Pulse by Ciphera vs Stormly

Confronta Pulse by Ciphera e Stormly su capacità, giurisdizione, garanzie e idoneità per acquirenti europei.

Entrambi elencati come alternative a: Google Analytics

Logo: Pulse by Ciphera

Pulse by Ciphera

Belgium· Web Analytics

Needs review

Shortlist Pulse when you want cookieless traffic analytics plus uptime and Lighthouse in one Belgian-operated, Swiss-hosted SaaS and can accept a closed managed backend. Skip when you need full self-hosting or GA-style user-level history; consider Plausible Analytics or Simple Analytics instead.

EU-operatedCookielessOpen-source clientSwiss-hosted dataNo analytics cookies
Pulse by Ciphera vs Stormly: Sintesi
CaratteristicaLogo: Pulse by CipheraPulse by CipheraLogo: StormlyStormly
Paese di origineBelgiumNetherlands
CategoriaWeb AnalyticsWeb Analytics
Open sourceNo
Self-hostedNoNo
SedeBelgiumNon indicato
Soggetto giuridicoCiphera BVNon indicato
Legge applicabileBelgian law (GDPR); Swiss FADP for infrastructure locationNon indicato
Capogruppo / controllo USANessuna capogruppo USA notaNon indicato
Esposizione CLOUD Act (indicativa)BassoNon indicato
Stato di hosting UEParzialeNon indicato
Hosting / residenzaPrimary compute and object storage on Exoscale in Switzerland (Zurich). Encrypted backups and domain registration via Infomaniak (Switzerland). CDN/DNS/DDoS via Bunny (Slovenia HQ, global edge for transient IPs). Payments via Mollie (Netherlands). GitHub (US) for public source code only, per Trust page.Non indicato
Riassunto

Cookie-free web analytics with traffic, funnels, uptime and Lighthouse checks in one Belgian-operated, Swiss-hosted dashboard.

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

Tag
A colpo d'occhio: Pulse by Ciphera vs Stormly
A colpo d'occhioLogo: Pulse by CipheraPulse by CipheraLogo: StormlyStormly
HQDiegem, Belgium (Ciphera BV)Non indicato
Legal entityCiphera BV (KBO/BCE 1013.721.660)Non indicato
Founded18 September 2024 (CBE)Non indicato
Primary data regionSwitzerland (Exoscale Zurich)Non indicato
LicenseAGPL-3.0 client; managed backend closedNon indicato
Commercial modelFree Hobby tier; paid plans by traffic scaleNon indicato
CookielessYes (vendor claim: no cookies, no fingerprinting)Non indicato
Data residency regionsSwitzerland (Exoscale primary; Infomaniak backups)Non indicato
Key capabilities: Pulse by Ciphera vs Stormly
Key capabilitiesLogo: Pulse by CipheraPulse by CipheraLogo: StormlyStormly
EU-operatedNon indicato
CookielessNon indicato
Open-source clientNon indicato
Swiss-hosted dataNon indicato
No analytics cookiesNon indicato

Pulse by Ciphera

  • Cookieless traffic dashboard

    Pageviews, unique-visitor estimates, referrers, UTM campaigns, device or browser splits, and country-level geo from a single script tag, without cookies or fingerprinting according to Ciphera's privacy docs.

  • Journeys and conversion funnels

    Step-by-step path columns and multi-step funnels with drop-off analysis, filterable by page, country, device, or referrer for privacy-preserving conversion debugging.

  • Uptime monitors with alert routes

    Built-in uptime checks with downtime and recovery alerts to email, Slack, Discord, or a webhook, so availability sits beside traffic in one console.

  • Daily Lighthouse and Core Web Vitals

    Scheduled mobile and desktop Lighthouse runs with performance, accessibility, best-practices, SEO scores, and Core Web Vitals trends without a separate RUM product.

  • Inspectable AGPL client and read API

    Dashboard and tracking script are AGPL-3.0 on GitHub; Ciphera also documents a public read API, CLI, and export paths while keeping the managed backend closed.

Stormly

  • No-Code Event Tracking

    Setup eventi senza developer pesante; autotrack opzioni base.

  • Funnels, Retention, and Cohorts

    Analisi conversione, churn, cohort behavior per product managers.

  • GDPR-Ready EU Hosting

    Dati UE; DPA; configurazione minimizzazione PII.

Assurance & compliance: Pulse by Ciphera vs Stormly
Assurance & complianceLogo: Pulse by CipheraPulse by CipheraLogo: StormlyStormly
Independent security / no-logs audit
Not found

Trust page states no independent audit yet; Tessera self-audit published; independent audit planned.

Non indicato
ISO 27001
Not found

Ciphera explicitly states it holds no ISO 27001 certification.

Non indicato
SOC 2 / SOC 3
Not found

Ciphera explicitly states it holds no SOC 2 certification.

Non indicato
GDPR / EU data protection
Vendor claimed

Belgian controller; privacy policy describes GDPR/FADP bases and Pulse processor role. Not legal advice.

Non indicato
US CLOUD Act exposure (indicative)
Partial

EU (Belgian) entity with no known US parent; primary hosts are European (Exoscale, Infomaniak, Bunny, Mollie). Residual paths: GitHub (US) for source code only; Bunny global edge for transient IPs. Indicative only, not legal advice.

Non indicato
Data processing agreement (B2B)
On request / NDA

Privacy policy: DPA available on request at privacy@ciphera.net for Pulse processor relationships.

Non indicato
EU AI Act
Not applicable

Web analytics product; not an AI system product page.

Non indicato
Considerations & known limitations: Pulse by Ciphera vs Stormly
Considerations & known limitationsLogo: Pulse by CipheraPulse by CipheraLogo: StormlyStormly
Managed backend is not open source
Medium

You can audit the browser script and dashboard code, but not the operated ingestion and storage service. Procurement that requires full-stack self-host or full server auditability should look elsewhere.

Non indicato
No ISO/SOC or independent audit yet
Medium

Ciphera publishes threat models, a warrant canary, and a subprocessor list, but explicitly has no ISO 27001 or SOC 2 and no completed independent audit. Enterprise security reviews will need questionnaires and a signed DPA.

Non indicato
Primary data residency is Switzerland, not EU/EEA
Low

Swiss adequacy covers many GDPR transfer questions, but policies that hard-require EU/EEA datacenter soil will classify this as partial rather than EU-hosted.

Non indicato
Marketing vs privacy wording conflicts
Low

Product FAQ pages disagree on whether custom events ship today and whether a DPA is needed. Prefer privacy@ and the privacy policy for legal commitments until Ciphera aligns the FAQs.

Non indicato

Idoneità

Pulse by Ciphera

Best fit when

  • EU or Swiss organisations replacing GA4 primarily to remove analytics cookies and consent-banner friction
  • Teams that want traffic, funnels, uptime, and Lighthouse scores in one vendor console
  • Buyers who need a Belgian legal entity and named European subprocessors rather than a US cookieless SaaS
  • Sites that can work with aggregate and month-scoped visitor estimates instead of persistent user IDs
  • Engineering leads who want the browser script and dashboard code on GitHub under AGPL-3.0 for inspection

Poor fit when

  • Organisations that must self-host the full analytics backend (Pulse's managed core is closed)
  • Product analytics use cases that need durable cross-visit identity, cohorting, or GA4 BigQuery-style user exports
  • Buyers requiring completed ISO 27001, SOC 2, or a published independent security audit today
  • Teams that need EU/EEA soil specifically rather than Swiss residency (primary data is in Switzerland)

Consider instead when

  • When: You need a mature EU cookieless analytics product with an official full-stack self-host option

    Consider: Plausible Analytics

    Plausible (Estonia) is the common self-host plus SaaS peer; Pulse keeps the backend managed-only.

  • When: You want a minimal Dutch cookieless counter without uptime or Lighthouse bundles

    Consider: Simple Analytics

    Closer peer for strictly analytics SaaS; Pulse differentiates with ops-style panels.

  • When: You need enterprise analytics with strong EU residency controls and heavier compliance packaging

    Consider: Piwik PRO or Friendly Analytics

    Heavier Matomo-class or Swiss-hosted peers when Pulse's startup assurance set is too thin.

Stormly

Best fit when

Non indicato

Poor fit when

Non indicato

Open questions for due diligence

Pulse by Ciphera

  • Will Ciphera sign your standard DPA and return the full registered-address subprocessor appendix on request?
  • What is the retention and deletion SLA for a single customer's Pulse project data after contract end?
  • When is the planned independent security audit scheduled, and will the report be public?
  • Are Google Search Console, Bing, or CDN analytics panels generally available, or only mentioned in some marketing copy?

Stormly

Non indicato