Pulse by Ciphera vs Vantevo Analytics

Compare Pulse by Ciphera and Vantevo Analytics on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics

Logo: Pulse by Ciphera

Pulse by Ciphera

Belgium· Web Analytics

Needs review

Shortlist Pulse when you want cookieless traffic analytics plus uptime and Lighthouse in one Belgian-operated, Swiss-hosted SaaS and can accept a closed managed backend. Skip when you need full self-hosting or GA-style user-level history; consider Plausible Analytics or Simple Analytics instead.

EU-operatedCookielessOpen-source clientSwiss-hosted dataNo analytics cookies
Logo: Vantevo Analytics

Vantevo Analytics

Italy· Web Analytics

Needs review

Shortlist Vantevo when you want Italian-operated, cookie-less site analytics with a flat dashboard, goals/events, optional GA historical import, and beta ecommerce funnel events under a public DPA. Skip when you need multi-day returning-visitor identity, self-hosting/open source, or enterprise-grade public certifications—consider Plausible/Simple Analytics/Pirsch for lighter peers, or Piwik PRO for self-host/compliance-heavy programs.

Cookie-less trackingSingle-dashboard metricsEcommerce events (beta)GA history importPublic DPAItalian operator
Pulse by Ciphera vs Vantevo Analytics: Snapshot
FeatureLogo: Pulse by CipheraPulse by CipheraLogo: Vantevo AnalyticsVantevo Analytics
Country of originBelgiumItaly
CategoryWeb AnalyticsWeb Analytics
Open sourceYesNo
Self-hostedNoNo
HeadquartersBelgiumItaly
Legal entityCiphera BVNetforce Srl, Via Po' 136/A, 43124 Parma PR, Italy
Governing lawBelgian law (GDPR); Swiss FADP for infrastructure locationItalian law (controller established in Italy; Terms governed by place of establishment)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
EU-hosted statusPartialNot listed
Hosting / residencyPrimary compute and object storage on Exoscale in Switzerland (Zurich). Encrypted backups and domain registration via Infomaniak (Switzerland). CDN/DNS/DDoS via Bunny (Slovenia HQ, global edge for transient IPs). Payments via Mollie (Netherlands). GitHub (US) for public source code only, per Trust page.Vendor claims EU servers and EU backups. Public DPA names OVH Datacenter Roubaix and an AWS datacenter for storage/processing. Additional third parties: Stripe (payments), Crisp (support chat), optional Google Analytics and Search Console APIs when customers connect them.
Summary

Cookie-free web analytics with traffic, funnels, uptime and Lighthouse checks in one Belgian-operated, Swiss-hosted dashboard.

Italian cookie-less web analytics from Netforce Srl (Parma): single-dashboard traffic, events, goals, and ecommerce funnels with EU processing claims and a public DPA.

Tags
At a glance: Pulse by Ciphera vs Vantevo Analytics
At a glanceLogo: Pulse by CipheraPulse by CipheraLogo: Vantevo AnalyticsVantevo Analytics
HQDiegem, Belgium (Ciphera BV)Parma, Italy (Netforce Srl)
Legal entityCiphera BV (KBO/BCE 1013.721.660)Not listed
Founded18 September 2024 (CBE)Not listed
Primary data regionSwitzerland (Exoscale Zurich)Not listed
LicenseAGPL-3.0 client; managed backend closedNot listed
Commercial modelFree Hobby tier; paid plans by traffic scaleView-based subscription after free trial
Product typeNot listedCookie-less web analytics SaaS
Self-host / OSSNot listedNo (SaaS only; not open source)
Hosting (public DPA)Not listedOVH Roubaix + AWS datacenter; EU processing claims
Notable limitNot listedNo multi-day returning visitors; max 50 sites/account (Terms)
CookielessYes (vendor claim: no cookies, no fingerprinting)Not listed
Data residency regionsSwitzerland (Exoscale primary; Infomaniak backups)Not listed
Key capabilities: Pulse by Ciphera vs Vantevo Analytics
Key capabilitiesLogo: Pulse by CipheraPulse by CipheraLogo: Vantevo AnalyticsVantevo Analytics
EU-operatedYesNot listed
CookielessYesNot listed
Open-source clientYesNot listed
Swiss-hosted dataYesNot listed
No analytics cookiesYesNot listed
Cookie-less trackingNot listedYes
Single-dashboard metricsNot listedYes
Ecommerce events (beta)Not listedYes
GA history importNot listedYes
Public DPANot listedYes
Italian operatorNot listedYes

Pulse by Ciphera

  • Cookieless traffic dashboard

    Pageviews, unique-visitor estimates, referrers, UTM campaigns, device or browser splits, and country-level geo from a single script tag, without cookies or fingerprinting according to Ciphera's privacy docs.

  • Journeys and conversion funnels

    Step-by-step path columns and multi-step funnels with drop-off analysis, filterable by page, country, device, or referrer for privacy-preserving conversion debugging.

  • Uptime monitors with alert routes

    Built-in uptime checks with downtime and recovery alerts to email, Slack, Discord, or a webhook, so availability sits beside traffic in one console.

  • Daily Lighthouse and Core Web Vitals

    Scheduled mobile and desktop Lighthouse runs with performance, accessibility, best-practices, SEO scores, and Core Web Vitals trends without a separate RUM product.

  • Inspectable AGPL client and read API

    Dashboard and tracking script are AGPL-3.0 on GitHub; Ciphera also documents a public read API, CLI, and export paths while keeping the managed backend closed.

Vantevo Analytics

  • Daily-rotating hash visitor counting (no analytics cookies)

    Visitor uniqueness for a day is derived from HASH(salt + domain + IP + User-Agent) with a salt that rotates every 24 hours; IP and User-Agent are not retained after hashing, per the DPA and docs. No cookies, localStorage, or browser cache for the analytics session—and therefore no multi-day new/returning visitor split. Fits privacy-led sites that prioritize aggregate trends over identity graphs.

  • Single-page traffic dashboard

    Unique visitors, sessions, page views, bounce rate, duration, entry/exit pages, geography, devices, languages, referrals, and UTM campaigns appear on one overview without multi-level custom report builders. Aimed at agencies and SMEs that want operational metrics without a full-time analytics specialist.

  • Custom events, goals, and automatic link/download tracking

    Track button clicks, scrolls, form submits, custom event names with metadata, and conversion goals; outbound links and file downloads can be auto-captured with HTML attributes to exclude specific URLs. Useful for content and lead-gen sites measuring meaningful actions without cookie tags.

  • Ecommerce funnel events (beta script)

    Optional vantevo-ecommerce.js records wishlist, view item, cart add/remove, checkout stages, payment type, coupons, variants/categories, and purchase—docs mark the ecommerce section as still in beta. Best for shops that need privacy-oriented funnel visibility and can accept beta maturity.

  • Universal Analytics import and multi-platform install paths

    Connect Google Analytics to import page statistics from January 2018 onward into the same calendar view (with documented metric gaps and API limits). Ship via head script, WordPress plugin, React/Vue/npm packages, Shopify/Wix theme paste, hybrid apps, or server-side event APIs—plus optional Search Console connection for keyword/impression views.

Assurance & compliance: Pulse by Ciphera vs Vantevo Analytics
Assurance & complianceLogo: Pulse by CipheraPulse by CipheraLogo: Vantevo AnalyticsVantevo Analytics
Independent security / no-logs audit
Not found

Trust page states no independent audit yet; Tessera self-audit published; independent audit planned.

Not found

No public third-party audit PDF or no-logs attestation found on security/docs pages searched.

ISO 27001
Not found

Ciphera explicitly states it holds no ISO 27001 certification.

Not found

No ISO 27001 certificate or registry evidence found on the public site.

SOC 2 / SOC 3
Not found

Ciphera explicitly states it holds no SOC 2 certification.

Not found

No SOC 2/3 report referenced on public trust/legal pages.

GDPR / EU data protection
Vendor claimed

Belgian controller; privacy policy describes GDPR/FADP bases and Pulse processor role. Not legal advice.

Vendor claimed

Italian controller (Netforce Srl); cookie-less visitor model and EU hosting asserted on docs/GDPR pages; public DPA available. Vendor “100% GDPR compliant” wording is a claim, not independent legal certification.

US CLOUD Act exposure (indicative)
Partial

EU (Belgian) entity with no known US parent; primary hosts are European (Exoscale, Infomaniak, Bunny, Mollie). Residual paths: GitHub (US) for source code only; Bunny global edge for transient IPs. Indicative only, not legal advice.

Partial

EU entity / no known US parent, but DPA lists AWS alongside OVH Roubaix; Stripe and optional Google APIs are US-group services. Not a clean EU-only infrastructure story. Not legal advice.

Data processing agreement (B2B)
On request / NDA

Privacy policy: DPA available on request at privacy@ciphera.net for Pulse processor relationships.

Vendor claimed

Public DPA at vantevo.io/dpa; Terms state DPA forms part of the main agreement (customer controller, Netforce processor).

EU AI Act
Not applicable

Web analytics product; not an AI system product page.

Not applicable

Web analytics SaaS; not marketed as an AI system product.

Considerations & known limitations: Pulse by Ciphera vs Vantevo Analytics
Considerations & known limitationsLogo: Pulse by CipheraPulse by CipheraLogo: Vantevo AnalyticsVantevo Analytics
Managed backend is not open source
Medium

You can audit the browser script and dashboard code, but not the operated ingestion and storage service. Procurement that requires full-stack self-host or full server auditability should look elsewhere.

Not listed
No ISO/SOC or independent audit yet
Medium

Ciphera publishes threat models, a warrant canary, and a subprocessor list, but explicitly has no ISO 27001 or SOC 2 and no completed independent audit. Enterprise security reviews will need questionnaires and a signed DPA.

Not listed
Primary data residency is Switzerland, not EU/EEA
Low

Swiss adequacy covers many GDPR transfer questions, but policies that hard-require EU/EEA datacenter soil will classify this as partial rather than EU-hosted.

Not listed
Marketing vs privacy wording conflicts
Low

Product FAQ pages disagree on whether custom events ship today and whether a DPA is needed. Prefer privacy@ and the privacy policy for legal commitments until Ciphera aligns the FAQs.

Not listed
AWS (and other US-group services) in data pathNot listed
Medium

Despite Italian HQ and EU hosting marketing, the DPA explicitly stores data at OVH Roubaix and an AWS datacenter. Stripe payments and optional Google integrations add further US-group processors. Organizations with strict “no US cloud” policies need written clarification of regions, SCCs, and residual access risk.

No public ISO/SOC or independent auditNot listed
Medium

Shortlisting relies on vendor security measures described in the DPA (encryption, backups, breach notification windows) without published certs or third-party audit reports. Security questionnaires and NDA evidence may be required for regulated buyers.

No multi-day visitor identity by designNot listed
Low

Daily salt rotation and cookie-less design prevent classic returning-visitor and cross-device analysis. This is a privacy feature for many buyers and a hard product limit for others.

Ecommerce module still betaNot listed
Medium

Official ecommerce docs mark the section as beta/incomplete for final publication. Do not assume GA ecommerce parity or long-term event stability without a pilot.

View overage and website caps in TermsNot listed
Low

Recording can pause after plan-specific overage tolerances; Terms also set a 50-website maximum per account. Align marketing “unlimited domains” language with contract terms before large agency rollouts.

SaaS-only dependencyNot listed
Low

No public self-host option. Continuity depends on Netforce operations, OVH/AWS, and export/delete workflows (JSON/CSV return or delete timelines in DPA/Terms).

Fit

Pulse by Ciphera

Best fit when

  • EU or Swiss organisations replacing GA4 primarily to remove analytics cookies and consent-banner friction
  • Teams that want traffic, funnels, uptime, and Lighthouse scores in one vendor console
  • Buyers who need a Belgian legal entity and named European subprocessors rather than a US cookieless SaaS
  • Sites that can work with aggregate and month-scoped visitor estimates instead of persistent user IDs
  • Engineering leads who want the browser script and dashboard code on GitHub under AGPL-3.0 for inspection

Poor fit when

  • Organisations that must self-host the full analytics backend (Pulse's managed core is closed)
  • Product analytics use cases that need durable cross-visit identity, cohorting, or GA4 BigQuery-style user exports
  • Buyers requiring completed ISO 27001, SOC 2, or a published independent security audit today
  • Teams that need EU/EEA soil specifically rather than Swiss residency (primary data is in Switzerland)

Consider instead when

  • When: You need a mature EU cookieless analytics product with an official full-stack self-host option

    Consider: Plausible Analytics

    Plausible (Estonia) is the common self-host plus SaaS peer; Pulse keeps the backend managed-only.

  • When: You want a minimal Dutch cookieless counter without uptime or Lighthouse bundles

    Consider: Simple Analytics

    Closer peer for strictly analytics SaaS; Pulse differentiates with ops-style panels.

  • When: You need enterprise analytics with strong EU residency controls and heavier compliance packaging

    Consider: Piwik PRO or Friendly Analytics

    Heavier Matomo-class or Swiss-hosted peers when Pulse's startup assurance set is too thin.

Vantevo Analytics

Best fit when

  • EU/Italian teams replacing Google Analytics for marketing-site KPIs without analytics cookies
  • Agencies needing a simple multi-site dashboard clients can read without GA training
  • Shops that want privacy-oriented funnel events (cart → checkout → purchase) and accept beta maturity
  • Migrations that need to pull Universal Analytics page history into a privacy-first tool
  • Stacks using WordPress, Shopify, React/Next, Vue/Nuxt, or server-side event APIs

Poor fit when

  • Requirements for multi-day returning visitors, cross-device identity, or ad-platform audience sync
  • Mandatory self-hosting, open-source code audit, or on-prem only deployments
  • Procurement that requires public ISO 27001/SOC 2 evidence and independent security audits before shortlist
  • Heavy product analytics / cohort experimentation beyond site and ecommerce funnel events
  • Accounts that need more than the Terms’ 50-website cap without vendor exception

Consider instead when

  • When: You want a well-known lightweight EU privacy analytics tool with strong community presence

    Consider: Plausible Analytics or Simple Analytics

    Compare ecommerce depth, GA import, and commercial packaging side by side.

  • When: You need self-host or enterprise compliance packaging

    Consider: Piwik PRO (or Matomo self-host outside this catalog’s EU-SaaS peers)

    Vantevo is SaaS-only with no public self-host edition found.

  • When: You need full product analytics and long-horizon cohorts

    Consider: Mixpanel or similar product analytics suites

    Different category: identity-rich product instrumentation vs privacy-first site metrics.

  • When: You specifically want German-market privacy analytics peers

    Consider: Pirsch Analytics or etracker (catalog peers)

    Validate feature parity on ecommerce and import paths.

Open questions for due diligence

Pulse by Ciphera

  • Will Ciphera sign your standard DPA and return the full registered-address subprocessor appendix on request?
  • What is the retention and deletion SLA for a single customer's Pulse project data after contract end?
  • When is the planned independent security audit scheduled, and will the report be public?
  • Are Google Search Console, Bing, or CDN analytics panels generally available, or only mentioned in some marketing copy?

Vantevo Analytics

  • Which exact AWS region(s) and services are in production, and are standard contractual clauses / transfer impact assessments available on request?
  • Is a current subprocessor list (beyond DPA/privacy mentions of OVH, AWS, Stripe, Crisp, Google) available under NDA?
  • Are ISO 27001, SOC 2, or independent penetration-test summaries available for enterprise procurement?
  • What is the production roadmap and support SLA for ecommerce events leaving beta?
  • How should multi-brand agencies interpret “unlimited domains” marketing versus the Terms’ 50-website cap—exceptions available?