3 ms·
Not just PII, but access tokens to 3rd party systems in case of integrations and whatnot. A Sentry data leak could include valid access tokens to, say, all dat
by metafunctor 4y ago
Not just PII, but access tokens to 3rd party systems in case of integrations and whatnot.
A Sentry data leak could include valid access tokens to, say, all data on a customer's Docusign account. We try to make sure data like that is scrubbed before sending to Sentry… but mistakes can happen. This is simply not a risk we are willing to take.
Thus, we self-host Sentry in our own secure infrastructure (we are a SaaS provider ourselves), and accept all the maintenance burden that it entails.