Skip to content
SealMetrics

Trust center · security posture

The safest visitor record
is the one you never create.

SealMetrics begins with data minimisation, then applies encryption, isolation and automatic retention to the aggregate evidence that remains.

GDPR by architecture · ePrivacy · Schrems II clean · Dublin, Ireland

Four structural controls

Reduce the attack surface
before securing it.

Security is easier to inspect when each control has a narrow job. The first four remove data and identity paths conventional analytics normally creates.

01

No visitor storage

The measurement pixel writes no cookie, localStorage, sessionStorage or IndexedDB entry to the visitor device.

02

No persisted IP

Visitor IP addresses have no analytics-database column. Any network handling is transient and is not retained as analytics data.

03

Account isolation

Every data path is scoped to an account. Requests are checked against that boundary before analytics records are read.

04

Data minimisation

Reports use aggregate commercial events, without names, emails or identifiers designed to follow a person across websites.

Inspect the data path

One operating boundary.
Four explicit stages.

Visitor measurement and the service databases operate in Dublin, Ireland. Each stage narrows what can proceed to the next one.

01 · Collect

Cookieless event

The browser sends the page or commercial event without writing an identifier to the device.

02 · Validate

Signed request

Domain checks and expiring signed tokens reduce unauthorised event injection.

03 · Aggregate

Account-scoped data

Operational records are separated by account and converted into reporting aggregates.

04 · Expire

Database TTL

Retention is enforced by the data layer instead of relying on a manual deletion calendar.

Technical and organisational measures

Controls a security team
can question directly.

The summary below is aligned with the DPA. When a contractual detail and this page differ, the signed DPA prevails.

ControlApplied measureEvidence boundary
TransportTLS 1.2+Service communications
Data at restAES-256Service databases and encrypted backups
AccessRBAC, MFA and least privilegeUser and administrative access
Customer isolationAccount-scoped keys and query validationAll analytics storage layers
SecretsManaged outside source codePlatform credentials and customer BYOK keys
Administrative activityLogged accessPrivileged service operations

Retention is a control

Fixed periods.
Automatic enforcement.

Analytics retention does not depend on someone remembering to run a deletion process. Database-level TTLs enforce the operating periods.

Data classMaximum operating period
Event-level technical log1 day
Hourly aggregates90 days
Daily aggregates and conversions24 months
Active session state2 hours

Procurement evidence

Claims are useful
only when bounded.

SealMetrics documents the architecture, contractual measures and subprocessors without presenting a certification the company does not hold.

GDPRBy architecture

Data minimisation, purpose restriction and an Article 28 DPA.

ePrivacyCookieless operation

No visitor-device storage is required for measurement.

Schrems IIClean visitor path

Visitor analytics data remains in Dublin, Ireland.

DPAIncluded

Technical and organisational measures and audit rights are documented.

TPSRAvailable

A structured package for technical, privacy and security review.

CertificationsNot claimed

SealMetrics does not currently claim ISO 27001 or SOC 2 certification.

Review the source documents

Move from website claim
to reviewable evidence.

Use the DPA for contractual controls, the privacy policy for processing disclosures and the Trust Center for the wider assurance surface.

Security review

Bring the questions
your approval depends on.

Walk through retention, isolation, the Dublin data boundary and the DPA with the person responsible for the implementation.