| Independent security / no-logs audit | —Not applicableNot a no-logs VPN/analytics product; marketing data platform processes customer event/profile data by design. | 🔒On request / NDAVendor claims annual external penetration tests and publishes a Trust Portal with pentest reports behind access. No public independent no-logs audit (this is a recorder, not a no-logs VPN). |
|---|
| Independent security / pentest program | ⚠️Vendor claimedSecurity product sheet claims external pentests (black/grey box) every six months and customer audit rights; no public audit PDF reviewed. | Non indicato |
|---|
| ISO 27001 | ⚠️PartialSecurity sheet attributes ISO 27001 (and related) compliance to the hosting provider in France; not verified as Commanders Act's own current certificate. | ⚠️Vendor claimedContentsquare states it is ISO 27001 certified (also claims ISO 27017, 27018, 27701). Certificates are on the Trust Portal; not independently downloaded for this draft. |
|---|
| SOC 2 / SOC 3 | ⚠️PartialSecurity sheet states hosting provider complies with SOC Type 1 and 2; not verified as vendor-owned SOC 2 report. | ⚠️Vendor claimedTrust portal and security pages claim a SOC 2 Type II report. Report not independently downloaded. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedFrench controller/processor entity; public privacy policy, named DPO, EU storage claim for site data, integrated consent tooling. Customer DPA terms not fully public on marketing pages. | ⚠️Vendor claimedEU parent and contracting entity for non-Americas Hotjar Services. Public DPA, SCCs, and GDPR language. Customer is controller and must supply a lawful basis for visitor capture. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity / no known US parent, but Cloudflare CDN on public app/platform hostnames and incomplete public subprocessor list for customer data path. Not legal advice. | ⚠️PartialAssessment, not a vendor slogan. French parent and no known US parent, but AWS and Azure host visitor data, Content Square, Inc. and Zendesk process support data, and US regions exist. Not legal advice. |
|---|
| Data processing agreement (B2B) | ?UnknownWebsite privacy policy covers visitor/site processing; standard B2B DPA / Art. 28 package not located as a public self-serve download—request in procurement. | ⚠️Vendor claimedPublic Contentsquare DPA incorporated by the MSA. Execution of the MSA or an order form is treated as execution of the DPA and SCCs. |
|---|
| EU AI Act | —Not applicableIncludes AI-assisted ad recommendations; not assessed here as a high-risk AI system product category. | —Not applicableCore product is analytics and replay, not an AI system sold as such. Sense AI and survey LLMs exist as optional features. Confirm AI Act role if you enable those modules. |
|---|
| CSA STAR | Non indicato | ⚠️Vendor claimedSecurity page displays a STAR badge. Scope and level not independently verified. |
|---|