Infracost

Infracost publicly advertises 2 compliance frameworks through a trust center hosted by Vanta.

Developer Tools & Infrastructure

2

Advertised frameworks

Vanta

Trust center platform

May 2024

First observed

Founding to trust center

FinOps governance for platform teams. Prevent cloud waste and budget overruns before every deploy.

Summary from the company’s website.

Publicly advertised compliance posture

As observed on September 8, 2026 on the organization’s public trust center.

  • SOC 2

    Independent CPA audit of controls for security, availability, and confidentiality.

  • GDPR

    Public claim of alignment with the EU General Data Protection Regulation.

Compliance timeline

  1. May 2024

    Trust center first observed in public web archives

  2. September 8, 2026

    Posture last observed by Trust Index

Subprocessors

Third parties Infracost discloses on its trust center. Linked entries have their own profile in the Trust Index.

72% chain trust: 13 of 18 disclosed subprocessors are themselves in the Trust Index.

  • Amazon Web Services Production infrastructure
  • Google Workspace Workspaces including email
  • Auth0 Authentication of users
  • Close Customer Relationship Management
  • Segment Product analytics
  • Postmark Sending user emails
  • Mixpanel Product analytics
  • Sentry Error analytics
  • Clearbit Customer Relation Management
  • Stripe Payment processor
  • Retool Product analytics
  • Pylon Customer support
  • Linear Collaboration
  • Notion Document management
  • Incident.io Incident management, used internally to detect, manage, and resolve operational incidents affecting our platform.
  • LaunchDarkly Feature flagging, enabling controlled rollout and management of product features.
  • Anthropic AI-powered capabilities within the product, as well as limited internal use to support debugging, investigation, and improvement of system behaviour.
  • Common Room Customer engagement and product analytics, helping us understand usage patterns and improve customer experience.

About this data

The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.

More in Developer Tools & Infrastructure

How can we work together

Schedule a discovery session

A complimentary, exploratory meeting to discuss your business goals and challenges, identify potential solutions, and determine if our services align with your needs.

Hire us for a project

Augmenting a specific initiative or project, leveraging our expertise and resources to deliver a defined outcome.

Retain us long term

Ongoing collaboration and support through regular meetings, check-ins, and access to our team's collective knowledge and experience, empowering you to make informed decisions and drive sustained growth.