Langfuse

Langfuse (ClickHouse)

Open Source

Open-source LLM engineering platform for tracing, evaluations, prompt management and cost/latency dashboards, built on OpenTelemetry.

Curated by Tiberiu ArvaVerified

MIT core + EE pathsVersion 4.48.0Released 2026-09-30

Strengths

  • MIT core self-hostable at production scale
  • Prompt management with versioning and playground
  • OpenTelemetry-based tracing with 100+ integrations

Practitioner note

ClickHouse acquired Langfuse in January 2026 and committed to keeping the core MIT. Self-hosting means running Postgres, ClickHouse, Redis/Valkey and S3-compatible storage, and audit logs and SCIM are Enterprise-only, so budget for both before choosing self-hosting over Langfuse Cloud.

Warning

Langfuse: Langfuse is open core: everything outside the ee/, web/src/ee/ and worker/src/ee/ directories is MIT, but code in those directories needs a commercial Langfuse Enterprise License for production use (development and testing are allowed without one).

Governance posture

Reviewed 2026-09-30
YesData residency

Langfuse Cloud offers US (us-west-2), EU (eu-west-1), JP (ap-northeast-1) and a HIPAA region; self-hosting keeps all data in the operator's infrastructure.

Source
YesDeployment model

Managed Langfuse Cloud, or self-hosted via Docker Compose (single VM) or Kubernetes/Helm on AWS, Azure or GCP. (saas, self-hosted)

Source
PartialAudit logging

Audit logs are listed only on the Enterprise cloud plan ($2,499/month) and in the licensed EE features. Lower tiers and the MIT core have none.

Source
YesSOC 2

Langfuse Cloud has completed a SOC 2 Type II audit (report on Pro/Team/Enterprise plans). Self-hosted deployments rely on the operator's controls.

Source
YesISO 27001

Langfuse Cloud is ISO 27001 certified (certificate on request for Pro/Team/Enterprise). Not applicable to self-hosted instances.

Source
UnknownISO 42001

The Langfuse security page lists SOC 2, ISO 27001, HIPAA and GDPR but does not mention ISO 42001.

N/AEU AI Act

Observability and evaluation tooling for AI applications, not an AI system placed on the market. Obligations rest with the deployer of the traced system. (role: not-applicable)

YesLicense risk

Open core: MIT outside the ee/ directories, with a commercial license required for EE features in production. ClickHouse committed to keeping the core MIT after the acquisition. (medium)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from Langfuse's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.