Trust center
Security at GetCookies
GetCookies stores consent records and account data for the websites that use it. This page lists the security controls we actually run in production. If a control is not listed here, we do not claim it. GetCookies holds no SOC 2 or ISO 27001 certification today.
Where your data lives
Customer data is hosted on Railway, a US-based infrastructure provider. Cloudflare sits in front of getcookies.co for DNS, edge filtering and DDoS mitigation. International transfers are covered by data processing agreements with Standard Contractual Clauses, in line with GDPR Chapter V.
The full list of providers, their purpose and location is on the subprocessors page. Our processor terms are in the Data Processing Addendum.
Encryption
In transit
All traffic to getcookies.co and app.getcookies.co is served over HTTPS. HSTS is enabled with a two-year max-age, includeSubDomains and preload, and plain HTTP is upgraded automatically.
At rest
Our PostgreSQL and Redis instances run on Railway, which encrypts data at rest at the infrastructure level. Managed backups inherit the same encryption.
Passwords
Passwords are hashed with bcrypt and never stored in plaintext.
API keys
API keys are stored as SHA-256 hashes. The plaintext key is shown once, when you create it.
Infrastructure and application security
Private networking
The database and cache are not exposed to the public internet. Only the application reaches them over Railway's internal network.
Separate environments
Production and development run as separate services with separate credentials.
Rate limiting
Authentication and public API endpoints are rate-limited with Redis to slow down brute-force and abuse.
Input validation
Request payloads are validated against strict schemas before they reach business logic, and database access goes through an ORM with parameterized queries.
Output sanitization
User-supplied HTML, such as blog content, is sanitized with DOMPurify before it is rendered.
Security headers
Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and HSTS are set on responses.
Authentication and access control
Multi-factor authentication
Every account can enable TOTP-based MFA with Google Authenticator, Authy or a compatible app.
Passwordless sign-in
Optional single-use magic links sent by email.
Bearer-token sessions
The dashboard authenticates with JWT bearer tokens instead of ambient session cookies, which removes a class of CSRF exposure.
Organization isolation
Domains, consent logs and API keys belong to one organization. Roles (owner, admin, editor, viewer) control what each teammate can do.
Audit log
Sensitive account and configuration changes are recorded so you can see who changed what, and when.
Signed webhooks
Outbound webhooks are signed with HMAC-SHA256 so you can verify they came from GetCookies.
No single sign-on
SSO (SAML or OpenID Connect) is not available on any plan today. Accounts sign in with a password, a magic link or Google, optionally with TOTP MFA.
Vulnerability management and incidents
Dependabot monitors our dependencies for known vulnerabilities and opens update pull requests. Changes are reviewed before they reach production.
If a personal data breach affects you, we notify you without undue delay and, where GDPR Article 33 requires it, within 72 hours.
Responsible disclosure
Report vulnerabilities to [email protected]. Our contact is also published in /.well-known/security.txt in the RFC 9116 format. Please include reproduction steps and the potential impact.
Security reviews and questionnaires
Need answers for a vendor assessment or a security questionnaire? Email [email protected] with the questionnaire attached and we will fill it in. We only answer with what is on this page and in our DPA; we will tell you plainly when a control is not in place.
Conservation des données
Les journaux de consentement sont votre preuve de consentement. Chacun est conservé pendant une durée fixe qui dépend de l'offre du compte propriétaire du site, puis une tâche en arrière-plan le supprime automatiquement :
- Free : 1 an après la création de l'enregistrement
- Starter : 1 an après la création de l'enregistrement
- Pro : 3 ans après la création de l'enregistrement
- Business : 3 ans après la création de l'enregistrement
- Enterprise : jamais supprimés automatiquement
- Les comptes sans abonnement actif, en période d'essai ou en retard de paiement conservent les journaux de consentement pendant la durée de l'offre Free.
- Si un compte passe à une offre dont la durée est plus courte, les journaux de consentement plus anciens que cette durée sont supprimés. Exportez-les d'abord si vous devez les conserver.
- Aucune limite mensuelle de volume de journaux de consentement n'est appliquée, quelle que soit l'offre : un enregistrement est stocké pour chaque choix d'un visiteur.
Try GetCookies on your own site
Start on the Free plan: one domain, a cookie scan and a consent banner, no credit card required. Upgrade only when you need more.
Commencer gratuitement