Most B2B product-led companies obscure their marketing infrastructure behind custom front ends. PostHog's public capture instead shows a deliberately static Gatsby 4.25.9 build deployed on Vercel, protected by Cloudflare DNS with forced HTTPS, and a demand engine that routes visible conversion intent almost entirely through /pricing. This analysis excludes PostHog's own SDKs and tags by scanner design, so all observations below reflect third-party dependencies only.
The Stack at a Glance
PostHog's marketing site runs on Gatsby 4.25.9, a React-based static site generator, with Vercel as the deployment platform. The presence of Strapi as a headless CMS and Cloudinary for media transformation indicates a content pipeline built for editorial velocity rather than hand-coded page updates. Cloudflare sits in front for DNS, and Let's Encrypt issues the TLS certificate with forced HTTPS enabled. Email infrastructure is anchored by Google Workspace, with a backup MX record and SPF, DKIM, and DMARC policies set to quarantine.
The captured public sample is dominated by educational content, including buyer-focused sections such as /founders and /product-engineers. A lone utility SEO page, /google-analytics-alternative, targets a high-intent comparison keyword, while /pricing appears as the primary conversion endpoint in the sampled sitemap. No developer documentation pages were observed in the main marketing sitemap sample; app.posthog.com and us.posthog.com are linked but were not scanned, so product documentation and application delivery remain out of scope.
Google Tag Manager is the only third-party analytics tag detected on the captured pages. The scanner excludes PostHog's own instrumentation, so the absence of PostHog's product from the detected stack is not evidence of weak dogfooding. Action data from the crawl showed zero captured conversion events, but interactive forms and chat widgets may exist on unscanned subdomains or behind JavaScript-loaded components.
Content infrastructure choices matter for a product-led business. Gatsby pre-renders pages for performance and SEO, Strapi lets content teams publish without deploying code, and Cloudinary offloads image optimization. This stack reduces the operational burden on engineering while giving the marketing team a scalable publishing system. The tradeoff is that a static Gatsby site on Vercel cannot natively host server-side personalization or real-time A/B testing without additional JavaScript; no experimentation tooling was observed in the capture.
For engineering leaders, this stack signals a preference for composable front-end tooling over a monolithic CMS. Vercel provides edge caching and atomic deploys, Cloudflare manages DNS and DDoS protection, and Let's Encrypt keeps certificate costs at zero. The absence of a CAA record means certificate issuance is not restricted to approved authorities, which is a minor enterprise hardening gap despite a strong overall DNS posture.
The separation between marketing and product infrastructure is visible in the domain structure. The marketing site lives on posthog.com and is served by Vercel, while app.posthog.com and us.posthog.com are linked but unscanned. API domains include posthog.com and internal-c.posthog.com, suggesting that the product application and internal services run on separate infrastructure from the public marketing site. This is a common pattern for SaaS vendors that want marketing content to remain statically cacheable while the application runs on dynamic infrastructure.
Strapi and Cloudinary deserve specific attention because they reveal an operational philosophy: content teams own publishing, engineering owns performance. Strapi provides structured content APIs that Gatsby consumes at build time, and Cloudinary handles transformation, compression, and delivery for media. Without this pair, a content-heavy site would require more engineering involvement for every image or article update. The observed setup lets PostHog scale educational content without scaling marketing engineering headcount proportionally.
The only detected analytics tool is Google Tag Manager, which acts as a container for third-party tags. The scanner does not see PostHog's own product tags because those are filtered by design. Therefore, this capture cannot answer whether PostHog uses its own product analytics, session replay, feature flags, or A/B testing. Any statement about PostHog's dogfooding must come from product-level or public engineering sources, not this third-party stack scan.
How PostHog Captures Demand
PostHog's demand capture follows a content-heavy, product-led motion. The marketing site funnels visitors from educational articles and tutorials to /pricing, which links to app.posthog.com for product signup. Google Tag Manager is present for analytics injection, but no CRM, chat, ABM, or standalone ad pixel tools were observed in the captured sample. This means the visible top-of-funnel motion relies on organic content discovery and self-serve conversion rather than outbound or sales-assisted capture.
The content infrastructure directly supports this motion. Strapi enables non-technical authors to publish blog posts and tutorials, while Gatsby ensures each page is statically rendered for fast load times and search indexing. Cloudinary handles media optimization so images do not bloat page weight. The captured sitemap shows a high concentration of educational sections; buyer education is aimed at founders and product engineers, aligning with PostHog's product-led go-to-market.
The /google-analytics-alternative page is the clearest evidence of competitor-focused SEO. It targets buyers actively searching for a replacement to an incumbent analytics tool, a classic PLG wedge. The /pricing page is the only observed conversion path in the captured sample, which suggests PostHog wants pricing transparency to qualify self-serve users rather than hiding pricing behind a demo request.
Missing from the captured sample are forms, chat widgets, and marketing automation signals. Google Workspace is the only email-related detection, and that covers corporate email rather than lifecycle marketing. No Salesforce, HubSpot, Intercom, or Drift was detected, but the scanner's limited page sample and unscanned app/us subdomains mean these tools could exist behind authentication or in other properties. The captured action_count of zero reinforces that the survey did not observe interactive conversion events on the two captured posthog.com pages.
For product leaders, this GTM pattern suggests a deliberate choice to invest in content-led acquisition before building expensive marketing automation. Google Tag Manager gives flexibility to add pixels later, but the current capture shows no advertising pixels or experimentation tags. That aligns with PostHog's historical positioning: product analytics for developers, sold through a self-serve funnel that prioritizes volume and clarity over gated sales processes.
The content strategy also has a lifecycle gap. A large educational library can attract traffic, but without observed marketing automation, retargeting, or lifecycle emails, the captured sample provides no evidence of nurturing visitors who do not convert immediately. Competitors with HubSpot workflows, Customer.io sequences, or Meta and Google Ads pixels may be better positioned to re-engage anonymous visitors. However, PostHog's own product capabilities could fill some of these gaps, and the scanner excludes those tags.
The absence of observed chat and forms is notable. Many PLG companies use Intercom, Crisp, or Drift to answer pre-sales questions and capture emails from high-intent visitors. PostHog's captured sample shows no such widget, which may reflect a self-serve philosophy where the product itself answers questions. But a marketing site without visible interactive capture mechanisms can lose prospects who are not ready to sign up immediately. The /pricing page likely handles self-serve conversion, but anything beyond that would require deeper product or app subdomain scanning.
For founders evaluating PostHog's approach, the key insight is that content-led demand engineering works when the product is the salesperson. PostHog publishes deep tutorials and buyer education, then routes readers to pricing and product signup. The infrastructure stack supports this with Gatsby for speed, Strapi for publishing, and Cloudinary for media. What is not visible is the retargeting and lifecycle layer, which could be intentionally lean or located in PostHog's own product rather than third-party tools.
Infrastructure & Delivery Architecture
PostHog's public infrastructure scores high on operational trust. Cloudflare DNS maintains a grade A score of 97, with DNSSEC enabled and TLS certificates valid for 69 days. Forced HTTPS is active, and Let's Encrypt serves the certificate. Email security is also strong: SPF, DKIM, and DMARC policies are in place, with DMARC set to quarantine. MTA-STS and TLS reporting pass, suggesting the domain owner has configured email authentication to reduce spoofing and phishing risk.
The only observed infrastructure gap is the absent CAA record. Without CAA, certificate issuance is not restricted to approved certificate authorities, which is a hardening step enterprises often require. It is a minor issue compared with the overall DNS and email posture, but it stands out because PostHog otherwise shows meticulous configuration.
The application delivery path remains partially unknown. app.posthog.com and us.posthog.com are linked from the marketing site but were not scanned, and their HTTP status was null in the capture. API domains include posthog.com and internal-c.posthog.com. This suggests the product application and internal services are separated from the public marketing site, which is normal for a SaaS vendor. The marketing site uses Vercel for deployment, while the product likely runs on separate infrastructure not visible in the sitemap sample.
Cloudinary and Strapi represent the content pipeline's media and CMS layer. Gatsby consumes content from Strapi and media from Cloudinary at build time or via API, producing a static site that Vercel serves from its edge network. Cloudflare handles DNS and TLS termination before traffic reaches Vercel, creating a layered edge architecture.
For an enterprise buyer, the public infrastructure signals partial readiness. The DNS score of 97 and email security configuration are strong. However, the captured sitemap contains no trust center, security, compliance, or enterprise sales pages. Only /pricing is observed as a conversion endpoint in the sample. No demo request or contact sales page was captured, which can create friction for procurement teams that need vendor risk assessments and SLAs before purchase.
This split between infrastructure hygiene and enterprise-facing content is common for PLG companies. PostHog likely relies on self-serve adoption and product documentation to answer security questions, but those documentation pages may live on a separate subdomain not captured. The absence of a CAA record and lack of visible trust/compliance content in the sampled marketing sitemap are gaps that competitors can exploit in enterprise deals.
The email configuration deserves detail because it is a strong signal of domain maturity. SPF prevents unauthorized senders from using posthog.com in envelope from addresses. DKIM attaches cryptographic signatures to outgoing messages. DMARC set to quarantine tells receiving mail servers to isolate messages that fail authentication. Together with MTA-STS and TLS reporting, this setup reduces phishing and spoofing risk. For a company selling analytics to developers, that operational discipline transfers to buyer trust.
The DNS scorecard grade A with a 97 score reflects multiple factors: DNSSEC protects against DNS spoofing, forced HTTPS ensures all traffic uses TLS, and Let's Encrypt automation keeps certificates fresh. The 69-day validity window observed for the TLS certificate is typical for automated issuance and renewal. The one missing element is CAA, which would restrict certificate issuance to approved authorities like Let's Encrypt or DigiCert. Without CAA, a rogue certificate from an unauthorized CA is theoretically possible.
For engineering leaders evaluating infrastructure, the observed architecture is repeatable and cost-efficient. Gatsby static builds on Vercel cost little to serve at scale, and Cloudflare provides DDoS mitigation and DNS management. Strapi and Cloudinary add modest operational costs but dramatically reduce content and media delivery complexity. Google Workspace provides business email without running mail servers. This is a modern, low-maintenance infrastructure stack that prioritizes speed and security over custom tooling.
The product delivery architecture, though unseen, is hinted at by the domain names. internal-c.posthog.com suggests an internal service, possibly for configuration or ingestion. app.posthog.com likely hosts the product UI, and us.posthog.com may be a regional endpoint or user-specific subdomain. Because these were not scanned, the end-to-end product architecture cannot be assessed. However, the public marketing site's infrastructure does not need to reveal the product stack, and posthog.com API domains indicate that the main domain also serves API traffic.
What This Means for Competitors
Competitors evaluating PostHog's GTM should recognize that the captured public surface is a product-led education engine, not an enterprise marketing machine. Gatsby on Vercel with Strapi enables rapid content publishing, while Cloudflare and Google Workspace provide solid infrastructure. The visible conversion path is narrow: /pricing to app.posthog.com. This simplicity can drive high conversion rates for self-serve users, but it also leaves room for competitors to win deals where buyers expect sales engagement, security documentation, or procurement support.
The absence of detected advertising pixels, experimentation tools, and marketing automation in the captured sample suggests PostHog's growth maturity is rooted in organic content and product-led signups rather than paid acquisition or lifecycle orchestration. Competitors running HubSpot, Qualified, 6sense, or Google Ads with retargeting may generate more enterprise pipeline, but they also carry higher CAC. PostHog's approach likely produces lower-cost inbound leads at the expense of sales-assisted conversion.
For builders and founders, this stack shows how to assemble a high-velocity content system without heavy CMS licenses. Gatsby and Vercel provide modern front-end performance, Strapi gives marketing autonomy, and Cloudinary eliminates media bottlenecks. The downside is that a static site requires extra JavaScript for personalization, A/B testing, and interactive lead capture; none of those were observed in the captured sample.
The /google-analytics-alternative page is a strategic wedge. It targets a high-intent search phrase for users actively seeking to leave an incumbent analytics product. Competitors in the product analytics space should map PostHog's utility SEO pages and build counter-content that addresses migration pain points. Because the captured sample is truncated, there may be additional comparison pages beyond the one observed, but the presence of even one such page confirms the SEO playbook.
Infrastructure-wise, PostHog's grade A DNS and email security are table stakes for enterprise trust. However, the missing CAA record and the absence of trust/compliance pages in the sampled public sitemap create an opening. Competitors can differentiate by publishing transparent security documentation, maintaining CAA records, and offering a clear enterprise sales path with demo and contact-sales pages.
Finally, product leaders should not conclude that PostHog lacks experimentation or analytics simply because the scanner did not detect its own tags. The scanner filters PostHog's own SDKs by design, and the app and us subdomains were not scanned. Any competitive inference about PostHog's own product usage must come from separate product-level research, not this marketing-site capture.
The content supply chain is another competitive signal. Strapi as a headless CMS means PostHog can publish rapidly across blog and tutorial sections without involving engineers. Cloudinary automates image resizing and optimization, which keeps page performance high even with rich media. Competitors that rely on legacy CMS platforms like WordPress or custom content systems may ship content more slowly. A content velocity advantage becomes an SEO moat when combined with a static Gatsby front end that search engines can crawl efficiently.
PostHog's packaging of buyer education around /founders and /product-engineers shows persona-specific content at the top of the funnel. Founders get content about startup analytics and product-led growth, while product engineers get technical tutorials and migration guides. Competitors that treat all visitors with the same generic content will lose relevance. The infrastructure supports this personalization at the content architecture level, not through real-time personalization tools; instead, it uses URL-level segmentation and editorial targeting.
The observation that no CRM, chat, or ABM tools were captured should be understood as a limitation of the sampled public surface rather than a definitive statement about PostHog's sales stack. Many companies hide Salesforce or HubSpot behind forms or authenticated subdomains. The scanner's action_count of zero means no form submissions or chat interactions were captured, but that could be because the crawl did not trigger JavaScript-heavy widgets or because those widgets live on app.posthog.com. Competitors should validate this with their own product and sales intelligence before concluding PostHog has no sales-assisted motion.
For product leaders making build-vs-buy decisions, PostHog's public stack demonstrates that modern marketing infrastructure can be assembled from best-of-breed components: Gatsby for static generation, Vercel for deployment, Strapi for CMS, Cloudinary for media, Cloudflare for DNS, and Google Workspace for email. None of these tools are proprietary to PostHog, and the pattern is replicable by any B2B SaaS company. The differentiation is not the stack itself but the content engine and conversion routing built on top of it.
Key Takeaways
- PostHog's public marketing stack is Gatsby 4.25.9 on Vercel, with Strapi for CMS, Cloudinary for media, and Cloudflare for DNS/TLS — a composable, static-first architecture built for content velocity and edge performance.
- The captured conversion surface is narrow: /pricing routes to app.posthog.com, and no CRM, chat, ABM, or form data was observed in the sampled pages; Google Tag Manager is the only third-party analytics signal.
- Infrastructure trust is strong but not enterprise-complete: DNS grades A with a 97 score, DNSSEC, forced HTTPS, SPF/DKIM/DMARC quarantine, MTA-STS, and TLS reporting pass; the missing CAA record and absent trust/security pages in the sample are procurement friction points.
- The content strategy is heavily educational, with buyer-focused sections like /founders and /product-engineers plus a /google-analytics-alternative comparison page; this supports a product-led, self-serve GTM over sales-assisted motion.
- Founders and product leaders should treat this capture as a sampled public view, not a complete inventory: app.posthog.com, us.posthog.com, and PostHog's own product tags are excluded or unscanned, so product dogfooding and full funnel behavior remain unverified.