Commanders Act vs Publytics

Compare Commanders Act and Publytics on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Adobe Analytics, Google Analytics

Logo: Commanders Act

Commanders Act

France· Web Analytics

Needs review

Shortlist when you need an EU-headquartered enterprise stack combining server-side tag management, consent, real-time CDP activation, and independent media attribution (Adloop). Skip when you only need lightweight privacy analytics or open-source self-hosting—consider etracker or fusedeck for narrower EU measurement/tagging scopes, or Matomo-class tools for self-host analytics.

EU-operated (FR)Server-side TMSReal-time CDPIntegrated CMPAdloop attributionSaaS only
Logo: Publytics

Publytics

Italy· Web Analytics

Needs review

Shortlist when you need cookieless, unsampled publisher analytics with multi-site Network views and a public EU DPA from an Italian SaaS operator. Skip when you need self-hosting, product analytics at GA4/Adobe depth, or product-level ISO/SOC—consider Plausible (simpler privacy analytics / self-host options) or Matomo (self-host ownership) instead.

Cookieless trackingNo default samplingMulti-site NetworkEU-hosted (EuroVPS/Hetzner)Public B2B DPAPublisher-focused UX
Commanders Act vs Publytics: Snapshot
FeatureLogo: Commanders ActCommanders ActLogo: PublyticsPublytics
Country of originFranceItaly
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersFranceItaly
Legal entityFjord Technologies SAS (trading name Commanders Act), SIREN 527 730 782, ParisPublytics S.r.l. / Publytics SRL, Via Val Leventina 3 INT 1, 20148 Milan (MI), Italy (VAT IT13079420967)
Governing lawNot listedItaly / EU GDPR (processor under published DPA)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyVendor: EU/France data centers for platform hosting; privacy policy: site data stored in EU. Public DNS: app/platform behind Cloudflare CDN. Hosting provider certs (ISO 27001, SOC 1/2, etc.) claimed on Security product sheet. Full customer-data subprocessor list not published on marketing site.Analytics infrastructure subprocessors in public DPA: EuroVPS (Euclid Services Ltd, Cyprus) and Hetzner Online GmbH (Germany). Data policy/DPA: EU storage (NL, DE, FI; DPA also IT); no transfer outside the EU for analytics processing. Account path: Stripe (payments), Brevo/Sendinblue (email).
Summary

French PlatformX MarTech suite from Fjord Technologies: enterprise server-side tag management, integrated consent, real-time CDP, and Adloop media attribution for multi-channel marketing teams.

Cookieless web analytics SaaS for digital publishers: unsampled real-time and historical metrics, multi-site Network views, GA import, and EU-hosted measurement from an Italian company.

Tags
At a glance: Commanders Act vs Publytics
At a glanceLogo: Commanders ActCommanders ActLogo: PublyticsPublytics
HQParis, France (Fjord Technologies SAS)Milan, Italy
SIREN527 730 782Not listed
Founded2010 (as TagCommander / Fjord Technologies)Not listed
DeploymentManaged SaaS (not self-hosted)Managed SaaS (not self-hosted)
Core suiteTMS + CMP + CDP + AdloopNot listed
Commercial modelDemo / enterprise quote (no public list price)Pageview tiers; free trial
Legal entityNot listedPublytics S.r.l. (VAT IT13079420967)
HostingNot listedEuroVPS + Hetzner (EU regions)
Open sourceNot listedNo (tracker uses MIT library code)
Key capabilities: Commanders Act vs Publytics
Key capabilitiesLogo: Commanders ActCommanders ActLogo: PublyticsPublytics
EU-operated (FR)YesNot listed
Server-side TMSYesNot listed
Real-time CDPYesNot listed
Integrated CMPYesNot listed
Adloop attributionYesNot listed
SaaS onlyYesNot listed
Cookieless trackingNot listedYes
No default samplingNot listedYes
Multi-site NetworkNot listedYes
EU-hosted (EuroVPS/Hetzner)Not listedYes
Public B2B DPANot listedYes
Publisher-focused UXNot listedYes

Commanders Act

  • Enterprise Tag Manager with server-side destinations and CAPIs

    Collect first-party and omnichannel events, transform/enrich without code, and deliver to 1,200+ destinations including 100+ server-side paths and major CAPIs (Google, Meta, Amazon, TikTok, Snapchat per vendor). GTM-ready server-side integration supports hybrid Google Tag Manager workflows.

  • Integrated consent and privacy governance tooling

    Native CMP/consent features (TrustCommander lineage) with Google Consent Mode support and Google CMP partner listing. Privacy monitoring, data-quality dashboards, filters before partner delivery, and cookie-related scanners help marketing ops control what leaves the property.

  • Real-time CDP: identity resolution, segments, activation

    Unify profiles across sources (including CRM enrichment), build no-code audiences with many filter criteria, push dynamic segment updates into ad and personalization destinations, and support cross-device experience consistency under consent rules.

  • Adloop media optimization and data-driven attribution

    After the 2023 Adloop acquisition, centralize campaign data via API connectors, run behaviour-based attribution as an independent measurement layer versus ad-platform KPIs, set spend/anomaly alerts, and use AI-assisted ad-level recommendations.

  • Operational QA for tagging teams

    No-code QA tooling (live event inspector, debug mode), continuous data-quality monitoring, and role/IP-restricted platform access claims reduce reliance on pure developer debugging when tags and server-side pipelines change.

Publytics

  • Unsampled real-time and daily publisher metrics

    Dashboard and Real-time views show active users (including last-minute and 30-minute windows), top pages, sources, social referrals, and day trends—with minute-level trend comparison documented for real-time. Vendor states no default data sampling, so reports reflect full counted client-side traffic rather than GA-style estimates on large properties.

  • Multi-site Network mode for content portfolios

    Business and Enterprise plans can group properties into Networks (plan caps apply: e.g. up to three Networks on Business, unlimited on Enterprise). Network views mirror site dashboards with split-by-site filters, combined real-time tables, and PDF/CSV export across the portfolio—built for multi-brand publishers rather than single blogs.

  • Cookieless measurement with daily-rotating visitor hash

    Tracking avoids cookies and permanent device IDs. Per the DPA, IP and User-Agent are used only to derive a daily salted hash for unique visitors, then discarded; metrics stay aggregated (URL, referrer, browser/OS, device, country). Designed so many sites can skip consent banners for analytics alone—confirm with counsel for your jurisdictions and any custom IDs you add.

  • Historical import, custom events/dimensions, and API

    Import paths cover GA4 and other tools (Plausible/Fathom mentioned) with support-assisted finalization. Custom events, dimensions, and metrics scale by plan; REST API uses Sanctum Bearer tokens scoped to subscribed sites. Fits teams rebuilding GA-era reporting without rebuilding infrastructure.

  • AI referral traffic reporting

    Dedicated documentation for traffic referred from AI systems (ChatGPT, Gemini, Claude, Perplexity, Copilot, Mistral, Google AI Overviews, Deepseek, and others). Useful for publishers optimizing for answer-engine and AI-overview discovery alongside classic SEO sources.

Assurance & compliance: Commanders Act vs Publytics
Assurance & complianceLogo: Commanders ActCommanders ActLogo: PublyticsPublytics
Independent security / no-logs audit
Not applicable

Not a no-logs VPN/analytics product; marketing data platform processes customer event/profile data by design.

Not found

Searched official site; no public third-party security or no-logs audit PDF found. DPA describes hashing and non-retention of raw IP/UA.

Independent security / pentest program
Vendor claimed

Security product sheet claims external pentests (black/grey box) every six months and customer audit rights; no public audit PDF reviewed.

Not listed
ISO 27001
Partial

Security sheet attributes ISO 27001 (and related) compliance to the hosting provider in France; not verified as Commanders Act's own current certificate.

Not found

No Publytics product certificate found. Host EuroVPS markets ISO certifications; that is infrastructure provider scope, not Publytics certification.

SOC 2 / SOC 3
Partial

Security sheet states hosting provider complies with SOC Type 1 and 2; not verified as vendor-owned SOC 2 report.

Not found

No public SOC 2/3 report found on official Publytics pages.

GDPR / EU data protection
Vendor claimed

French controller/processor entity; public privacy policy, named DPO, EU storage claim for site data, integrated consent tooling. Customer DPA terms not fully public on marketing pages.

Vendor claimed

Italian controller/processor entity; cookieless design; public Art. 28 DPA; EU hosting named. Not legal advice.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but Cloudflare CDN on public app/platform hostnames and incomplete public subprocessor list for customer data path. Not legal advice.

Partial

EU entity, no known US parent; analytics hosts EuroVPS + Hetzner in EU with DPA no third-country transfer for service data. Account billing via Stripe (US company). Not a vendor 'safe' claim—EuropeanStack assessment only.

Data processing agreement (B2B)
Unknown

Website privacy policy covers visitor/site processing; standard B2B DPA / Art. 28 package not located as a public self-serve download—request in procurement.

Vendor claimed

Full public DPA at https://publytics.net/dpa with Annex B subprocessors and Annex C security/transfer instructions.

EU AI Act
Not applicable

Includes AI-assisted ad recommendations; not assessed here as a high-risk AI system product category.

Not applicable

Web analytics product; AI-referral reporting is measurement of referrers, not an AI system product.

Considerations & known limitations: Commanders Act vs Publytics
Considerations & known limitationsLogo: Commanders ActCommanders ActLogo: PublyticsPublytics
Limited public subprocessor inventory
Medium

Marketing site does not publish a clear list of subprocessors for customer event/CDP data. Cloudflare is observable on public hostnames; backend host is described generically as a French data center. Request written subprocessors, regions, and SCCs before relying on 'EU-only' narratives.

Not listed
ISO/SOC claims tied to hosting provider
Medium

Security sheet language credits the data-center provider for ISO 27001 and SOC Type 1/2. Do not treat footer logos as proof of Commanders Act's own certifications without certificate IDs.

Not listed
Enterprise SaaS scope and switching cost
Medium

PlatformX spans TMS, CMP, CDP, and media optimization. Implementation (server-side migration, consent redesign, CAPI mapping) is non-trivial; not a drop-in free GTM replacement for all teams.

Not listed
No self-host option
Low

Fully managed SaaS only. Organizations with hard on-prem or open-source requirements need different tools.

Not listed
SaaS-only (no self-host)Not listed
Medium

All measurement depends on Publytics cloud availability and vendor roadmap. Teams with residency or air-gap requirements need Matomo/Plausible CE-style self-host alternatives.

No public independent security auditNot listed
Medium

Hashing and non-retention claims are first-party (DPA/docs). No public third-party audit was found—enterprise security reviews will need questionnaires, DPA audit rights, and possibly NDA materials.

Feature depth tied to pageview tiersNot listed
Low

Networks, API rate limits, custom dimensions/metrics, retention years, and time granularity differ by Lite/Business/Enterprise. Validate limits against portfolio size before migration.

US payment processor on account pathNot listed
Low

Stripe processes payments (US company). Separate from DPA Annex B analytics hosts, but relevant if procurement treats all vendor SaaS touchpoints as in-scope for CLOUD Act diligence.

Customer-injected identifiers can re-identifyNot listed
Medium

DPA warns controllers not to inject unique user IDs that re-identify visitors via the script. Misconfiguration can undermine the cookieless privacy model.

Fit

Commanders Act

Best fit when

  • Marketing ops teams replacing or complementing GTM with governed server-side destinations and CAPIs
  • Enterprises that want tag management, consent, CDP segments, and activation under one French SaaS contract
  • Performance teams needing independent multi-channel attribution and campaign data hub after Adloop
  • Organizations prioritizing an EU legal entity and EU data-center marketing claims for MarTech collection tooling
  • Teams that need no-code QA, data-quality monitoring, and consent-aware partner delivery controls

Poor fit when

  • Solo sites or SMBs that only need free/client-side GTM or lightweight privacy page analytics
  • Buyers requiring open-source or fully self-hosted tag/CDP infrastructure
  • Procurement that must prove vendor-owned ISO 27001/SOC 2 from public certificate registries before RFP (provider-level claims need clarification)
  • Use cases limited to pure product analytics without marketing destination/CAPI complexity

Consider instead when

  • When: You mainly need EU web analytics with lighter tag/consent tooling, not a full CDP + media stack

    Consider: etracker

    German analytics + tag/consent oriented stack; smaller surface than PlatformX

  • When: You want Swiss cookieless analytics plus server-side tagging/activation without a French enterprise CDP suite

    Consider: fusedeck

    Narrower product; different jurisdiction (CH)

  • When: You need free client-side tagging and Google-native defaults, and can accept US hyperscaler jurisdiction

    Consider: Google Tag Manager (and Google marketing stack)

    Often retained in hybrid with Commanders Act server-side

  • When: Self-host open analytics is a hard requirement

    Consider: Matomo (self-host or EU Matomo hosting peers such as Friendly Analytics)

    Not a CDP/CAPI replacement

Publytics

Best fit when

  • Content publishers and media sites that want GA3-style reporting without cookies or default sampling
  • Multi-brand portfolios that need Network dashboards, split-by-site filters, and shared exports
  • Teams migrating historical series from GA4 (or Plausible/Fathom) into a privacy-oriented SaaS
  • EU-oriented controllers who want Italian legal entity, published DPA, and EU infrastructure subprocessors named in annexes
  • Editorial/SEO leads who need real-time active users, sources, and AI-referral reporting without operating self-hosted analytics

Poor fit when

  • Organizations that require self-hosted or open-source analytics only
  • Product/growth teams that need GA4/Adobe-class event modeling, experiment stacks, and ads ecosystem integrations
  • Buyers that need verified product ISO 27001/SOC 2 certificates before shortlist (none found for Publytics itself)
  • Very simple single-site blogs that only need minimal privacy metrics—lighter tools may be enough

Consider instead when

  • When: You want open-core privacy analytics with optional self-host

    Consider: Plausible Analytics

    Simpler surface; stronger self-host/open-core path than Publytics SaaS-only model

  • When: You must run analytics on your own infrastructure

    Consider: Matomo (self-host) or Plausible Community Edition

    Publytics is managed cloud only—no official on-prem product

  • When: You need deep product analytics and marketing stack integration

    Consider: Google Analytics or Adobe Analytics

    Trade privacy/EU-hosting priorities for ecosystem breadth

Open questions for due diligence

Commanders Act

  • Will Fjord Technologies provide a current Art. 28 DPA, subprocessor list, and data-flow diagram for PlatformX customer event data?
  • Which legal entity and cloud region process production customer data today, and are backups/DR in the same jurisdiction?
  • Does Commanders Act hold its own ISO 27001 or SOC 2 (certificate number/date), or only rely on hosting-provider attestations?
  • What is the minimum commercial package if the buyer only needs TMS + CMP versus full CDP + Adloop?
  • How are US ad-platform CAPIs and optional Google/Meta connections handled for transfer impact assessments?

Publytics

  • Will Publytics provide completed security questionnaire, pen-test summary, or ISO evidence under NDA for enterprise procurement?
  • Exact current pageview tier limits, Network caps, and retention for the sites you will migrate?
  • Is GA4 historical import complete for your property structure (events, custom dimensions) or only core traffic series?
  • How are subprocessors for account services (Stripe, Brevo) contractually covered relative to the analytics DPA annex?
  • Any planned US or non-EU hosting options that would change the current EU-only transfer instruction?