management · logging/monitoring · physical/hosting security detail · compliance report access path
Mixpanel 17/20
encryption at rest · encryption in transit · SSO/SAML · subprocessor list · data residency · pentest cadence · DPA · access control · backups · incident response · vulnerability management · vendor risk management · data retention/deletion · change management · logging/monitoring · physical/hosting security detail · compliance report access path
Heap 15/20
encryption at rest · SSO/SAML · subprocessor list · data residency · DPA · access control · backups · incident response · vulnerability management · employee security training · BC/DR · data retention/deletion · logging/monitoring · physical/hosting security detail · compliance report access path