| Independent security / no-logs audit | —Not applicableNot a no-logs VPN/analytics product; marketing data platform processes customer event/profile data by design. | 🔒On request / NDATrust portal lists a pentest report and security whitepaper behind access. Security page claims annual external pentests, monthly scans, and a public bug bounty. No public no-logs audit (wrong category for a behavior recorder). |
|---|
| Independent security / pentest program | ⚠️Vendor claimedSecurity product sheet claims external pentests (black/grey box) every six months and customer audit rights; no public audit PDF reviewed. | Not listed |
|---|
| ISO 27001 | ⚠️PartialSecurity sheet attributes ISO 27001 (and related) compliance to the hosting provider in France; not verified as Commanders Act's own current certificate. | ⚠️Vendor claimedTrust portal and security page state ISO/IEC 27001 certification (also 27017, 27018). Certificate files require portal access. Not independently verified in a public registry during this draft. |
|---|
| SOC 2 / SOC 3 | ⚠️PartialSecurity sheet states hosting provider complies with SOC Type 1 and 2; not verified as vendor-owned SOC 2 report. | ⚠️Vendor claimedVendor states it holds a SOC 2 Type II report. Report is on the trust portal, not a public PDF in this research pass. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedFrench controller/processor entity; public privacy policy, named DPO, EU storage claim for site data, integrated consent tooling. Customer DPA terms not fully public on marketing pages. | ⚠️Vendor claimedFrench SAS, public DPA with GDPR, UK GDPR, ePrivacy Directive, EU SCCs (French law, French courts), customer-as-controller. Customer still owns consent, masking, and lawful basis for visitor capture. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity / no known US parent, but Cloudflare CDN on public app/platform hostnames and incomplete public subprocessor list for customer data path. Not legal advice. | ⚠️PartialEuropeanStack assessment, not a vendor slogan. French entity and no known US parent, but visitor data sits on AWS and Azure (US-group clouds), a US affiliate provides support, and US SaaS subprocessors include Zendesk, Postmark, OpenAI, Deepgram, Snowflake, and Salesforce. US region is an explicit option. DPF covers the US entity. Not legal advice. |
|---|
| Data processing agreement (B2B) | ?UnknownWebsite privacy policy covers visitor/site processing; standard B2B DPA / Art. 28 package not located as a public self-serve download—request in procurement. | ⚠️Vendor claimedPublic DPA last updated June 2026 (v.2026.2). Subprocessor objection window 30 days. SCCs Module Two and Three. |
|---|
| EU AI Act | —Not applicableIncludes AI-assisted ad recommendations; not assessed here as a high-risk AI system product category. | ⚠️PartialSense is in-product generative AI over customer and visitor data (Bedrock, Azure, OpenAI). No public AI Act conformity statement found. Customer is told to avoid personal data in prompts. Not treated as not_applicable. |
|---|
| ISO 27701 | Not listed | ⚠️Vendor claimedVendor claims ISO/IEC 27701 on the trust portal and company page. Same access-gated evidence. |
|---|
| EU-U.S. Data Privacy Framework | Not listed | ⚠️Vendor claimedDPA and services privacy policy state Content Square, Inc. is DPF certified (EU-U.S., UK Extension, Swiss-U.S.). Listing not re-opened during this draft. |
|---|
| HIPAA | Not listed | ⚠️Vendor claimedSecurity page displays a HIPAA mark. No public BAA text reviewed. Confirm with vendor if health data is in scope (DPA says the service is not designed for sensitive data). |
|---|
| CSA STAR | Not listed | ⚠️Vendor claimedSecurity page shows a STAR mark. Trust portal lists CAIQ. Registry entry not independently opened. |
|---|