Trust center
Security at Privatus Analytics
The best protection for visitor data is not having it. We minimize first, then protect what remains. Here is how.
Architecture
Visitor IPs and user agents are processed in memory only and never stored. The ingest pipeline, application and databases run in one US region.
Encryption
TLS for all traffic (TLS 1.3 preferred), encrypted database connections, and encryption of secrets such as two-factor keys and integration credentials.
Access control
Role-based permissions in every workspace, and support access only with a customer’s time-limited grant.
Resilience
A database read replica, and queued ingestion so accepted events are still processed after an incident.
Secure development
Dependency auditing, static analysis in CI, and secrets kept out of source code.
Account security
Two-factor authentication (TOTP), passkeys, recovery codes, SAML/OIDC SSO on Business, scoped API tokens with IP allowlists, and an audit log.
Certifications
We don’t hold any certifications yet, and we won’t claim one before the report exists. Need our security documentation for a review? Contact us.
Responsible disclosure
If you find a vulnerability, please tell us privately first. We’ll acknowledge your report within 2 business days, keep you updated, and credit you if you wish.
- Report through the contact form (topic: Security). Contact details are also in our security.txt.
- Test only against your own account and data. Don’t access other customers’ data, degrade the service, or use social engineering.
- Give us reasonable time to fix the issue before disclosure.
We won’t take legal action against good-faith research that follows these rules.
Incident response
We keep an incident response plan with an on-call rotation. If a personal data breach affects your data, we’ll notify you within 48 hours of becoming aware of it, faster than the 72 hours the GDPR gives controllers to notify regulators.
Live system health is on our status page.