Commanders Act vs Swetrix

Compare Commanders Act and Swetrix on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: Commanders Act

Commanders Act

France· Web Analytics

Needs review

Shortlist when you need an EU-headquartered enterprise stack combining server-side tag management, consent, real-time CDP activation, and independent media attribution (Adloop). Skip when you only need lightweight privacy analytics or open-source self-hosting—consider etracker or fusedeck for narrower EU measurement/tagging scopes, or Matomo-class tools for self-host analytics.

EU-operated (FR)Server-side TMSReal-time CDPIntegrated CMPAdloop attributionSaaS only
Logo: Swetrix

Swetrix

United Kingdom· Web Analytics

Needs review

Shortlist Swetrix when you want cookieless traffic plus product-oriented tools (funnels, RUM, errors, optional Cloud replays) under a UK company with Hetzner DE hosting and AGPLv3 self-host CE. Skip when you need public ISO/SOC packs, zero US-group subprocessors, multi-year cookie retention cohorts, or free forever hosted analytics—consider Plausible Analytics or Simple Analytics for minimal traffic-only privacy analytics, or Matomo for heavyweight self-host control.

Cookieless trackingHetzner DE hostingOpen source (AGPLv3)Self-host CEFunnels + errors + RUMPublic DPA
Commanders Act vs Swetrix: Snapshot
FeatureLogo: Commanders ActCommanders ActLogo: SwetrixSwetrix
Country of originFranceUnited Kingdom
CategoryWeb AnalyticsWeb Analytics
Open sourceNoYes
Self-hostedNoYes
HeadquartersFranceUnited Kingdom
Legal entityFjord Technologies SAS (trading name Commanders Act), SIREN 527 730 782, ParisSwetrix Ltd (SC797389), Edinburgh, Scotland
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor: EU/France data centers for platform hosting; privacy policy: site data stored in EU. Public DNS: app/platform behind Cloudflare CDN. Hosting provider certs (ISO 27001, SOC 1/2, etc.) claimed on Security product sheet. Full customer-data subprocessor list not published on marketing site.Cloud analytics data: Hetzner Online GmbH (Germany) per DPA/Data Policy. End User error monitoring sub-processor: Sentry / Functional Software Inc. (United States). Customer-side Privacy Policy list also includes Paddle (UK payments), Fastmail (Australia business email), AWS (US transactional/marketing email), OpenRouter (US optional AI chat). No known US parent.
Summary

French PlatformX MarTech suite from Fjord Technologies: enterprise server-side tag management, integrated consent, real-time CDP, and Adloop media attribution for multi-channel marketing teams.

Cookieless, privacy-first web analytics from a UK company: traffic, funnels, errors, and performance on Hetzner in Germany, with AGPLv3 self-host Community Edition and optional Cloud session replays.

Tags
At a glance: Commanders Act vs Swetrix
At a glanceLogo: Commanders ActCommanders ActLogo: SwetrixSwetrix
HQParis, France (Fjord Technologies SAS)Edinburgh, United Kingdom
SIREN527 730 782Not listed
Founded2010 (as TagCommander / Fjord Technologies)Not listed
DeploymentManaged SaaS (not self-hosted)Not listed
Core suiteTMS + CMP + CDP + AdloopNot listed
Commercial modelDemo / enterprise quote (no public list price)Event-volume Cloud subscription; free self-host CE; timed trial
Legal entityNot listedSwetrix Ltd (SC797389)
Governing lawNot listedScotland (Terms)
Primary hostingNot listedHetzner Online GmbH, Germany
LicenseNot listedAGPLv3 (Community Edition)
Open sourceNot listedYes — github.com/Swetrix/swetrix
Key capabilities: Commanders Act vs Swetrix
Key capabilitiesLogo: Commanders ActCommanders ActLogo: SwetrixSwetrix
EU-operated (FR)YesNot listed
Server-side TMSYesNot listed
Real-time CDPYesNot listed
Integrated CMPYesNot listed
Adloop attributionYesNot listed
SaaS onlyYesNot listed
Cookieless trackingNot listedYes
Hetzner DE hostingNot listedYes
Open source (AGPLv3)Not listedYes
Self-host CENot listedYes
Funnels + errors + RUMNot listedYes
Public DPANot listedYes

Commanders Act

  • Enterprise Tag Manager with server-side destinations and CAPIs

    Collect first-party and omnichannel events, transform/enrich without code, and deliver to 1,200+ destinations including 100+ server-side paths and major CAPIs (Google, Meta, Amazon, TikTok, Snapchat per vendor). GTM-ready server-side integration supports hybrid Google Tag Manager workflows.

  • Integrated consent and privacy governance tooling

    Native CMP/consent features (TrustCommander lineage) with Google Consent Mode support and Google CMP partner listing. Privacy monitoring, data-quality dashboards, filters before partner delivery, and cookie-related scanners help marketing ops control what leaves the property.

  • Real-time CDP: identity resolution, segments, activation

    Unify profiles across sources (including CRM enrichment), build no-code audiences with many filter criteria, push dynamic segment updates into ad and personalization destinations, and support cross-device experience consistency under consent rules.

  • Adloop media optimization and data-driven attribution

    After the 2023 Adloop acquisition, centralize campaign data via API connectors, run behaviour-based attribution as an independent measurement layer versus ad-platform KPIs, set spend/anomaly alerts, and use AI-assisted ad-level recommendations.

  • Operational QA for tagging teams

    No-code QA tooling (live event inspector, debug mode), continuous data-quality monitoring, and role/IP-restricted platform access claims reduce reliance on pure developer debugging when tags and server-side pipelines change.

Swetrix

  • Cookieless traffic analytics with hashed sessions

    Lightweight script captures pageviews, referrers/UTMs, devices, and city-level geo without cookies or client-side storage. Per the Data Policy, IP and User-Agent are hashed in memory with a daily rotating salt; only a random session id is stored—so you get sessions without long-term cross-day visitor retention.

  • Funnels, custom events, and goals

    Instrument signups, purchases, and other conversions as custom events; build multi-step funnels and goals in the dashboard. Useful for product and growth teams who need drop-off analysis without bolting on a second product-analytics SaaS.

  • Real-user performance and client error tracking

    Records Web Performance API timings (TTFB, DNS, TLS, render, full page load) and optional JavaScript errors with stack/context by page and browser. Bridges marketing traffic views with engineering signals that pure pageview tools omit.

  • Opt-in Cloud session replays with privacy modes

    Cloud projects can call startSessionReplay() to record DOM and interactions; default modes mask text/inputs. Replays are not created by ordinary pageviews—customers must enable them and own consent, masking, and page exclusions. Cloud-only versus Community Edition.

  • AGPLv3 open source with Docker self-host CE

    Core platform is public on GitHub under GNU AGPLv3; Community Edition deploys via official Docker docs with MySQL, ClickHouse, and Redis. CE includes core analytics, events, sessions, funnels, performance, and errors—but not all Cloud extras (replays, some alerts/org/AI features).

  • Alerts, API, GA import, and team access

    Configure alerts to email, Slack, Telegram, Discord, webhooks, or push; pull or push data via the API; import GA4 history; invite organisations with roles or share password-protected/public dashboards. Fits agencies and multi-site operators who outgrow single-user tools.

Assurance & compliance: Commanders Act vs Swetrix
Assurance & complianceLogo: Commanders ActCommanders ActLogo: SwetrixSwetrix
Independent security / no-logs audit
Not applicable

Not a no-logs VPN/analytics product; marketing data platform processes customer event/profile data by design.

Not found

Searched marketing, DPA, privacy, and data policy; no public independent audit PDF located. Open-source code is available for review.

Independent security / pentest program
Vendor claimed

Security product sheet claims external pentests (black/grey box) every six months and customer audit rights; no public audit PDF reviewed.

Not listed
ISO 27001
Partial

Security sheet attributes ISO 27001 (and related) compliance to the hosting provider in France; not verified as Commanders Act's own current certificate.

Not found

No public ISO 27001 certification claim found on primary pages.

SOC 2 / SOC 3
Partial

Security sheet states hosting provider complies with SOC Type 1 and 2; not verified as vendor-owned SOC 2 report.

Not found

No public SOC 2/3 report found.

GDPR / EU data protection
Vendor claimed

French controller/processor entity; public privacy policy, named DPO, EU storage claim for site data, integrated consent tooling. Customer DPA terms not fully public on marketing pages.

Vendor claimed

UK company; public GDPR/PECR discussion in Data Policy; cookieless design with non-stored IPs for standard analytics; Hetzner DE hosting; public DPA. Optional replays may be personal data depending on configuration—customer assesses legal basis.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but Cloudflare CDN on public app/platform hostnames and incomplete public subprocessor list for customer data path. Not legal advice.

Partial

No known US parent; primary analytics on Hetzner DE. Material exception: Sentry (US) processes End User error data per DPA; Privacy Policy also lists AWS and OpenRouter (US) for customer email/AI. Indicative medium exposure—not a clean bill. Not legal advice.

Data processing agreement (B2B)
Unknown

Website privacy policy covers visitor/site processing; standard B2B DPA / Art. 28 package not located as a public self-serve download—request in procurement.

Vendor claimed

Public DPA at swetrix.com/dpa incorporated by Terms; acceptance by use of Service; signed copy on request.

EU AI Act
Not applicable

Includes AI-assisted ad recommendations; not assessed here as a high-risk AI system product category.

Not applicable

Core product is web analytics, not an AI system. Optional Ask AI / OpenRouter is ancillary; confirm if your deployment enables it.

Considerations & known limitations: Commanders Act vs Swetrix
Considerations & known limitationsLogo: Commanders ActCommanders ActLogo: SwetrixSwetrix
Limited public subprocessor inventory
Medium

Marketing site does not publish a clear list of subprocessors for customer event/CDP data. Cloudflare is observable on public hostnames; backend host is described generically as a French data center. Request written subprocessors, regions, and SCCs before relying on 'EU-only' narratives.

Not listed
ISO/SOC claims tied to hosting provider
Medium

Security sheet language credits the data-center provider for ISO 27001 and SOC Type 1/2. Do not treat footer logos as proof of Commanders Act's own certifications without certificate IDs.

Not listed
Enterprise SaaS scope and switching cost
Medium

PlatformX spans TMS, CMP, CDP, and media optimization. Implementation (server-side migration, consent redesign, CAPI mapping) is non-trivial; not a drop-in free GTM replacement for all teams.

Not listed
No self-host option
Low

Fully managed SaaS only. Organizations with hard on-prem or open-source requirements need different tools.

Not listed
US-group subprocessors (Sentry, AWS, OpenRouter)Not listed
Medium

Primary analytics hosting is Hetzner DE, but Sentry (US) is an End User error-tracking sub-processor on the DPA, and AWS/OpenRouter appear for customer email/AI. Orgs with strict no-US-cloud rules need explicit acceptance or self-host CE to avoid those paths.

Session replay is opt-in and controller-ownedNot listed
Medium

Cloud replays can capture DOM and inputs unless masked. Customers must enable startSessionReplay(), configure privacy modes/exclusions, and provide notices/consent where required—misconfiguration can reintroduce personal data risk that standard cookieless pageviews avoid.

No public ISO/SOC or third-party auditNot listed
Medium

Assurance relies on first-party policies, Hetzner infrastructure claims, and open source. Enterprise questionnaires that hard-gate on certs will stall until materials are provided under NDA or produced.

Cloud vs Community Edition feature gapNot listed
Low

Self-host CE is free and covers core analytics, but replays and several Cloud growth/ops features are limited or Cloud-only. Budget and feature planning must not assume feature parity.

Daily salt rotation limits retention metricsNot listed
Low

Cookieless design deliberately prevents classic multi-day visitor retention. Teams that need that metric class need another product or consented identity.

Fit

Commanders Act

Best fit when

  • Marketing ops teams replacing or complementing GTM with governed server-side destinations and CAPIs
  • Enterprises that want tag management, consent, CDP segments, and activation under one French SaaS contract
  • Performance teams needing independent multi-channel attribution and campaign data hub after Adloop
  • Organizations prioritizing an EU legal entity and EU data-center marketing claims for MarTech collection tooling
  • Teams that need no-code QA, data-quality monitoring, and consent-aware partner delivery controls

Poor fit when

  • Solo sites or SMBs that only need free/client-side GTM or lightweight privacy page analytics
  • Buyers requiring open-source or fully self-hosted tag/CDP infrastructure
  • Procurement that must prove vendor-owned ISO 27001/SOC 2 from public certificate registries before RFP (provider-level claims need clarification)
  • Use cases limited to pure product analytics without marketing destination/CAPI complexity

Consider instead when

  • When: You mainly need EU web analytics with lighter tag/consent tooling, not a full CDP + media stack

    Consider: etracker

    German analytics + tag/consent oriented stack; smaller surface than PlatformX

  • When: You want Swiss cookieless analytics plus server-side tagging/activation without a French enterprise CDP suite

    Consider: fusedeck

    Narrower product; different jurisdiction (CH)

  • When: You need free client-side tagging and Google-native defaults, and can accept US hyperscaler jurisdiction

    Consider: Google Tag Manager (and Google marketing stack)

    Often retained in hybrid with Commanders Act server-side

  • When: Self-host open analytics is a hard requirement

    Consider: Matomo (self-host or EU Matomo hosting peers such as Friendly Analytics)

    Not a CDP/CAPI replacement

Swetrix

Best fit when

  • SMEs, agencies, and product teams replacing GA4 who need cookieless traffic stats without a cookie banner driven only by analytics
  • Engineering-minded buyers who want error tracking and real-user performance in the same privacy-first dashboard as pageviews
  • Teams that may enable Cloud session replays later but can treat them as explicit opt-in with their own legal basis
  • Operators willing to run Docker Community Edition (MySQL/ClickHouse/Redis) when Cloud commercial terms or feature limits do not fit
  • Buyers who need a public B2B DPA, API access, GA4 import, and multi-channel alerts under a UK legal entity

Poor fit when

  • Enterprises that require published ISO 27001 / SOC 2 certificates or independent audit PDFs before shortlist
  • Policies that forbid any US-group subprocessors (Sentry is listed for End User error data; AWS/OpenRouter appear for customer services)
  • Use cases that depend on long-term cookie-based retention or cross-device identity graphs
  • Buyers who only want free hosted analytics with no paid Cloud tier and no self-host operations burden
  • Sites that will run session replays on sensitive flows without capacity to configure masking, exclusions, and consent

Consider instead when

  • When: You only need minimal cookieless pageviews/referrers with the smallest possible product surface

    Consider: Plausible Analytics or Simple Analytics

    Swetrix adds funnels, errors, RUM, and Cloud replays; peers stay closer to pure traffic analytics.

  • When: You need deep on-prem control, plugins, and mature enterprise self-host packaging

    Consider: Matomo (self-host or managed EU hosts such as Matomo by Stackhero)

    Heavier ops and optional cookies; stronger fit for large controlled deployments.

  • When: You must stay inside Google advertising measurement and free GA4 ecosystem tooling

    Consider: Google Analytics

    Trade privacy, consent, and transfer complexity for ads integration and zero software fee.

Open questions for due diligence

Commanders Act

  • Will Fjord Technologies provide a current Art. 28 DPA, subprocessor list, and data-flow diagram for PlatformX customer event data?
  • Which legal entity and cloud region process production customer data today, and are backups/DR in the same jurisdiction?
  • Does Commanders Act hold its own ISO 27001 or SOC 2 (certificate number/date), or only rely on hosting-provider attestations?
  • What is the minimum commercial package if the buyer only needs TMS + CMP versus full CDP + Adloop?
  • How are US ad-platform CAPIs and optional Google/Meta connections handled for transfer impact assessments?

Swetrix

  • Can Enterprise contracts exclude or replace Sentry (and other US-group subprocessors) for End User data paths?
  • Are ISO 27001, SOC 2, or pen-test summaries available under NDA?
  • What is the exact backup/DR location topology beyond “secure backups” wording on the DPA?
  • Which Cloud-only features remain permanently out of CE versus delayed open-source release?
  • For session replay at your traffic volumes, what retention defaults and export/delete SLAs apply on your plan?