Vercel
Security & compliance
Releases
Log drain pointing at an unrecognized third-party host
Part of the Account supply chain check · fix arrives as a guide
What it is
A log drain is configured to forward deployment and runtime logs to a host that is not a recognised observability provider.
Why it matters
Log drains carry request paths, headers, and anything your application logs, continuously, to that endpoint. If it was configured by someone who has since left or by an integration nobody recognises, it is exfiltration on a schedule.
How to fix it
Confirm who set up the drain and what the destination is. Remove any you cannot account for, and check what your logs contain — a drain matters far more if the logs carry tokens or personal data.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.