Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Datadog

Datadog

enrichedPublic company (DDOG) ↗
Application Security (ASPM)Cloud-Native Application Protection (CNAPP)Data Loss PreventionSecrets DetectionSIEMWAF / DDoS / App ProtectionWorkload Protection

Represented by Carahsoft ↗

datadoghq.com ↗ · required email domain for this vendor's users

Headquartered in United StatesHeadquarters countrySourced only from this vendor's own published headquarters address (schema.org structured data on their site) — never guessed from domain TLD. Source ↗

Do you work at Datadog?

This profile was built from public sources and hasn't been claimed yet. Claiming it lets you correct what's wrong and add details only you can confirm — and marks that information as vendor-verified for buyers.

Free, and it does not affect ranking, placement, or comparison results. The first person verified on Datadog's email domain becomes the profile admin.

Claim this profileAlready have an account?

Trust profileHow to read thisFive separate questions a buyer actually asks, each answered with its own evidence and a link to the source. There is deliberately no overall score: a single number invites comparison it cannot support, and would mostly reflect how much of Datadog we have managed to scan rather than anything about the vendor.

Not checked means we have not looked yet, and is never counted against a vendor. Limited means we did look, but found only one line of evidence — enough to report, not enough to corroborate.

checked 8 of 16 signals
  • Limited

    Independently verified

    Has anyone other than the vendor confirmed this?

    checked 3 of 4

    Nothing here has been confirmed by an independent third party yet.

    • No third-party certifications found
    • Profile not claimed by the vendor
  • Strong

    Operating durability

    Is this a real, durable business?

    checked 2 of 4

    How long this vendor has been operating, and who stands behind them.

    • Headquarters: United States
    • 1 public SEC filing(s) — financials are a matter of record
  • Mixed

    Behaviour under stress

    What do they do when something goes wrong?

    checked 2 of 3

    What their public record shows about handling vulnerabilities and outages.

    • 28 published CVE(s) — a public disclosure record exists
    • 4 rated critical
    • Publishes a public status page
  • Limited

    Disclosure posture

    Do they tell you the awkward things unprompted?

    checked 1 of 3

    How much this vendor volunteers before you have to ask.

    • No bug bounty or vulnerability disclosure policy found
  • Not checked

    Momentum

    Are they still shipping, or coasting?

    checked 0 of 2

    We have not tracked this vendor's release activity yet.

    Nothing checked here yet — this is not a mark against Datadog.

Data coverage: 20/100What this measures (and doesn't)

Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.

Verification depth0/100
Security signal0/100
Buyer feedbackno data yet (0 reviews so far)
Profile completeness50/100
claim · HQ · materials · screenshots · integrations · certifications · security check

The platform admin controls the formula's weights.

Data coverage profileHow to read thisThe same four components behind the data coverage score above, shaped instead of listed — a vendor strong on verification but thin on buyer feedback looks visibly different from one that's the other way around. Security and feedback plot at the neutral midpoint (50) when there's no data yet (no products tracked, no reviews), matching how the actual score itself treats missing data — not a guess either way.

VerificationSecurityFeedbackCompletenessThis vendor — Verification: 0This vendor — Security: 0This vendor — Feedback: no data yetThis vendor — Completeness: 50

IntegrationsUI-12 — integration graphDetected from this vendor's own published integration/partner pages by the enrichment loop — each entry links the exact page it was found on. Directional: "integrates with" is claimed by this vendor; "integrated by" is claimed by the other vendor's site. Coverage grows as the scan progresses.

56 detected

Integrated by: AppOmni, Aqua Security, Bitsight, Cakewalk, Chainguard, CrowdStrike, D3 Security, Dropzone AI, Edge Delta, Elastio, Entro Security, Expel, ExtraHop, Fiddler AI, First Recon AI, FusionAuth, Gigamon, Hadrian, Invary, Konvu, Lansweeper, Monad, NetBird, Netmaker, OctoXLabs, Offroad, Oleria, Operant AI, Portkey, Portnox, Prophet Security, Reco, Red Canary, Relyance AI, Safe Security, Scytale, Seceon Inc, Secureframe, Seemplicity, Sentra, Simbian, Strobes Security, Sumo Logic, Teleport, Tenzir, Token Security, Torq, UpGuard, Upwind, Verosint, Wallarm, Willow, Wiz, Zscaler, spin.ai, torii

Buyer reviewsUI-14 — verified-buyer reviewsWritten only by domain-verified buyers at other companies, attributed to their company domain (never their identity), and moderated. Buyer-sourced opinion, clearly separate from the neutral catalog facts above — and never an input to search or comparison ordering.

verified buyers only

No buyer reviews yet.

Reputation ratingUI-20 — anonymous ratingA single anonymous 5-star signal from buyers, resellers, and analysts who've engaged with this vendor — separate from the domain-attributed reviews above. No rater identity is ever shown, not even at company level.

anonymous

No ratings in this window yet.

External ratingsUI-22 — third-party ratingsAggregate rating and review count pulled directly from the source site's own published data — never the review text itself, which belongs to that site. Links go to the real page so you can read the actual reviews there.

via third-party review sites
PeerSpot: 4.3/5 (211 reviews) ↗

Runtime protection for web apps and APIs against attacks and threats AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →

Product screenshots (3)

from their products
Datadog IaC SecurityautoDatadog Code Security Secret ScanningautoDatadog Cloud Securityauto

Security & trust signalsAbout these signalsCertifications are keyword-matched from the vendor's own public pages (each claim links to its source — verify directly before relying on it). Security headers are checked live against the vendor's homepage, re-checked every 90 days. Both are independent, automated signals, not a vendor-submitted or audited claim, and are not blended into a single score.

6 of 9 technical checks completed — not a score, just coverage

Security headers (5/5) — checked 8/14/2026

  • ✓ Strict-Transport-Security
  • ✓ Content-Security-Policy
  • ✓ X-Frame-Options
  • ✓ X-Content-Type-Options
  • ✓ Referrer-Policy
  • ✕ security.txt

Infrastructure & transparency signals

Status: operational ↗HSTS preloaded

Status historyAbout this timelineEvery incident detected on this vendor's own public status page since we started watching it — sourced from the same structural check as the status chip above, checked roughly hourly (every 5 minutes while an incident is active), never inferred. A resolution requires a real check confirming "operational" again; an incident with no resolution yet shown is still ongoing as of the most recent check.

No outages recorded since we started watching (first checked Aug 13, 2026, 11:59 PM).

CVE severity over timeUI-24 — CVE severity timelineEvery known CVE with a disclosure date and severity, plotted by when it was published — lets you see whether disclosures are trending toward more or less severe, not just a raw count. Same NVD-sourced, name-matched data as the list below.

LOWMEDIUMHIGHCRITICAL201820192020202120222023202420252026CVE-2026-47364 · MEDIUM 6.5 · 2026-08-07CVE-2026-47363 · MEDIUM 6.3 · 2026-08-07CVE-2026-47362 · MEDIUM 4.6 · 2026-08-07CVE-2026-47361 · MEDIUM 6.4 · 2026-08-07CVE-2026-44965 · MEDIUM 5.5 · 2026-08-07CVE-2026-44964 · MEDIUM 6.5 · 2026-08-07CVE-2026-50274 · HIGH 7.5 · 2026-07-17CVE-2026-50272 · HIGH 7.5 · 2026-07-17CVE-2026-50271 · HIGH 7.5 · 2026-07-17CVE-2026-50273 · HIGH 7.5 · 2026-07-17CVE-2026-57522 · LOW 3.5 · 2026-06-26CVE-2026-39197 · MEDIUM 6.5 · 2026-06-16CVE-2026-39196 · CRITICAL 9.8 · 2026-06-16CVE-2026-9270 · CRITICAL 9.1 · 2026-06-05CVE-2026-11362 · CRITICAL 9.8 · 2026-06-05CVE-2026-33728 · CRITICAL 9.8 · 2026-03-27CVE-2025-12697 · LOW 2.2 · 2026-03-11CVE-2025-59405 · HIGH 7.5 · 2025-10-02CVE-2024-38525 · HIGH 7.5 · 2024-06-29CVE-2023-37944 · MEDIUM 6.5 · 2023-07-12CVE-2023-0483 · MEDIUM 5.5 · 2023-03-10CVE-2022-3483 · MEDIUM 5.5 · 2022-11-10CVE-2022-3018 · MEDIUM 6.8 · 2022-10-28CVE-2022-2534 · LOW 2.2 · 2022-08-05CVE-2021-22260 · HIGH 7.7 · 2021-11-05CVE-2021-21331 · LOW 3.0 · 2021-03-04CVE-2017-1000114 · LOW 3.1 · 2017-10-05

Known CVEs (28)10 newAbout this listSourced from the public NVD database, matched by vendor name. This is a name-based match, not exact version tracking — always check the linked NVD record for affected versions before drawing conclusions. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-47364 ↗MEDIUM 6.5new2026

    In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash …

  • CVE-2026-47363 ↗MEDIUM 6.3new2026

    In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no …

  • CVE-2026-47362 ↗MEDIUM 4.6new2026

    In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recip…

  • CVE-2026-47361 ↗MEDIUM 6.4new2026

    In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the a…

  • CVE-2026-44965 ↗MEDIUM 5.5new2026

    In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallP…

  • CVE-2026-44964 ↗MEDIUM 6.5new2026

    In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-con…

  • CVE-2026-50274 ↗HIGH 7.5new2026

    Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage prop…

  • CVE-2026-50272 ↗HIGH 7.5new2026

    dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incom…

  • CVE-2026-50271 ↗HIGH 7.5new2026

    Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BA…

  • CVE-2026-50273 ↗HIGH 7.5new2026

    Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers wit…

  • CVE-2026-57522 ↗LOW 3.52026

    Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates with…

  • CVE-2026-39197 ↗MEDIUM 6.52026

    An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or payload.

  • CVE-2026-39196 ↗CRITICAL 9.82026

    Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to acc…

  • CVE-2026-9270 ↗CRITICAL 9.12026

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_st…

  • CVE-2026-11362 ↗CRITICAL 9.82026

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sourc…

  • CVE-2026-33728 ↗CRITICAL 9.82026

    dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data withou…

  • CVE-2025-12697 ↗LOW 2.22026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-…

  • CVE-2025-61667 ↗2025

    The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog Linux Host Agent versions 7.65.0 through 7.70.2 exists due to insufficient permis…

  • CVE-2025-59405 ↗HIGH 7.52025

    The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) contains a clear…

  • CVE-2024-38525 ↗HIGH 7.52024

    dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohm…

  • …and 8 more

Competitors (12)

full alternatives comparison →
AgileBlueAlibaba CloudApiiroAqua SecurityArray NetworksAstra SecurityBitdefenderBroadcomCheckmarxCrowdStrikeEntersoft SecurityRapid7

Products (11)

SIEM

1
  • Datadog Cloud SIEMAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Cloud-based SIEM for threat detection and security monitoring

WAF / DDoS / App Protection

1
  • Datadog App & API ProtectionAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Runtime protection for web apps and APIs against attacks and threats

Cloud-Native Application Protection (CNAPP)

2
  • Datadog Cloud SecurityAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Cloud security platform with CSPM, CIEM, vulnerability mgmt, and compliance
  • Datadog IaC SecurityAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Scans IaC templates for security misconfigurations before deployment

Application Security (ASPM)

4
  • Datadog Code SecurityAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Code security platform with SAST, SCA, IAST, and IaC security capabilities
  • Datadog Runtime Code Analysis (IAST)AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    IAST solution for runtime code vulnerability detection in applications
  • Datadog Software Composition AnalysisAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    SCA tool for identifying vulnerabilities in open-source dependencies
  • Datadog Static Code AnalysisAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    SAST tool for identifying security vulnerabilities in source code

Data Loss Prevention

1
  • Datadog Sensitive Data ScannerAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Scans logs and data streams to detect and redact sensitive data in real-time.

Workload Protection

1
  • Datadog Workload ProtectionAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Runtime workload protection for cloud and containerized environments

Secrets Detection

1
  • Datadog Code Security Secret ScanningAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Scans code repositories and runtime environments for exposed secrets and credentials