Trust center

Security at GetCookies

GetCookies stores consent records and account data for the websites that use it. This page lists the security controls we actually run in production. If a control is not listed here, we do not claim it. GetCookies holds no SOC 2 or ISO 27001 certification today.

Where your data lives

Customer data is hosted on Railway, a US-based infrastructure provider. Cloudflare sits in front of getcookies.co for DNS, edge filtering and DDoS mitigation. International transfers are covered by data processing agreements with Standard Contractual Clauses, in line with GDPR Chapter V.

The full list of providers, their purpose and location is on the subprocessors page. Our processor terms are in the Data Processing Addendum.

Encryption

  • In transit

    All traffic to getcookies.co and app.getcookies.co is served over HTTPS. HSTS is enabled with a two-year max-age, includeSubDomains and preload, and plain HTTP is upgraded automatically.

  • At rest

    Our PostgreSQL and Redis instances run on Railway, which encrypts data at rest at the infrastructure level. Managed backups inherit the same encryption.

  • Passwords

    Passwords are hashed with bcrypt and never stored in plaintext.

  • API keys

    API keys are stored as SHA-256 hashes. The plaintext key is shown once, when you create it.

Infrastructure and application security

  • Private networking

    The database and cache are not exposed to the public internet. Only the application reaches them over Railway's internal network.

  • Separate environments

    Production and development run as separate services with separate credentials.

  • Rate limiting

    Authentication and public API endpoints are rate-limited with Redis to slow down brute-force and abuse.

  • Input validation

    Request payloads are validated against strict schemas before they reach business logic, and database access goes through an ORM with parameterized queries.

  • Output sanitization

    User-supplied HTML, such as blog content, is sanitized with DOMPurify before it is rendered.

  • Security headers

    Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and HSTS are set on responses.

Authentication and access control

  • Multi-factor authentication

    Every account can enable TOTP-based MFA with Google Authenticator, Authy or a compatible app.

  • Passwordless sign-in

    Optional single-use magic links sent by email.

  • Bearer-token sessions

    The dashboard authenticates with JWT bearer tokens instead of ambient session cookies, which removes a class of CSRF exposure.

  • Organization isolation

    Domains, consent logs and API keys belong to one organization. Roles (owner, admin, editor, viewer) control what each teammate can do.

  • Audit log

    Sensitive account and configuration changes are recorded so you can see who changed what, and when.

  • Signed webhooks

    Outbound webhooks are signed with HMAC-SHA256 so you can verify they came from GetCookies.

  • No single sign-on

    SSO (SAML or OpenID Connect) is not available on any plan today. Accounts sign in with a password, a magic link or Google, optionally with TOTP MFA.

Vulnerability management and incidents

Dependabot monitors our dependencies for known vulnerabilities and opens update pull requests. Changes are reviewed before they reach production.

If a personal data breach affects you, we notify you without undue delay and, where GDPR Article 33 requires it, within 72 hours.

Responsible disclosure

Report vulnerabilities to [email protected]. Our contact is also published in /.well-known/security.txt in the RFC 9116 format. Please include reproduction steps and the potential impact.

Security reviews and questionnaires

Need answers for a vendor assessment or a security questionnaire? Email [email protected] with the questionnaire attached and we will fill it in. We only answer with what is on this page and in our DPA; we will tell you plainly when a control is not in place.

Aufbewahrungsdauer

Consent-Protokolle sind Ihr Nachweis der Einwilligung. Jedes Protokoll wird für einen festen Zeitraum aufbewahrt, der vom Tarif des Kontos abhängt, dem die Website gehört. Danach löscht ein Hintergrundjob es automatisch:

  • Free: 1 Jahr nach Erstellung des Protokolls
  • Starter: 1 Jahr nach Erstellung des Protokolls
  • Pro: 3 Jahre nach Erstellung des Protokolls
  • Business: 3 Jahre nach Erstellung des Protokolls
  • Enterprise: wird nie automatisch gelöscht
  • Konten ohne aktives, testweises oder überfälliges Abonnement behalten Consent-Protokolle so lange wie im Free-Tarif.
  • Wechselt ein Konto in einen Tarif mit kürzerer Aufbewahrungsdauer, werden Consent-Protokolle gelöscht, die älter als dieser Zeitraum sind. Exportieren Sie sie vorher, wenn Sie sie behalten müssen.
  • Monatliche Obergrenzen für Consent-Protokolle werden in keinem Tarif durchgesetzt: Für jede Entscheidung eines Besuchers wird unabhängig vom Tarif ein Protokoll gespeichert.

Try GetCookies on your own site

Start on the Free plan: one domain, a cookie scan and a consent banner, no credit card required. Upgrade only when you need more.

Kostenlos starten