Commanders Act vs SEAL Metrics

Compare Commanders Act and SEAL Metrics on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Adobe Analytics, Google Analytics

Logo: Commanders Act

Commanders Act

France· Web Analytics

Needs review

Shortlist when you need an EU-headquartered enterprise stack combining server-side tag management, consent, real-time CDP activation, and independent media attribution (Adloop). Skip when you only need lightweight privacy analytics or open-source self-hosting—consider etracker or fusedeck for narrower EU measurement/tagging scopes, or Matomo-class tools for self-host analytics.

EU-operated (FR)Server-side TMSReal-time CDPIntegrated CMPAdloop attributionSaaS only
Logo: SEAL Metrics

SEAL Metrics

Spain· Web Analytics

Needs review

Shortlist when European eCommerce or hospitality teams need cookieless full-traffic capture and last-click ROAS they can align with finance—without GA4 Consent Mode as the measurement backbone. Skip when you need self-host or open source, session replay and product analytics depth, or a certified ISO/SOC package today—consider Plausible, Simple Analytics, Pirsch, or Matomo-based hosts instead.

Cookieless first-party pixelEU-hosted (Dublin)Revenue / ROAS focusReal-time dashboardsDPA includedSaaS only
Commanders Act vs SEAL Metrics: Snapshot
FeatureLogo: Commanders ActCommanders ActLogo: SEAL MetricsSEAL Metrics
Country of originFranceSpain
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersFranceSpain
Legal entityFjord Technologies SAS (trading name Commanders Act), SIREN 527 730 782, ParisSealMetrics (Spain; exact registered company name not found on public imprint)
Governing lawNot listedSpain (Terms of Service; courts of Barcelona)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor: EU/France data centers for platform hosting; privacy policy: site data stored in EU. Public DNS: app/platform behind Cloudflare CDN. Hosting provider certs (ISO 27001, SOC 1/2, etc.) claimed on Security product sheet. Full customer-data subprocessor list not published on marketing site.Customer analytics app, DB, and backups: Dublin, Ireland (EU data center, provider not named publicly). Subprocessor: Cloudflare for CDN/DDoS on encrypted transit at EU edge locations; vendor states no analytics data at rest on Cloudflare and no US cloud storage of customer analytics.
Summary

French PlatformX MarTech suite from Fjord Technologies: enterprise server-side tag management, integrated consent, real-time CDP, and Adloop media attribution for multi-channel marketing teams.

Spanish cookieless web analytics for European eCommerce: first-party capture, Dublin EU storage, last-click revenue and ROAS without consent-dependent tags.

Tags
At a glance: Commanders Act vs SEAL Metrics
At a glanceLogo: Commanders ActCommanders ActLogo: SEAL MetricsSEAL Metrics
HQParis, France (Fjord Technologies SAS)Spain (Spanish law; Barcelona courts per Terms)
SIREN527 730 782Not listed
Founded2010 (as TagCommander / Fjord Technologies)2020 (vendor how-it-works page)
DeploymentManaged SaaS (not self-hosted)Not listed
Core suiteTMS + CMP + CDP + AdloopNot listed
Commercial modelDemo / enterprise quote (no public list price)Not listed
HostingNot listedDublin, Ireland — EU data center; Cloudflare edge transit
ModelNot listedSaaS; event-volume plans; free agentic tier + trial
Open sourceNot listedNo
Self-hostNot listedNo
Key capabilities: Commanders Act vs SEAL Metrics
Key capabilitiesLogo: Commanders ActCommanders ActLogo: SEAL MetricsSEAL Metrics
EU-operated (FR)YesNot listed
Server-side TMSYesNot listed
Real-time CDPYesNot listed
Integrated CMPYesNot listed
Adloop attributionYesNot listed
SaaS onlyYesYes
Cookieless first-party pixelNot listedYes
EU-hosted (Dublin)Not listedYes
Revenue / ROAS focusNot listedYes
Real-time dashboardsNot listedYes
DPA includedNot listedYes

Commanders Act

  • Enterprise Tag Manager with server-side destinations and CAPIs

    Collect first-party and omnichannel events, transform/enrich without code, and deliver to 1,200+ destinations including 100+ server-side paths and major CAPIs (Google, Meta, Amazon, TikTok, Snapchat per vendor). GTM-ready server-side integration supports hybrid Google Tag Manager workflows.

  • Integrated consent and privacy governance tooling

    Native CMP/consent features (TrustCommander lineage) with Google Consent Mode support and Google CMP partner listing. Privacy monitoring, data-quality dashboards, filters before partner delivery, and cookie-related scanners help marketing ops control what leaves the property.

  • Real-time CDP: identity resolution, segments, activation

    Unify profiles across sources (including CRM enrichment), build no-code audiences with many filter criteria, push dynamic segment updates into ad and personalization destinations, and support cross-device experience consistency under consent rules.

  • Adloop media optimization and data-driven attribution

    After the 2023 Adloop acquisition, centralize campaign data via API connectors, run behaviour-based attribution as an independent measurement layer versus ad-platform KPIs, set spend/anomaly alerts, and use AI-assisted ad-level recommendations.

  • Operational QA for tagging teams

    No-code QA tooling (live event inspector, debug mode), continuous data-quality monitoring, and role/IP-restricted platform access claims reduce reliance on pure developer debugging when tags and server-side pipelines change.

SEAL Metrics

  • 846-byte first-party cookieless pixel

    Install a tiny first-party script on your domain that logs pageviews without cookies, localStorage, or fingerprinting. Designed so ad blockers that target third-party analytics domains hit less often. Benefit: fuller traffic capture for teams stuck with consent-gated tags; trade-off: aggregate and channel metrics rather than person-level journey stitching.

  • Last-click revenue and ROAS attribution

    Attributes conversions and revenue to channels, campaigns, and landing pages with last-click models the vendor positions as CRM-alignable. Built for eCommerce and hospitality media decisions—not generic pageview vanity charts. Limits: not a full multi-touch marketing mix model out of the box; validate against your CRM as the case studies do.

  • Real-time promo and campaign dashboards

    Live views of revenue, channels, campaigns, and products during Promo Days so media teams can reallocate spend the same day. Suited to peak-load retail calendars. Constraint: value depends on tagging microconversions and keeping UTM hygiene; not a substitute for warehouse-grade BI alone.

  • LENS private AI on full capture

    Optional LENS layer answers growth, risk, and wasted-spend questions in plain language against SealMetrics data (vendor states exclusive private AI on Enterprise tiers). Useful when analysts are scarce. Caveat: AI outputs are assistive—confirm high-stakes budget cuts against raw reports and offline finance data.

  • MCP and AI-assisted provisioning

    Hosted MCP endpoint and docs let teams spin up accounts, pixels, and reports from AI coding assistants instead of a pure UI-only onboarding path. Speeds evaluation for engineering-heavy stacks. Still SaaS-only—there is no self-hosted SEAL Metrics server to run in your VPC.

  • EU Dublin storage with exports

    Vendor documents processing and backups in Dublin, Ireland, with TLS 1.3, AES-256 at rest, and roughly 24-month analytics retention. API and BigQuery-style exports support dual-running with GA4. Hosting operator is described generically as an EU data center; Cloudflare sits on the transit path only.

Assurance & compliance: Commanders Act vs SEAL Metrics
Assurance & complianceLogo: Commanders ActCommanders ActLogo: SEAL MetricsSEAL Metrics
Independent security / no-logs audit
Not applicable

Not a no-logs VPN/analytics product; marketing data platform processes customer event/profile data by design.

Not found

Vendor mentions regular security audits and independent legal audits; no public third-party audit PDF found on site/docs.

Independent security / pentest program
Vendor claimed

Security product sheet claims external pentests (black/grey box) every six months and customer audit rights; no public audit PDF reviewed.

Not listed
ISO 27001
Partial

Security sheet attributes ISO 27001 (and related) compliance to the hosting provider in France; not verified as Commanders Act's own current certificate.

Not found

Data location docs list ISO 27001 as planned, not certified.

SOC 2 / SOC 3
Partial

Security sheet states hosting provider complies with SOC Type 1 and 2; not verified as vendor-owned SOC 2 report.

Partial

Vendor docs list SOC 2 Type II as in progress — not a completed public report.

GDPR / EU data protection
Vendor claimed

French controller/processor entity; public privacy policy, named DPO, EU storage claim for site data, integrated consent tooling. Customer DPA terms not fully public on marketing pages.

Vendor claimed

Spanish entity; cookieless architecture; EEA processing claims; DPA published. Legal conclusion remains for counsel.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but Cloudflare CDN on public app/platform hostnames and incomplete public subprocessor list for customer data path. Not legal advice.

Partial

EU entity / no known US parent; analytics at rest in Dublin. Cloudflare (US group) processes TLS transit at EU edge. Not legal advice.

Data processing agreement (B2B)
Unknown

Website privacy policy covers visitor/site processing; standard B2B DPA / Art. 28 package not located as a public self-serve download—request in procurement.

Vendor claimed

Public DPA page; vendor states standard DPA with every plan, custom on Enterprise.

EU AI Act
Not applicable

Includes AI-assisted ad recommendations; not assessed here as a high-risk AI system product category.

Not applicable

Core product is measurement analytics; optional LENS private AI is a feature—confirm classification if heavily relied on for automated decisions.

Considerations & known limitations: Commanders Act vs SEAL Metrics
Considerations & known limitationsLogo: Commanders ActCommanders ActLogo: SEAL MetricsSEAL Metrics
Limited public subprocessor inventory
Medium

Marketing site does not publish a clear list of subprocessors for customer event/CDP data. Cloudflare is observable on public hostnames; backend host is described generically as a French data center. Request written subprocessors, regions, and SCCs before relying on 'EU-only' narratives.

Not listed
ISO/SOC claims tied to hosting provider
Medium

Security sheet language credits the data-center provider for ISO 27001 and SOC Type 1/2. Do not treat footer logos as proof of Commanders Act's own certifications without certificate IDs.

Not listed
Enterprise SaaS scope and switching cost
Medium

PlatformX spans TMS, CMP, CDP, and media optimization. Implementation (server-side migration, consent redesign, CAPI mapping) is non-trivial; not a drop-in free GTM replacement for all teams.

Not listed
No self-host option
Low

Fully managed SaaS only. Organizations with hard on-prem or open-source requirements need different tools.

Not listed
US-group edge subprocessor (Cloudflare)Not listed
Medium

Even with Dublin storage, Cloudflare sits on encrypted traffic. Procurement that bans any US-group vendor in the path will need a written exception or alternative edge posture.

ISO/SOC not fully certified yetNot listed
Medium

SOC 2 in progress and ISO planned per vendor docs. Enterprise security questionnaires may block until reports are available under NDA.

Consentless claim is architectural, not a warrantyNot listed
Medium

Vendor argues no personal data / no cookies so analytics need no banner. Other scripts on the same site and national guidance still matter—get DPO sign-off.

SaaS-only, proprietary pipelineNot listed
Low

No self-host path. Mitigate with API/BigQuery export and dual-running with GA4 during evaluation.

Hosting operator not namedNot listed
Low

Docs say EU data center in Dublin without naming the cloud or colo operator. Ask for the concrete provider in the TPSR pack.

Fit

Commanders Act

Best fit when

  • Marketing ops teams replacing or complementing GTM with governed server-side destinations and CAPIs
  • Enterprises that want tag management, consent, CDP segments, and activation under one French SaaS contract
  • Performance teams needing independent multi-channel attribution and campaign data hub after Adloop
  • Organizations prioritizing an EU legal entity and EU data-center marketing claims for MarTech collection tooling
  • Teams that need no-code QA, data-quality monitoring, and consent-aware partner delivery controls

Poor fit when

  • Solo sites or SMBs that only need free/client-side GTM or lightweight privacy page analytics
  • Buyers requiring open-source or fully self-hosted tag/CDP infrastructure
  • Procurement that must prove vendor-owned ISO 27001/SOC 2 from public certificate registries before RFP (provider-level claims need clarification)
  • Use cases limited to pure product analytics without marketing destination/CAPI complexity

Consider instead when

  • When: You mainly need EU web analytics with lighter tag/consent tooling, not a full CDP + media stack

    Consider: etracker

    German analytics + tag/consent oriented stack; smaller surface than PlatformX

  • When: You want Swiss cookieless analytics plus server-side tagging/activation without a French enterprise CDP suite

    Consider: fusedeck

    Narrower product; different jurisdiction (CH)

  • When: You need free client-side tagging and Google-native defaults, and can accept US hyperscaler jurisdiction

    Consider: Google Tag Manager (and Google marketing stack)

    Often retained in hybrid with Commanders Act server-side

  • When: Self-host open analytics is a hard requirement

    Consider: Matomo (self-host or EU Matomo hosting peers such as Friendly Analytics)

    Not a CDP/CAPI replacement

SEAL Metrics

Best fit when

  • European eCommerce, DTC, and hospitality brands measuring paid media ROAS against incomplete consent-gated analytics
  • Marketing ops and agencies that need a single channel revenue source of truth finance can challenge less often
  • Teams that want side-by-side GA4 calibration without migrating off Google Ads tooling immediately
  • DPOs and CISOs evaluating analytics that claim no cookies, no fingerprinting, and EEA-only storage of analytics data
  • Stacks that prefer SaaS plus API/BigQuery export over running Matomo themselves

Poor fit when

  • Organizations that require self-hosted or open-source analytics under their own admin control
  • Product teams needing session replay, heatmaps, or deep multi-touch product analytics (Heap/FullStory class)
  • Buyers that will not accept SaaS until ISO 27001 or SOC 2 Type II is fully certified and publicly evidenced
  • Hobby sites and blogs that only need lightweight open-source pageview analytics

Consider instead when

  • When: You need open-source or self-hosted cookieless analytics

    Consider: Plausible Analytics (self-host Community Edition) or Matomo

    SEAL Metrics is SaaS-only with no public source license.

  • When: You want simple privacy-first page analytics without eCommerce ROAS tooling

    Consider: Simple Analytics or Pirsch Analytics

    Lighter EU privacy analytics peers; less paid-media attribution depth.

  • When: You need managed Matomo with Swiss hosting or enterprise on-prem options

    Consider: Friendly Analytics

    Matomo ecosystem plugins and heatmaps vs SealMetrics proprietary ROAS focus.

  • When: You need Google Ads-native reporting and free-tier product analytics breadth

    Consider: Google Analytics 4

    Different sovereignty and consent trade-offs; often kept alongside SealMetrics.

Open questions for due diligence

Commanders Act

  • Will Fjord Technologies provide a current Art. 28 DPA, subprocessor list, and data-flow diagram for PlatformX customer event data?
  • Which legal entity and cloud region process production customer data today, and are backups/DR in the same jurisdiction?
  • Does Commanders Act hold its own ISO 27001 or SOC 2 (certificate number/date), or only rely on hosting-provider attestations?
  • What is the minimum commercial package if the buyer only needs TMS + CMP versus full CDP + Adloop?
  • How are US ad-platform CAPIs and optional Google/Meta connections handled for transfer impact assessments?

SEAL Metrics

  • What is the exact legal entity name (e.g. S.L.) and registered address for contracts?
  • Which Dublin operator hosts app/DB/backups (name on the infrastructure questionnaire)?
  • Current status and availability date of SOC 2 Type II report and ISO 27001 certification?
  • Does any account data, billing, or support channel leave the EEA (email, payments, CRM)?
  • For LENS AI: training data isolation guarantees and EU AI Act role for customer use cases?