CookieInspector
Security
Last updated: September 29, 2026
How we protect the data you trust us with, which providers handle it, and what we do not have yet.
Certifications
CookieInspector is not SOC 2 or ISO 27001 certified. We are a small team and have not been through an external audit. This page describes the controls we do have, and we answer security questionnaires: write to support@cookieinspector.com.
How we protect your data
- Where your data lives
- The application, its database and its file storage run on Microsoft Azure in the United States (East US, Virginia). Scans run from the location you choose for each one: US East (Virginia), US West (California) or Germany (Frankfurt).
- What a scan touches
- The scanner visits the public pages of a website the way a first-time visitor does. It needs no installation, no login and no access to your servers, and it cannot see anything behind a sign-in. What it keeps is what any visitor could observe: cookies, network requests, the consent banner and screenshots of the page.
- Encryption
- All traffic to CookieInspector is encrypted with TLS, and the site tells browsers to accept nothing else (HSTS, on the browser preload list). The database is encrypted at rest with AES-256, and files such as screenshots and PDF reports are encrypted at rest by Azure Storage.
- Accounts and access
- Passwords are stored only as salted PBKDF2 hashes. Session refresh tokens and API tokens are stored as hashes too, so a copy of the database would not let anyone sign in as you. Every report request is checked against the account, or the agency team, that owns the scan; a report is only visible to others if you create a share link for it. Only the founder has access to production systems.
- Backups
- The database can be restored to any point in the last 7 days. Weekly backups are kept for 4 weeks and monthly backups for 12 months.
- Payments
- Payments are handled by Stripe. Card numbers go to Stripe directly and never reach our servers.
- Deleting your account
- Ask us and we delete your account together with its scans, reports, screenshots, exported files and How to fix guides. We keep billing records, as tax rules require. Deleted data can remain inside encrypted database backups until those backups expire, at most 12 months later, and is not restored from them into the service.
Subprocessors
These providers process data on our behalf to run the service. We do not sell personal data to anyone.
| Provider | What it does for us | Where |
|---|---|---|
| Microsoft Azure | Hosting, database, file storage, scan workers, and Azure OpenAI, which writes the How to fix guide from the scan results | United States; Germany for scans run from Frankfurt |
| Stripe | Payments and invoices | United States |
| Resend | Account and report emails | United States |
| HostGator | Support mailbox | United States |
| Better Stack | Application logs | European Union |
| Sign in with Google (optional), reCAPTCHA on sign-up, and analytics and advertising measurement on our website, only after you accept cookies | United States |
If your organization needs a data processing agreement, email us and we will work one out with you.
Report a vulnerability
If you find a security problem in CookieInspector, email support@cookieinspector.com with “Security” in the subject. Include what you found and how to reproduce it. We read every report and will tell you what we do about it. Please do not access other customers' data or disrupt the service while testing.
Related
How we use personal data is in our privacy policy, and California residents' rights are in our California privacy notice.