Vercel Security & compliance Releases

Log drain pointing at an unrecognized third-party host

Part of the Account supply chain check · fix arrives as a guide

What it is

A log drain is configured to forward deployment and runtime logs to a host that is not a recognised observability provider.

Why it matters

Log drains carry request paths, headers, and anything your application logs, continuously, to that endpoint. If it was configured by someone who has since left or by an integration nobody recognises, it is exfiltration on a schedule.

How to fix it

Confirm who set up the drain and what the destination is. Remove any you cannot account for, and check what your logs contain — a drain matters far more if the logs carry tokens or personal data.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.