Pulse by Ciphera vs Swetrix

Compare Pulse by Ciphera and Swetrix on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics

Logo: Pulse by Ciphera

Pulse by Ciphera

Belgium· Web Analytics

Needs review

Shortlist Pulse when you want cookieless traffic analytics plus uptime and Lighthouse in one Belgian-operated, Swiss-hosted SaaS and can accept a closed managed backend. Skip when you need full self-hosting or GA-style user-level history; consider Plausible Analytics or Simple Analytics instead.

EU-operatedCookielessOpen-source clientSwiss-hosted dataNo analytics cookies
Logo: Swetrix

Swetrix

United Kingdom· Web Analytics

Needs review

Shortlist Swetrix when you want cookieless traffic plus product-oriented tools (funnels, RUM, errors, optional Cloud replays) under a UK company with Hetzner DE hosting and AGPLv3 self-host CE. Skip when you need public ISO/SOC packs, zero US-group subprocessors, multi-year cookie retention cohorts, or free forever hosted analytics—consider Plausible Analytics or Simple Analytics for minimal traffic-only privacy analytics, or Matomo for heavyweight self-host control.

Cookieless trackingHetzner DE hostingOpen source (AGPLv3)Self-host CEFunnels + errors + RUMPublic DPA
Pulse by Ciphera vs Swetrix: Snapshot
FeatureLogo: Pulse by CipheraPulse by CipheraLogo: SwetrixSwetrix
Country of originBelgiumUnited Kingdom
CategoryWeb AnalyticsWeb Analytics
Open sourceYesYes
Self-hostedNoYes
HeadquartersBelgiumUnited Kingdom
Legal entityCiphera BVSwetrix Ltd (SC797389), Edinburgh, Scotland
Governing lawBelgian law (GDPR); Swiss FADP for infrastructure locationNot listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
EU-hosted statusPartialNot listed
Hosting / residencyPrimary compute and object storage on Exoscale in Switzerland (Zurich). Encrypted backups and domain registration via Infomaniak (Switzerland). CDN/DNS/DDoS via Bunny (Slovenia HQ, global edge for transient IPs). Payments via Mollie (Netherlands). GitHub (US) for public source code only, per Trust page.Cloud analytics data: Hetzner Online GmbH (Germany) per DPA/Data Policy. End User error monitoring sub-processor: Sentry / Functional Software Inc. (United States). Customer-side Privacy Policy list also includes Paddle (UK payments), Fastmail (Australia business email), AWS (US transactional/marketing email), OpenRouter (US optional AI chat). No known US parent.
Summary

Cookie-free web analytics with traffic, funnels, uptime and Lighthouse checks in one Belgian-operated, Swiss-hosted dashboard.

Cookieless, privacy-first web analytics from a UK company: traffic, funnels, errors, and performance on Hetzner in Germany, with AGPLv3 self-host Community Edition and optional Cloud session replays.

Tags
At a glance: Pulse by Ciphera vs Swetrix
At a glanceLogo: Pulse by CipheraPulse by CipheraLogo: SwetrixSwetrix
HQDiegem, Belgium (Ciphera BV)Edinburgh, United Kingdom
Legal entityCiphera BV (KBO/BCE 1013.721.660)Swetrix Ltd (SC797389)
Founded18 September 2024 (CBE)Not listed
Primary data regionSwitzerland (Exoscale Zurich)Not listed
LicenseAGPL-3.0 client; managed backend closedAGPLv3 (Community Edition)
Commercial modelFree Hobby tier; paid plans by traffic scaleEvent-volume Cloud subscription; free self-host CE; timed trial
Governing lawNot listedScotland (Terms)
Primary hostingNot listedHetzner Online GmbH, Germany
Open sourceNot listedYes — github.com/Swetrix/swetrix
CookielessYes (vendor claim: no cookies, no fingerprinting)Not listed
Data residency regionsSwitzerland (Exoscale primary; Infomaniak backups)Not listed
Key capabilities: Pulse by Ciphera vs Swetrix
Key capabilitiesLogo: Pulse by CipheraPulse by CipheraLogo: SwetrixSwetrix
EU-operatedYesNot listed
CookielessYesYes
Open-source clientYesNot listed
Swiss-hosted dataYesNot listed
No analytics cookiesYesNot listed
Hetzner DE hostingNot listedYes
Open source (AGPLv3)Not listedYes
Self-host CENot listedYes
Funnels + errors + RUMNot listedYes
Public DPANot listedYes

Pulse by Ciphera

  • Cookieless traffic dashboard

    Pageviews, unique-visitor estimates, referrers, UTM campaigns, device or browser splits, and country-level geo from a single script tag, without cookies or fingerprinting according to Ciphera's privacy docs.

  • Journeys and conversion funnels

    Step-by-step path columns and multi-step funnels with drop-off analysis, filterable by page, country, device, or referrer for privacy-preserving conversion debugging.

  • Uptime monitors with alert routes

    Built-in uptime checks with downtime and recovery alerts to email, Slack, Discord, or a webhook, so availability sits beside traffic in one console.

  • Daily Lighthouse and Core Web Vitals

    Scheduled mobile and desktop Lighthouse runs with performance, accessibility, best-practices, SEO scores, and Core Web Vitals trends without a separate RUM product.

  • Inspectable AGPL client and read API

    Dashboard and tracking script are AGPL-3.0 on GitHub; Ciphera also documents a public read API, CLI, and export paths while keeping the managed backend closed.

Swetrix

  • Cookieless traffic analytics with hashed sessions

    Lightweight script captures pageviews, referrers/UTMs, devices, and city-level geo without cookies or client-side storage. Per the Data Policy, IP and User-Agent are hashed in memory with a daily rotating salt; only a random session id is stored—so you get sessions without long-term cross-day visitor retention.

  • Funnels, custom events, and goals

    Instrument signups, purchases, and other conversions as custom events; build multi-step funnels and goals in the dashboard. Useful for product and growth teams who need drop-off analysis without bolting on a second product-analytics SaaS.

  • Real-user performance and client error tracking

    Records Web Performance API timings (TTFB, DNS, TLS, render, full page load) and optional JavaScript errors with stack/context by page and browser. Bridges marketing traffic views with engineering signals that pure pageview tools omit.

  • Opt-in Cloud session replays with privacy modes

    Cloud projects can call startSessionReplay() to record DOM and interactions; default modes mask text/inputs. Replays are not created by ordinary pageviews—customers must enable them and own consent, masking, and page exclusions. Cloud-only versus Community Edition.

  • AGPLv3 open source with Docker self-host CE

    Core platform is public on GitHub under GNU AGPLv3; Community Edition deploys via official Docker docs with MySQL, ClickHouse, and Redis. CE includes core analytics, events, sessions, funnels, performance, and errors—but not all Cloud extras (replays, some alerts/org/AI features).

  • Alerts, API, GA import, and team access

    Configure alerts to email, Slack, Telegram, Discord, webhooks, or push; pull or push data via the API; import GA4 history; invite organisations with roles or share password-protected/public dashboards. Fits agencies and multi-site operators who outgrow single-user tools.

Assurance & compliance: Pulse by Ciphera vs Swetrix
Assurance & complianceLogo: Pulse by CipheraPulse by CipheraLogo: SwetrixSwetrix
Independent security / no-logs audit
Not found

Trust page states no independent audit yet; Tessera self-audit published; independent audit planned.

Not found

Searched marketing, DPA, privacy, and data policy; no public independent audit PDF located. Open-source code is available for review.

ISO 27001
Not found

Ciphera explicitly states it holds no ISO 27001 certification.

Not found

No public ISO 27001 certification claim found on primary pages.

SOC 2 / SOC 3
Not found

Ciphera explicitly states it holds no SOC 2 certification.

Not found

No public SOC 2/3 report found.

GDPR / EU data protection
Vendor claimed

Belgian controller; privacy policy describes GDPR/FADP bases and Pulse processor role. Not legal advice.

Vendor claimed

UK company; public GDPR/PECR discussion in Data Policy; cookieless design with non-stored IPs for standard analytics; Hetzner DE hosting; public DPA. Optional replays may be personal data depending on configuration—customer assesses legal basis.

US CLOUD Act exposure (indicative)
Partial

EU (Belgian) entity with no known US parent; primary hosts are European (Exoscale, Infomaniak, Bunny, Mollie). Residual paths: GitHub (US) for source code only; Bunny global edge for transient IPs. Indicative only, not legal advice.

Partial

No known US parent; primary analytics on Hetzner DE. Material exception: Sentry (US) processes End User error data per DPA; Privacy Policy also lists AWS and OpenRouter (US) for customer email/AI. Indicative medium exposure—not a clean bill. Not legal advice.

Data processing agreement (B2B)
On request / NDA

Privacy policy: DPA available on request at privacy@ciphera.net for Pulse processor relationships.

Vendor claimed

Public DPA at swetrix.com/dpa incorporated by Terms; acceptance by use of Service; signed copy on request.

EU AI Act
Not applicable

Web analytics product; not an AI system product page.

Not applicable

Core product is web analytics, not an AI system. Optional Ask AI / OpenRouter is ancillary; confirm if your deployment enables it.

Considerations & known limitations: Pulse by Ciphera vs Swetrix
Considerations & known limitationsLogo: Pulse by CipheraPulse by CipheraLogo: SwetrixSwetrix
Managed backend is not open source
Medium

You can audit the browser script and dashboard code, but not the operated ingestion and storage service. Procurement that requires full-stack self-host or full server auditability should look elsewhere.

Not listed
No ISO/SOC or independent audit yet
Medium

Ciphera publishes threat models, a warrant canary, and a subprocessor list, but explicitly has no ISO 27001 or SOC 2 and no completed independent audit. Enterprise security reviews will need questionnaires and a signed DPA.

Not listed
Primary data residency is Switzerland, not EU/EEA
Low

Swiss adequacy covers many GDPR transfer questions, but policies that hard-require EU/EEA datacenter soil will classify this as partial rather than EU-hosted.

Not listed
Marketing vs privacy wording conflicts
Low

Product FAQ pages disagree on whether custom events ship today and whether a DPA is needed. Prefer privacy@ and the privacy policy for legal commitments until Ciphera aligns the FAQs.

Not listed
US-group subprocessors (Sentry, AWS, OpenRouter)Not listed
Medium

Primary analytics hosting is Hetzner DE, but Sentry (US) is an End User error-tracking sub-processor on the DPA, and AWS/OpenRouter appear for customer email/AI. Orgs with strict no-US-cloud rules need explicit acceptance or self-host CE to avoid those paths.

Session replay is opt-in and controller-ownedNot listed
Medium

Cloud replays can capture DOM and inputs unless masked. Customers must enable startSessionReplay(), configure privacy modes/exclusions, and provide notices/consent where required—misconfiguration can reintroduce personal data risk that standard cookieless pageviews avoid.

No public ISO/SOC or third-party auditNot listed
Medium

Assurance relies on first-party policies, Hetzner infrastructure claims, and open source. Enterprise questionnaires that hard-gate on certs will stall until materials are provided under NDA or produced.

Cloud vs Community Edition feature gapNot listed
Low

Self-host CE is free and covers core analytics, but replays and several Cloud growth/ops features are limited or Cloud-only. Budget and feature planning must not assume feature parity.

Daily salt rotation limits retention metricsNot listed
Low

Cookieless design deliberately prevents classic multi-day visitor retention. Teams that need that metric class need another product or consented identity.

Fit

Pulse by Ciphera

Best fit when

  • EU or Swiss organisations replacing GA4 primarily to remove analytics cookies and consent-banner friction
  • Teams that want traffic, funnels, uptime, and Lighthouse scores in one vendor console
  • Buyers who need a Belgian legal entity and named European subprocessors rather than a US cookieless SaaS
  • Sites that can work with aggregate and month-scoped visitor estimates instead of persistent user IDs
  • Engineering leads who want the browser script and dashboard code on GitHub under AGPL-3.0 for inspection

Poor fit when

  • Organisations that must self-host the full analytics backend (Pulse's managed core is closed)
  • Product analytics use cases that need durable cross-visit identity, cohorting, or GA4 BigQuery-style user exports
  • Buyers requiring completed ISO 27001, SOC 2, or a published independent security audit today
  • Teams that need EU/EEA soil specifically rather than Swiss residency (primary data is in Switzerland)

Consider instead when

  • When: You need a mature EU cookieless analytics product with an official full-stack self-host option

    Consider: Plausible Analytics

    Plausible (Estonia) is the common self-host plus SaaS peer; Pulse keeps the backend managed-only.

  • When: You want a minimal Dutch cookieless counter without uptime or Lighthouse bundles

    Consider: Simple Analytics

    Closer peer for strictly analytics SaaS; Pulse differentiates with ops-style panels.

  • When: You need enterprise analytics with strong EU residency controls and heavier compliance packaging

    Consider: Piwik PRO or Friendly Analytics

    Heavier Matomo-class or Swiss-hosted peers when Pulse's startup assurance set is too thin.

Swetrix

Best fit when

  • SMEs, agencies, and product teams replacing GA4 who need cookieless traffic stats without a cookie banner driven only by analytics
  • Engineering-minded buyers who want error tracking and real-user performance in the same privacy-first dashboard as pageviews
  • Teams that may enable Cloud session replays later but can treat them as explicit opt-in with their own legal basis
  • Operators willing to run Docker Community Edition (MySQL/ClickHouse/Redis) when Cloud commercial terms or feature limits do not fit
  • Buyers who need a public B2B DPA, API access, GA4 import, and multi-channel alerts under a UK legal entity

Poor fit when

  • Enterprises that require published ISO 27001 / SOC 2 certificates or independent audit PDFs before shortlist
  • Policies that forbid any US-group subprocessors (Sentry is listed for End User error data; AWS/OpenRouter appear for customer services)
  • Use cases that depend on long-term cookie-based retention or cross-device identity graphs
  • Buyers who only want free hosted analytics with no paid Cloud tier and no self-host operations burden
  • Sites that will run session replays on sensitive flows without capacity to configure masking, exclusions, and consent

Consider instead when

  • When: You only need minimal cookieless pageviews/referrers with the smallest possible product surface

    Consider: Plausible Analytics or Simple Analytics

    Swetrix adds funnels, errors, RUM, and Cloud replays; peers stay closer to pure traffic analytics.

  • When: You need deep on-prem control, plugins, and mature enterprise self-host packaging

    Consider: Matomo (self-host or managed EU hosts such as Matomo by Stackhero)

    Heavier ops and optional cookies; stronger fit for large controlled deployments.

  • When: You must stay inside Google advertising measurement and free GA4 ecosystem tooling

    Consider: Google Analytics

    Trade privacy, consent, and transfer complexity for ads integration and zero software fee.

Open questions for due diligence

Pulse by Ciphera

  • Will Ciphera sign your standard DPA and return the full registered-address subprocessor appendix on request?
  • What is the retention and deletion SLA for a single customer's Pulse project data after contract end?
  • When is the planned independent security audit scheduled, and will the report be public?
  • Are Google Search Console, Bing, or CDN analytics panels generally available, or only mentioned in some marketing copy?

Swetrix

  • Can Enterprise contracts exclude or replace Sentry (and other US-group subprocessors) for End User data paths?
  • Are ISO 27001, SOC 2, or pen-test summaries available under NDA?
  • What is the exact backup/DR location topology beyond “secure backups” wording on the DPA?
  • Which Cloud-only features remain permanently out of CE versus delayed open-source release?
  • For session replay at your traffic volumes, what retention defaults and export/delete SLAs apply on your plan?