| Independent security / no-logs audit | 🔒On request / NDATrust portal lists a pentest report and security whitepaper behind access. Security page claims annual external pentests, monthly scans, and a public bug bounty. No public no-logs audit (wrong category for a behavior recorder). | ⚠️PartialVendor claims third-party penetration/vulnerability tests and offers a Security Kit; no public independent no-logs audit report found for download without request. |
|---|
| ISO 27001 | ⚠️Vendor claimedTrust portal and security page state ISO/IEC 27001 certification (also 27017, 27018). Certificate files require portal access. Not independently verified in a public registry during this draft. | ⚠️Vendor claimedVendor states data centers maintain ISO 27001; request Security Kit for certificate scope—not independently re-verified against a public registry in this draft. |
|---|
| ISO 27701 | ⚠️Vendor claimedVendor claims ISO/IEC 27701 on the trust portal and company page. Same access-gated evidence. | Not listed |
|---|
| SOC 2 / SOC 3 | ⚠️Vendor claimedVendor states it holds a SOC 2 Type II report. Report is on the trust portal, not a public PDF in this research pass. | ⚠️PartialPrivacy page mentions SOC 2 Type II-certified infrastructure; compliance/About emphasize SOC 1 Type II for data centers; FAQ prefers SOC 1 as internal standard. Confirm report type/scope via Security Kit. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedFrench SAS, public DPA with GDPR, UK GDPR, ePrivacy Directive, EU SCCs (French law, French courts), customer-as-controller. Customer still owns consent, masking, and lawful basis for visitor capture. | ⚠️Vendor claimedDanish entity; public GDPR page, DPA, IP masking, EU residency option, SCCs/DPF transfer language. Customer remains responsible for consent and PII exclusion from HTML. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEuropeanStack assessment, not a vendor slogan. French entity and no known US parent, but visitor data sits on AWS and Azure (US-group clouds), a US affiliate provides support, and US SaaS subprocessors include Zendesk, Postmark, OpenAI, Deepgram, Snowflake, and Salesforce. US region is an explicit option. DPF covers the US entity. Not legal advice. | ⚠️PartialDanish entity, no known US parent; session data on Google Cloud (Belgium/Iowa) and US affiliate Mouseflow, Inc. may process Customer Data. EU residency does not eliminate US-group cloud risk. Indicative only—not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedPublic DPA last updated June 2026 (v.2026.2). Subprocessor objection window 30 days. SCCs Module Two and Three. | ⚠️Vendor claimedPublic DPA at mouseflow.com/legal/data-processing-agreement/ with electronic signature; SCCs and DPF language included. |
|---|
| EU AI Act | ⚠️PartialSense is in-product generative AI over customer and visitor data (Bedrock, Azure, OpenAI). No public AI Act conformity statement found. Customer is told to avoid personal data in prompts. Not treated as not_applicable. | —Not applicableBehavior analytics SaaS with optional AI assistants (Mina, MCP); not positioned as a high-risk AI system product for this checklist. |
|---|
| EU-U.S. Data Privacy Framework | ⚠️Vendor claimedDPA and services privacy policy state Content Square, Inc. is DPF certified (EU-U.S., UK Extension, Swiss-U.S.). Listing not re-opened during this draft. | Not listed |
|---|
| HIPAA | ⚠️Vendor claimedSecurity page displays a HIPAA mark. No public BAA text reviewed. Confirm with vendor if health data is in scope (DPA says the service is not designed for sensitive data). | Not listed |
|---|
| CSA STAR | ⚠️Vendor claimedSecurity page shows a STAR mark. Trust portal lists CAIQ. Registry entry not independently opened. | Not listed |
|---|
| PCI DSS (data center) | Not listed | ⚠️Vendor claimedVendor states data centers maintain PCI DSS compliance; not a substitute for customer PCI scope on payment pages—mask card fields. |
|---|