Privacy-first analytics. Your data stays yours.
Privacy by design, not by configuration
Built for organizations with demanding security and privacy requirements
From regulated industries to organizations with strict internal security requirements, Countly gives teams the flexibility to understand users while retaining control over their data.
Security, privacy & compliance
Frequently asked questions
Can Countly be self-hosted?
Yes. Countly Enterprise can be deployed on-premise or within infrastructure controlled by your organization. Countly also offers private-cloud deployment options.
Does Countly have access to our data?
With a self-hosted deployment, customer data remains within the customer’s infrastructure and Countly does not have access unless explicitly granted. Access in other deployment models depends on the agreed setup and permissions.
Where can Countly data be hosted?
Data location depends on your deployment model. Self-hosted customers determine where their infrastructure and data reside, while private-cloud options can support organizational data-residency requirements.
Which security and compliance standards does Countly support?
Countly maintains ISO 27001, ISO 27017 and ISO 27018 certifications, undergoes SOC 2 Type II examinations, and supports organizations working with requirements including GDPR and HIPAA. Detailed security and compliance information is available in the Countly Trust Center.
Is Countly a TISAX® Participant?
Yes. Countly Ltd. a TISAX® Participant. TISAX is commonly used for information-security assessments across the automotive industry.
Does Countly support HIPAA requirements?
Countly can support organizations with HIPAA-related privacy and security requirements, particularly through deployment control, access management, and data-governance capabilities. Whether a specific implementation is HIPAA compliant depends on how Countly is deployed, configured, and used within the organization.
How does Countly support GDPR?
Countly provides privacy-focused capabilities such as first-party data collection, deployment control, consent management, access controls, and data-governance features that can help organizations meet GDPR requirements. Compliance ultimately depends on each organization’s implementation and use of the platform.