Ridgeline Technologies, LLC · Last updated: August 11, 2026
This page describes how our Grafana plugins handle your data and credentials, and how to report a security issue to us.
Our plugins are designed so that we never receive your data. The plugin executes entirely within your own Grafana environment and queries only the systems you configure it to query. No telemetry, metrics, monitored data, or credentials are transmitted to Ridgeline Technologies, and we operate no data collection or processing infrastructure in connection with the plugins.
This is an architectural property, not a policy commitment. There is no channel by which your operational data could reach us.
secureJsonData), managed and encrypted by your Grafana installation.Our plugins are distributed through the Grafana Labs Marketplace and are signed under Grafana’s plugin signing process. Grafana verifies the signature before loading a plugin. Install our plugins only through the Marketplace or another channel we have published.
If you believe you have found a security vulnerability in one of our plugins, please email [email protected].
Where possible, please include:
We will acknowledge your report within five business days and will keep you informed as we investigate. We ask that you give us a reasonable opportunity to remediate before public disclosure. We will not pursue legal action against researchers who report findings in good faith, avoid privacy violations and service degradation, and do not access or modify data beyond what is necessary to demonstrate the issue.
We do not currently operate a paid bug bounty program.
Ridgeline Technologies, LLC holds no third-party security certifications at this time. We do not claim SOC 2, ISO 27001, PCI DSS, or HIPAA compliance. We would rather state this plainly than imply coverage we do not have.
The third parties we rely on to operate our business are listed on our Subprocessors page. None of them receive data from your Grafana environment.
Ridgeline Technologies, LLC
[email protected]