Enterprise
Custom pricingRBAC, dedicated support, training, and more. Includes all features in the Scale and Boost packages.
Everything in Scale, plus
- SCIM
- Role-based access control
- Dedicated account manager
- Priority support · Target response time 8 hours
- Ongoing training
- Terms and conditions · Custom MSA
Scale
$750/moPriority support, SAML, and more features to scale your organization. Includes all features in the Boost package.
Everything in Boost, plus
- SAML SSO
- Priority support · Target response time 24 hours
- Approvals
- Activity logs · 2 months
- Real-time alerts · 10 alerts
- XAA authentication
Boost
$250/moUnlimited projects, white labeling, HIPAA BAA, SSO enforcement, and features for collaboration with team members.
- HIPAA BAA
- Enforce SSO login
- Enforce 2FA
- Projects · Unlimited
- White labeling
- Access control
Not convinced? Check out these four corporate buzzwords.
Compliance
Keeping regulators happy since 2020. PostHog is GDPR, HIPAA, and CCPA compliant.
- US or EU Cloud: Choose where your data is stored when you sign up: the US or Frankfurt, Germany.
- GDPR with a self-service DPA: PostHog is the processor, you are the controller. Generate, sign, and download your DPA in minutes.
- HIPAA-ready with a BAA: Standard BAAs on Boost, Scale, and Enterprise; custom BAAs on Enterprise. Our guidance covers setup requirements and features excluded from the BAA.
- Your data stays yours: You own the customer data you send to PostHog. We process it on your behalf, separately from analytics about your use of PostHog.
- Data deletion controls: Respond to deletion requests by removing people, their events, and their recordings through the UI or API.
- Documents for vendor review: Review our SOC 2 report, penetration test report, subprocessors, and security policies in the Trust Center.
Security
We try to break our product so you don't have to. We publicly publish our findings and security advisories and give you fine-grained controls to protect your data.
- SOC 2 Type 2: Audited every year by an external firm. The latest report is public and available via the link above.
- Annual third-party penetration testing: Plus a public vulnerability disclosure program. Reports are available in the Trust Center.
- SSO and 2FA enforcement, SAML, and SCIM: Enforce SSO and 2FA for the whole organization. Add SAML on Scale and SCIM provisioning on Enterprise.
- Role-based and property-level access: Custom roles across projects and resources, and access control down to individual event and person properties.
- Activity logs you can ship to your SIEM: Who changed what, when, and the before and after. Retained for up to 60 months on Enterprise.
- Public security advisories: We publish advisories and CVEs, and we contact affected users directly.
Scalability
Love vendor lock-in? Yeah, we don't either. We're building a platform that scales with your business, not the other way around.
- Sync from your warehouse: Pull tables from Snowflake, BigQuery, Redshift, Postgres, MySQL, SQL Server, ClickHouse, Databricks, and object storage.
- Export back out: Batch exports to S3, Snowflake, BigQuery, Redshift, Postgres, Databricks, and Azure Blob. Realtime destinations for everything else.
- No rate limit on capture: Public capture endpoints are not rate limited, and every official SDK batches and sends asynchronously.
- Managed migrations: Import history from Amplitude and Mixpanel directly, or from S3 for anything else. Historical imports are free.
- Unlimited projects, long retention: Separate projects per environment or business unit, and up to 60 months of replay retention on Enterprise.
- Case study: AssemblyAI: Moved millions of events a day to PostHog and stopped throttling ingestion.
Support
You can listen to hold music on your own time. Enterprise gives you a named human and engineers within reach when you need them.
- Dedicated account manager: One person who knows your setup, your contract, and your roadmap.
- Priority support, 8-hour target response: On Enterprise. Scale customers get a 24-hour target.
- A shared Slack channel: Talk to the engineers who build the product, in a private channel with your team.
- Ongoing training: Sessions for new teams and new products as your usage grows.
- Forward-deployed engineers: A paid, scoped engagement: we send an engineer to migrate, instrument, integrate, and train alongside your team.
Want your business to use PostHog?
Believe it or not, so do we! Set up a meeting with our sales team and we'll work out how to make it happen.
In the meantime - forward this email to your CISO
- To:
- CISO
- Subject:
- Urgent strategic alignment on PostHog
Good morning CISO,
I hope your morning is off to an exceptionally productive start. I am writing to bring a matter of urgent strategic importance to your attention: the potential adoption of PostHog. To facilitate a comprehensive, cross-functional assessment of this opportunity, I have proactively consolidated the following documentation into a single, conveniently actionable correspondence.
- Trust CenterReports, policies, and certifications
- SOC 2 reportThe current audit, in full
- Security handbookHow we run security
- Privacy and compliance docsGDPR, HIPAA, CCPA, data storage
- Data processing agreementGenerate and sign yourself
- Business associate agreementFor HIPAA customers
- Platform packagesWhat Boost, Scale, and Enterprise include
- Customer storiesWho runs on PostHog, and how
Kind regards,
Your proactively aligned colleague
(Sent using Microsoft Outlook 2007)