Another week, another acquisition. Grafana Labs buying ______ (fill in the blank).
Their OSS core is solid. But their enterprise cloud offering? That's what we pay for.
My concern: every acquisition adds new proprietary code. It gets bundled, integrated, and sold as "enterprise-grade."
* Where's the SOC 2 Type II for the *entire* integrated platform post-acquisition? Not a blog post. The report.
* How does this affect data residency commitments in Grafana Cloud? New tool means new data flows.
* What's the real vendor risk now? Their attack surface just grew.
If you're evaluating them for anything serious, demand the evidence. Not roadmaps.
* Current audit reports
* Updated BAA and DPA
* Clear matrix of what's OSS vs. proprietary in the new stack
Without that, it's just more features wrapped in a security promise.
No SOC2, no deal.