Security & Privacy

    Privacy-first analytics built for modern teams. Respect user privacy while getting the insights you need to grow.

    SOC2 Type I
    EU/US Residency
    Cookieless

    Privacy-First Architecture

    First-party, cookieless tracking with PII minimization. User data never leaves your control.

    End-to-End Encryption

    All data encrypted at rest and in transit using AES-256. Keys managed separately from data.

    Data Residency Choice

    Choose EU or US data residency. Your data stays in your preferred region, always.

    Zero Third-Party Cookies

    Completely cookieless option available. Respect user privacy without sacrificing insights.

    Privacy-First Architecture

    Built from the ground up to respect user privacy while delivering actionable insights.

    First-Party Data

    • Server-side verification

      All events verified server-side with JWT tokens

    • Identity stitching

      Connect user journeys without compromising privacy

    • PII minimization

      Hash sensitive fields at collection time

    Cookieless Option

    • No third-party cookies

      Optional first-party storage only

    • Session-based tracking

      Respect browser privacy settings

    • GDPR by design

      Built-in consent management

    Compliance & Certifications

    Meeting the highest standards for data protection and security.

    GDPR & CCPA Ready

    Built-in data subject rights automation and privacy controls

    SOC2 Type II

    Currently Type I certified, Type II completion Q1 2026

    HIPAA Compliance

    Enterprise

    Available on Enterprise plans with BAA signing

    Data Processing Agreements

    Signed DPAs available for Growth plans and above

    Technical Security

    Enterprise-grade security controls and monitoring.

    Field-level hashing for sensitive data
    IP address truncation by default
    Configurable data retention policies
    Audit logs for all administrative actions
    Role-based access controls (RBAC)
    SAML SSO with popular identity providers
    API key rotation and management
    Network isolation in dedicated VPCs

    Choose Your Data Region

    Available on Pro plans and above. Your data stays where you want it.

    πŸ‡ͺπŸ‡Ί

    European Union

    Hosted in Frankfurt, Germany
    GDPR compliant by default

    πŸ‡ΊπŸ‡Έ

    United States

    Hosted in Virginia, USA
    SOC2 Type II certified

    Security Reviews & DPAs

    Need a security review, DPA, or have compliance questions? Our security team is here to help.

    Request security review

    security@lonryo.com β€’ Response within 24 hours