PostHog, Inc.
United States · owned by Independent (United States) · posthog.com · 53 vendors
PostHog is an open-source product and data toolkit that provides engineers with a comprehensive suite of developer tools — including product analytics, session replay, feature flags, A/B testing, and a data warehouse — all in one platform. Founded in Y Combinator's W20 batch by James Hawkins and Tim Glaser, PostHog is designed to help product engineers build, test, measure, and ship successful products faster. The company serves over 190,000 teams and operates with a usage-based pricing model and a strong commitment to transparency and open source.
Resilience scores
- Digital Sovereignty: 81
- Digital Resilience: 9
Disruption prediction
PostHog, Inc. has an estimated 11% probability of disruption in the next 6 months.
29 of PostHog, Inc.'s 53 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Netlify, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 52 more
Services catalogue
5 services in catalogue across 3 categories; runs on 53 sub-vendors.
- Product Analytics
- Personal Data Processing
- Telemetry
Insights
Last updated 2026-09-12 · revision 21
53 direct vendors, 424 subvendors
Direct vendors by controlling owner country (sample)
- Poland: 1
- China: 2
- Sweden: 3
Subvendors by controlling owner country (sample)
- Japan: 6
- Czech Republic: 1
- Denmark: 6
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
PostHog exhibits very high migration readiness, scoring 92. This is primarily due to its cutting-edge, cloud-native architecture, strong compliance, and inherent flexibility in data deployment. **Strengths:** * **Cloud-Native and Containerized Architecture:** PostHog's internal tech stack is a prime example of modern cloud-native development, utilizing Kubernetes and Docker for containerization. This architecture, combined with microservices principles (Kafka, event-driven architecture) and multi-cloud deployment (AWS, GCP), makes their systems highly portable and adaptable to different environments. This significantly reduces the technical hurdles typically associated with large-scale migrations. * **Open-Source Foundation:** The extensive use of open-source technologies like ClickHouse, PostgreSQL, Python, and Kubernetes inherently reduces vendor lock-in. This provides flexibility in choosing infrastructure providers and tools, making migrations less dependent on proprietary systems and licensing agreements. * **Architectural Flexibility for Data Residency:** The availability of a self-hosting option, allowing customers to deploy PostHog in any region or cloud provider, is a testament to the platform's architectural flexibility. This demonstrates that PostHog's core systems are designed to be portable and can meet diverse data residency requirements, a critical factor for successful migrations. * **Strong Regulatory Compliance:** PostHog's certifications (GDPR, SOC 2 Type 2, ISO 27001) and awareness of NIS2 mean they have established processes and controls for data security and privacy. This maturity in compliance simplifies migration efforts, as their systems are already designed to meet stringent regulatory standards, reducing the risk of non-compliance during a transition. * **Financial Capacity:** The announcement of multiple funding rounds suggests a healthy financial position, providing the necessary capital to invest in and execute potential migration initiatives without significant financial strain. **Weaknesses/Challenges:** * **Unknown Vendor Lock-in Risk:** While the tech stack suggests low lock-in, the "Vendor Lock-in Risk: Unknown" for the 105 services is a potential area of concern. A detailed analysis of these services and their associated vendors would be necessary to fully quantify any hidden dependencies or contractual complexities that could impede migration. The "Total Vendors: 0" data point is contradictory and makes a precise assessment of vendor concentration difficult, though the open-source nature of core components mitigates this. * **Complexity of 105 Services:** While the architecture is modern, managing 105 services could introduce complexity during a migration if not properly orchestrated. Each service represents a potential dependency or integration point that needs careful planning. Despite the unknown vendor lock-in and the sheer number of services, PostHog's fundamentally modern, open-source, and flexible architecture positions it with exceptionally high migration readiness.
Compliance
6 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is a globally recognized information security standard and a common customer expectation in the technology sector, particularly outside North America. It is often requested alongside or as an alternative to SOC 2.
While not having ISO 27001 is a minor competitive disadvantage, the presence of a SOC 2 Type 2 report mitigates much of the associated risk, as it provides a comparable level of security assurance for most customers.
Evidence: https://posthog.com/handbook/company/security, https://posthog.com/docs/privacy, https://posthog.com/docs/privacy/soc2
ePrivacy Directive — Assessment Required
The directive applies to the use of cookies and similar tracking technologies on users in the EU. As an analytics platform, PostHog's product is directly related to these technologies, and its own website uses them.
Enforcement is typically handled by national DPAs, and penalties are less severe than under GDPR. The primary risk is the need to adjust cookie consent mechanisms on customer-facing websites.
Evidence: https://posthog.com/docs/privacy/gdpr-compliance, https://dealroom.co/companies/posthog/, https://posthog.com/people, https://leadiq.com/c/posthog/5e6ba3de1d6f06b382236a35, https://www.appsruntheworld.com/customers-database/products/view/posthog, https://pitchbook.com/profiles/company/433412-74
HIPAA (source) — Partially Compliant
PostHog is a "business associate" under HIPAA when its customers are "covered entities" that process Protected Health Information (PHI) through the PostHog platform. The company explicitly markets HIPAA-compliant analytics.
Handling PHI without full compliance could lead to severe penalties and reputational harm. The risk is medium as applicability depends on specific customer use cases, which PostHog has taken steps to manage contractually.
Evidence: https://posthog.com/docs/privacy, https://posthog.com/compare/best-hipaa-compliant-analytics-tools, https://posthog.com/compare/best-hipaa-compliant-ab-testing-tools, https://posthog.com/docs/privacy/hipaa-compliance, https://posthog.com/enterprise
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: null/10
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.