| Independent security / no-logs audit | ❌Not foundNo public third-party audit of cookieless/no-IP claims found | 🔒On request / NDATrust portal lists a pentest report and security whitepaper behind access. Security page claims annual external pentests, monthly scans, and a public bug bounty. No public no-logs audit (wrong category for a behavior recorder). |
|---|
| ISO 27001 | ❌Not foundNo ISO 27001 claim on public site/security pages (none published) | ⚠️Vendor claimedTrust portal and security page state ISO/IEC 27001 certification (also 27017, 27018). Certificate files require portal access. Not independently verified in a public registry during this draft. |
|---|
| SOC 2 / SOC 3 | ❌Not foundNo SOC 2/3 report referenced publicly | ⚠️Vendor claimedVendor states it holds a SOC 2 Type II report. Report is on the trust portal, not a public PDF in this research pass. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedGerman controller; cookieless/no-IP design claims on privacy policy (last updated 2022). Not legal advice—confirm with counsel and DPA. | ⚠️Vendor claimedFrench SAS, public DPA with GDPR, UK GDPR, ePrivacy Directive, EU SCCs (French law, French courts), customer-as-controller. Customer still owns consent, masking, and lawful basis for visitor capture. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU sole proprietor, no known US parent; vendor EU-hosting claims and DE-associated hosting for the public site. Optional Google Search Console involves Google; Paddle handles payments; infrastructure subprocessors not fully named. Indicative only—not legal advice. | ⚠️PartialEuropeanStack assessment, not a vendor slogan. French entity and no known US parent, but visitor data sits on AWS and Azure (US-group clouds), a US affiliate provides support, and US SaaS subprocessors include Zendesk, Postmark, OpenAI, Deepgram, Snowflake, and Salesforce. US region is an explicit option. DPF covers the US entity. Not legal advice. |
|---|
| Data processing agreement (B2B) | ❌Not foundNo public DPA page or in-product DPA download found; ask vendor before production use | ⚠️Vendor claimedPublic DPA last updated June 2026 (v.2026.2). Subprocessor objection window 30 days. SCCs Module Two and Three. |
|---|
| EU AI Act | —Not applicableWeb analytics measurement product; not marketed as an AI system | ⚠️PartialSense is in-product generative AI over customer and visitor data (Bedrock, Azure, OpenAI). No public AI Act conformity statement found. Customer is told to avoid personal data in prompts. Not treated as not_applicable. |
|---|
| ISO 27701 | Not listed | ⚠️Vendor claimedVendor claims ISO/IEC 27701 on the trust portal and company page. Same access-gated evidence. |
|---|
| EU-U.S. Data Privacy Framework | Not listed | ⚠️Vendor claimedDPA and services privacy policy state Content Square, Inc. is DPF certified (EU-U.S., UK Extension, Swiss-U.S.). Listing not re-opened during this draft. |
|---|
| HIPAA | Not listed | ⚠️Vendor claimedSecurity page displays a HIPAA mark. No public BAA text reviewed. Confirm with vendor if health data is in scope (DPA says the service is not designed for sensitive data). |
|---|
| CSA STAR | Not listed | ⚠️Vendor claimedSecurity page shows a STAR mark. Trust portal lists CAIQ. Registry entry not independently opened. |
|---|