Telemetry

Choose which daily reports your Burrow sends RatelKey, and see the next one exactly as it will be sent.

Updated Oct 4, 2026

The Telemetry section under Settings decides which reports your Burrow sends RatelKey each day. There are three types, Instance, Usage and Clients, and each has its own switch. All three are on until you turn them off. Only the Burrow's owner can see or change this section, and every change is recorded in the audit log.

Reports go from your Burrow to RatelKey signed with the credential it received when you claimed it, and RatelKey files each one under your Burrow and the account that owns it. A Burrow that hasn't been claimed sends nothing.

What is never sent#

No report carries a secret's value, or the name of a secret, project, environment, machine or anything else you created. Machines and members are counted, never listed. Activity is counted by the kind of action, such as a secret read or a sign-in, never by what it touched.

Instance#

How your Burrow runs and how it is configured:

  • The platform it runs on, whether it is a Docker container or an installed Burrow, the operating system and its version, the Java version, the number of CPUs, its memory limit, and how long it has been running.

  • Whether it uses its built-in database or one you provide, and whether it serves HTTPS itself and with which kind of certificate.

  • Whether each of these is on: a custom domain, automatic updates, the relay and whether it is connected right now, local network only, port mapping, machine approval, the machine IP allowlist, audit log retention, IP data, and backups.

Usage#

What your Burrow holds, and what happened in it that day:

  • How many projects, environments and secrets it holds, how many secrets are structured or canaries, how many canaries are armed, how many single-value secrets there are of each type, and how many stored versions there are in total.

  • How many machines it has, split into machines enrolled with a command, machines enrolled with a machine token, and machines that sign in with OIDC such as GitHub Actions, plus how many are pending approval, disabled, or made a request that day, and how many machine tokens are still valid.

  • How many members did something that day, how many share links are still open, and how many webhooks it has and how many of them are on.

  • How many times each kind of action in the audit log happened that day, and how many of those were refused or failed.

Clients#

Which versions of the ratel CLI and the SDKs called your Burrow that day, and how many requests each made, for example ratel-sdk-python/1.2.0. A machine that calls your Burrow directly, without one of these tools, is counted as an HTTP request.

Next report#

Under the switches, Next Report shows today's report so far, exactly as your Burrow would send it with the switches as they are. Turning a type off removes its part from the report straight away. Last Sent shows when RatelKey last accepted a report from your Burrow.

When reports are sent#

Your Burrow reports each day once it is over, counted in UTC. After you install or update it, it also sends the current day so far, which the full report for that day replaces the next day. If your Burrow was offline, it catches up on the days it missed, up to a week back.

Turning a type off stops it being counted and drops whatever it had counted and not yet sent. With all three off, your Burrow sends nothing, and the days it spends that way are not reported later when you turn telemetry back on.

RatelKey keeps each report for 12 months.