Trust center
Security at GetCookies
GetCookies stores consent records and account data for the websites that use it. This page lists the security controls we actually run in production. If a control is not listed here, we do not claim it. GetCookies holds no SOC 2 or ISO 27001 certification today.
Where your data lives
Customer data is hosted on Railway, a US-based infrastructure provider. Cloudflare sits in front of getcookies.co for DNS, edge filtering and DDoS mitigation. International transfers are covered by data processing agreements with Standard Contractual Clauses, in line with GDPR Chapter V.
The full list of providers, their purpose and location is on the subprocessors page. Our processor terms are in the Data Processing Addendum.
Encryption
In transit
All traffic to getcookies.co and app.getcookies.co is served over HTTPS. HSTS is enabled with a two-year max-age, includeSubDomains and preload, and plain HTTP is upgraded automatically.
At rest
Our PostgreSQL and Redis instances run on Railway, which encrypts data at rest at the infrastructure level. Managed backups inherit the same encryption.
Passwords
Passwords are hashed with bcrypt and never stored in plaintext.
API keys
API keys are stored as SHA-256 hashes. The plaintext key is shown once, when you create it.
Infrastructure and application security
Private networking
The database and cache are not exposed to the public internet. Only the application reaches them over Railway's internal network.
Separate environments
Production and development run as separate services with separate credentials.
Rate limiting
Authentication and public API endpoints are rate-limited with Redis to slow down brute-force and abuse.
Input validation
Request payloads are validated against strict schemas before they reach business logic, and database access goes through an ORM with parameterized queries.
Output sanitization
User-supplied HTML, such as blog content, is sanitized with DOMPurify before it is rendered.
Security headers
Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and HSTS are set on responses.
Authentication and access control
Multi-factor authentication
Every account can enable TOTP-based MFA with Google Authenticator, Authy or a compatible app.
Passwordless sign-in
Optional single-use magic links sent by email.
Bearer-token sessions
The dashboard authenticates with JWT bearer tokens instead of ambient session cookies, which removes a class of CSRF exposure.
Organization isolation
Domains, consent logs and API keys belong to one organization. Roles (owner, admin, editor, viewer) control what each teammate can do.
Audit log
Sensitive account and configuration changes are recorded so you can see who changed what, and when.
Signed webhooks
Outbound webhooks are signed with HMAC-SHA256 so you can verify they came from GetCookies.
No single sign-on
SSO (SAML or OpenID Connect) is not available on any plan today. Accounts sign in with a password, a magic link or Google, optionally with TOTP MFA.
Vulnerability management and incidents
Dependabot monitors our dependencies for known vulnerabilities and opens update pull requests. Changes are reviewed before they reach production.
If a personal data breach affects you, we notify you without undue delay and, where GDPR Article 33 requires it, within 72 hours.
Responsible disclosure
Report vulnerabilities to [email protected]. Our contact is also published in /.well-known/security.txt in the RFC 9116 format. Please include reproduction steps and the potential impact.
Security reviews and questionnaires
Need answers for a vendor assessment or a security questionnaire? Email [email protected] with the questionnaire attached and we will fill it in. We only answer with what is on this page and in our DPA; we will tell you plainly when a control is not in place.
Bewaartermijn
Toestemmingslogs zijn je bewijs van toestemming. Elke log wordt een vaste periode bewaard die afhangt van het abonnement van het account dat eigenaar is van de website. Daarna verwijdert een achtergrondtaak de log automatisch:
- Free: 1 jaar na het aanmaken van de log
- Starter: 1 jaar na het aanmaken van de log
- Pro: 3 jaar na het aanmaken van de log
- Business: 3 jaar na het aanmaken van de log
- Enterprise: nooit automatisch verwijderd
- Accounts zonder actief abonnement, proefabonnement of achterstallig abonnement bewaren toestemmingslogs even lang als op het Free-abonnement.
- Als een account overstapt naar een abonnement met een kortere bewaartermijn, worden toestemmingslogs die ouder zijn dan die termijn verwijderd. Exporteer ze eerst als je ze moet bewaren.
- Op geen enkel abonnement gelden maandelijkse limieten voor het aantal toestemmingslogs: voor elke keuze van een bezoeker wordt een log opgeslagen, ongeacht het abonnement.
Try GetCookies on your own site
Start on the Free plan: one domain, a cookie scan and a consent banner, no credit card required. Upgrade only when you need more.
Gratis beginnen