Skip to content
inetGeek

Security and compliance

SAML SSO, SCIM provisioning, MFA, audit logging, and whether a provider can be self-hosted — spanning auth, secrets management and observability, wherever a provider actually documents one of these. Every figure is sourced; a blank cell means undocumented, not "no."

Identity and access

ProviderCategorySAML SSOSCIMMFAAudit logsSelf-hostable
Auth0AuthenticationSupportedSupportedSupportedAudit log streaming to Datadog, Splunk, AWS and Azure, from the Essentials plan up. Auth0 publishes no retention window on the pricing page.
Better AuthAcquired by VercelAuthenticationSupportedSupportedSupported10,000 audit log events a month with 1-day retention on the free Starter plan; 20,000 on Pro, then $0.0001 per event.Supported
ClerkAuthenticationSupportedSupportedSupportedApplication logs with 1-day retention on the free Hobby plan; longer retention is a paid-plan feature Clerk lists without publishing the window.
DopplerSecrets management3 days of activity log retention on Developer (free), 90 days on Team, custom retention on Enterprise.
Elastic CloudError tracking and observabilityNot documentedSupported
GlitchTipError tracking and observabilityNot documentedSupported
Grafana CloudError tracking and observabilityNot documentedSupported
InfisicalSecrets managementNone on Free. 30-day retention on Pro, 90-day on Advanced, custom retention on Enterprise.
KindeAuthenticationSupportedSupportedNot documented
OpenObserveError tracking and observabilityNot documentedSupported
SentryError tracking and observabilityNot documentedLimited
SigNozError tracking and observabilityNot documentedSupported
StytchAcquired by TwilioAuthenticationSupportedSupportedSupportedNot documented
SuperTokensAuthenticationSupportedNot documentedSupported
WorkOSAuthenticationSupportedSupportedSupportedBilled rather than bundled: $125 per month per SIEM connection for log streaming, plus $99 per month per million events stored.

Compliance certifications

Yes/No/— compresses each provider's own sourced wording — a self-certification reads differently from an audited report, and the full nuance is one click away on the provider's own page. "No" only appears where a provider explicitly documents the absence (Clerk's own page says plainly it is not ISO 27001 certified); a dash means undocumented, never assumed.

ProviderCategorySOC 2ISO 27001HIPAAGDPRPCI DSS
Amazon S3Object storageYesYes
Auth0AuthenticationYesYesYesYesYes
AWS Secrets ManagerSecrets managementYesYes
ClerkAuthenticationYesNoYesYesNo
DopplerSecrets managementYesYes
KindeAuthenticationYesYesYesYes
NeonManaged databasesYesYesYesYesYes
NetlifyFrontend and serverlessYesYesYesYesYes
PostmarkTransactional emailYes
RailwayApplication platformsYesYesYes
ResendTransactional emailYesNoNoYes
SentryError tracking and observabilityYesYesYes
SupabaseManaged databasesYesYesYesYes
VercelFrontend and serverlessYesYesYesNoYes
WorkOSAuthenticationYesYesYes

When these numbers change, hear about it. Sources are re-checked monthly; a repricing goes out as a short note.

Confirm by email; unsubscribe from any issue. Your address goes to Kit and nowhere else — what we do with it.

Every page here is sourced and dated.