Insights vs Pulse by Ciphera

Compare Insights and Pulse by Ciphera on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics

Logo: Insights

Insights

Austria· Web Analytics

Needs review

Shortlist when you need cookie-free hosted analytics with first-class custom events for SPAs from an Austrian operator. Skip when you need self-host, public ISO/SOC packs, or infrastructure without Google Firebase—consider Plausible Analytics, Simple Analytics, or Pirsch Analytics instead (or self-hosted Matomo).

Cookie-free trackingCustom eventsMIT client (insights-js)Austrian entityHosted SaaSFirebase data path
Logo: Pulse by Ciphera

Pulse by Ciphera

Belgium· Web Analytics

Needs review

Shortlist Pulse when you want cookieless traffic analytics plus uptime and Lighthouse in one Belgian-operated, Swiss-hosted SaaS and can accept a closed managed backend. Skip when you need full self-hosting or GA-style user-level history; consider Plausible Analytics or Simple Analytics instead.

EU-operatedCookielessOpen-source clientSwiss-hosted dataNo analytics cookies
Insights vs Pulse by Ciphera: Snapshot
FeatureLogo: InsightsInsightsLogo: Pulse by CipheraPulse by Ciphera
Country of originAustriaBelgium
CategoryWeb AnalyticsWeb Analytics
Open sourceYesYes
Self-hostedNoNo
HeadquartersAustriaBelgium
Legal entityUnsourced Digital OGCiphera BV
Governing lawNot listedBelgian law (GDPR); Swiss FADP for infrastructure location
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
EU-hosted statusNot listedPartial
Hosting / residencyOperator: Unsourced Digital OG (Austria). Vendor-documented infrastructure includes Google Firebase—Cloud Functions, Firebase Authentication (customer accounts), and Firebase Hosting—with temporary IP handling described for those Google services. Visitor analytics designed without cookies and without IP storage in DB/logs; still a US-group cloud path for processing/hosting/auth.Primary compute and object storage on Exoscale in Switzerland (Zurich). Encrypted backups and domain registration via Infomaniak (Switzerland). CDN/DNS/DDoS via Bunny (Slovenia HQ, global edge for transient IPs). Payments via Mollie (Netherlands). GitHub (US) for public source code only, per Trust page.
Summary

Austrian privacy-first hosted web analytics: page views and custom events without cookies or stored visitor IPs, with an MIT open-source JS client (backend uses Google Firebase).

Cookie-free web analytics with traffic, funnels, uptime and Lighthouse checks in one Belgian-operated, Swiss-hosted dashboard.

Tags
At a glance: Insights vs Pulse by Ciphera
At a glanceLogo: InsightsInsightsLogo: Pulse by CipheraPulse by Ciphera
HQ / lawAustria (Unsourced Digital OG; Austrian governing law)Not listed
Product typeHosted privacy web analytics + custom eventsNot listed
Client licenseMIT (insights-js); backend proprietaryNot listed
Self-hostNo public self-host optionNot listed
Commercial modelFree low-volume tier; paid by monthly event/pageview volumeFree Hobby tier; paid plans by traffic scale
Known infraGoogle Firebase (Functions, Auth, Hosting) per vendor docsNot listed
HQNot listedDiegem, Belgium (Ciphera BV)
Legal entityNot listedCiphera BV (KBO/BCE 1013.721.660)
FoundedNot listed18 September 2024 (CBE)
Primary data regionNot listedSwitzerland (Exoscale Zurich)
LicenseNot listedAGPL-3.0 client; managed backend closed
CookielessNot listedYes (vendor claim: no cookies, no fingerprinting)
Data residency regionsNot listedSwitzerland (Exoscale primary; Infomaniak backups)
Key capabilities: Insights vs Pulse by Ciphera
Key capabilitiesLogo: InsightsInsightsLogo: Pulse by CipheraPulse by Ciphera
Cookie-free trackingYesNot listed
Custom eventsYesNot listed
MIT client (insights-js)YesNot listed
Austrian entityYesNot listed
Hosted SaaSYesNot listed
Firebase data pathYesNot listed
EU-operatedNot listedYes
CookielessNot listedYes
Open-source clientNot listedYes
Swiss-hosted dataNot listedYes
No analytics cookiesNot listedYes

Insights

  • Cookie-free page views and user flows

    Tracks bounce rate, referrers, visits, and user-flow style page statistics without setting analytics cookies, so sites can avoid cookie banners driven solely by analytics. Script init plus trackPages() is the usual path for SPAs.

  • Custom and cancelable event tracking

    insights-js supports named events with string parameters, unique-per-session flags, parameter-only updates, and remove/cancel for long-lived events (e.g. subscribe then unsubscribe). Built for product and funnel metrics, not pageviews only.

  • MIT open-source TypeScript client

    The browser/npm client (insights-js) is MIT-licensed on GitHub with TypeScript types and helpers for locale, screen type, path, referrer, and duration buckets. Supports React, Angular, Vue, UMD script, and multi-project App instances. Backend remains proprietary SaaS.

  • Visitor anonymization pipeline (vendor-described)

    Vendor docs: IPs hashed only in RAM for fraud checks (not stored in DB or logs); user agents reduced to browser/OS; optional screen sizes rounded to 50px; Do Not Track honoured. Confirm fit with your DPO—anonymous design is not a legal certification.

  • Developer-oriented integration

    One-minute script install or npm package; docs cover multi-project tracking, ignoreErrors/disabled flags for production environments, and hash/search options on page paths. Lightweight client positioned against heavier GA-style tags.

Pulse by Ciphera

  • Cookieless traffic dashboard

    Pageviews, unique-visitor estimates, referrers, UTM campaigns, device or browser splits, and country-level geo from a single script tag, without cookies or fingerprinting according to Ciphera's privacy docs.

  • Journeys and conversion funnels

    Step-by-step path columns and multi-step funnels with drop-off analysis, filterable by page, country, device, or referrer for privacy-preserving conversion debugging.

  • Uptime monitors with alert routes

    Built-in uptime checks with downtime and recovery alerts to email, Slack, Discord, or a webhook, so availability sits beside traffic in one console.

  • Daily Lighthouse and Core Web Vitals

    Scheduled mobile and desktop Lighthouse runs with performance, accessibility, best-practices, SEO scores, and Core Web Vitals trends without a separate RUM product.

  • Inspectable AGPL client and read API

    Dashboard and tracking script are AGPL-3.0 on GitHub; Ciphera also documents a public read API, CLI, and export paths while keeping the managed backend closed.

Assurance & compliance: Insights vs Pulse by Ciphera
Assurance & complianceLogo: InsightsInsightsLogo: Pulse by CipheraPulse by Ciphera
Independent security / no-logs audit
Not found

Vendor describes no IP storage in DB/logs and RAM-only hashing; no public third-party audit PDF found.

Not found

Trust page states no independent audit yet; Tessera self-audit published; independent audit planned.

ISO 27001
Not found

No public certificate on getinsights.io at research time.

Not found

Ciphera explicitly states it holds no ISO 27001 certification.

SOC 2 / SOC 3
Not found

No public SOC report found.

Not found

Ciphera explicitly states it holds no SOC 2 certification.

GDPR / EU data protection
Vendor claimed

Austrian entity; privacy policy and data-collection docs; cookie-free/no-stored-IP design for visitors. Firebase/Google processing still requires transfer/DPA diligence.

Vendor claimed

Belgian controller; privacy policy describes GDPR/FADP bases and Pulse processor role. Not legal advice.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but Google Firebase (US-group) used for Cloud Functions, Auth, and Hosting per vendor data page. Indicative medium exposure. Not legal advice.

Partial

EU (Belgian) entity with no known US parent; primary hosts are European (Exoscale, Infomaniak, Bunny, Mollie). Residual paths: GitHub (US) for source code only; Bunny global edge for transient IPs. Indicative only, not legal advice.

Data processing agreement (B2B)
Not found

No standalone public DPA page found; request from contact@getinsights.io for B2B use.

On request / NDA

Privacy policy: DPA available on request at privacy@ciphera.net for Pulse processor relationships.

EU AI Act
Not applicable

Web analytics product, not an AI system product page.

Not applicable

Web analytics product; not an AI system product page.

Considerations & known limitations: Insights vs Pulse by Ciphera
Considerations & known limitationsLogo: InsightsInsightsLogo: Pulse by CipheraPulse by Ciphera
Google Firebase on critical path
High

Vendor documents Firebase Cloud Functions, Auth, and Hosting. Anonymous visitor design does not remove US-group cloud dependency for hosting/auth/processing—material for sovereignty-sensitive buyers.

Not listed
No public independent audit or certs
Medium

No ISO 27001, SOC 2, or third-party no-logs audit found on the public site. Rely on vendor claims plus your own review of the open client.

Not listed
Client open source only; no self-host
Medium

insights-js is MIT; dashboard/backend are closed SaaS. You cannot run the full product on your infrastructure.

Not listed
Small team / continuity
Medium

Product presented as built by two freelance developers under Unsourced Digital OG. Assess vendor longevity and support SLAs for business-critical analytics.

Not listed
Bounce/unique metrics need SPA routing
Low

Client docs: trackPages bounce and unique views expect a client-side router and do not use cookies/localStorage; multi-page full reloads can skew metrics.

Not listed
Managed backend is not open sourceNot listed
Medium

You can audit the browser script and dashboard code, but not the operated ingestion and storage service. Procurement that requires full-stack self-host or full server auditability should look elsewhere.

No ISO/SOC or independent audit yetNot listed
Medium

Ciphera publishes threat models, a warrant canary, and a subprocessor list, but explicitly has no ISO 27001 or SOC 2 and no completed independent audit. Enterprise security reviews will need questionnaires and a signed DPA.

Primary data residency is Switzerland, not EU/EEANot listed
Low

Swiss adequacy covers many GDPR transfer questions, but policies that hard-require EU/EEA datacenter soil will classify this as partial rather than EU-hosted.

Marketing vs privacy wording conflictsNot listed
Low

Product FAQ pages disagree on whether custom events ship today and whether a DPA is needed. Prefer privacy@ and the privacy policy for legal commitments until Ciphera aligns the FAQs.

Fit

Insights

Best fit when

  • Indie developers and small teams who want pageviews plus product/funnel events without analytics cookies
  • SPA and web-app builders using client-side routers who can call insights-js track/trackPages APIs
  • Teams that accept a free low-volume tier then event-volume paid plans (check current limits on getinsights.io)
  • Buyers who value an MIT-auditable client library even if the backend stays closed
  • EU sites prioritizing no-stored-visitor-IP design over full stack self-host control

Poor fit when

  • Orgs that require self-hosted or fully open-source analytics backend
  • Procurement needing published DPA, ISO 27001, or SOC 2 on the vendor site today
  • Policies that forbid Google Firebase / US-group cloud on any analytics path
  • Classic multi-page sites expecting accurate cookie-free bounce/unique metrics without SPA routing
  • Teams needing GA-class free segmentation, ads integrations, or data warehouse export

Consider instead when

  • When: You want simple hosted EU privacy page analytics with a strong Plausible-style product footprint

    Consider: Plausible Analytics

    Compare event depth: Insights markets custom events as a core differentiator vs simpler page-focused tools.

  • When: You want cookie-free analytics with an explicit privacy brand and different commercial packaging

    Consider: Simple Analytics

    Verify each vendor's hosting and subprocessor pages side by side.

  • When: You prefer a German peer privacy analytics product

    Consider: Pirsch Analytics

    Compare event features, regions, and legal docs for your DPA process.

  • When: You need full control of the stack or on-prem processing

    Consider: Self-hosted Matomo (or similar open analytics)

    Higher ops cost; no dependency on Insights SaaS or Firebase.

Pulse by Ciphera

Best fit when

  • EU or Swiss organisations replacing GA4 primarily to remove analytics cookies and consent-banner friction
  • Teams that want traffic, funnels, uptime, and Lighthouse scores in one vendor console
  • Buyers who need a Belgian legal entity and named European subprocessors rather than a US cookieless SaaS
  • Sites that can work with aggregate and month-scoped visitor estimates instead of persistent user IDs
  • Engineering leads who want the browser script and dashboard code on GitHub under AGPL-3.0 for inspection

Poor fit when

  • Organisations that must self-host the full analytics backend (Pulse's managed core is closed)
  • Product analytics use cases that need durable cross-visit identity, cohorting, or GA4 BigQuery-style user exports
  • Buyers requiring completed ISO 27001, SOC 2, or a published independent security audit today
  • Teams that need EU/EEA soil specifically rather than Swiss residency (primary data is in Switzerland)

Consider instead when

  • When: You need a mature EU cookieless analytics product with an official full-stack self-host option

    Consider: Plausible Analytics

    Plausible (Estonia) is the common self-host plus SaaS peer; Pulse keeps the backend managed-only.

  • When: You want a minimal Dutch cookieless counter without uptime or Lighthouse bundles

    Consider: Simple Analytics

    Closer peer for strictly analytics SaaS; Pulse differentiates with ops-style panels.

  • When: You need enterprise analytics with strong EU residency controls and heavier compliance packaging

    Consider: Piwik PRO or Friendly Analytics

    Heavier Matomo-class or Swiss-hosted peers when Pulse's startup assurance set is too thin.

Open questions for due diligence

Insights

  • Will Unsourced Digital OG sign a customer DPA and provide a current subprocessor list with regions?
  • Which Firebase/GCP regions process analytics and auth data today?
  • Are there any independent security assessments available under NDA?
  • What is the data retention schedule for events and account data after cancellation?
  • Is there an official path for enterprise SSO, invoice billing, or custom retention?

Pulse by Ciphera

  • Will Ciphera sign your standard DPA and return the full registered-address subprocessor appendix on request?
  • What is the retention and deletion SLA for a single customer's Pulse project data after contract end?
  • When is the planned independent security audit scheduled, and will the report be public?
  • Are Google Search Console, Bing, or CDN analytics panels generally available, or only mentioned in some marketing copy?