CookieInspector

Security

Last updated: September 29, 2026

How we protect the data you trust us with, which providers handle it, and what we do not have yet.

Certifications

CookieInspector is not SOC 2 or ISO 27001 certified. We are a small team and have not been through an external audit. This page describes the controls we do have, and we answer security questionnaires: write to support@cookieinspector.com.

How we protect your data

Where your data lives
The application, its database and its file storage run on Microsoft Azure in the United States (East US, Virginia). Scans run from the location you choose for each one: US East (Virginia), US West (California) or Germany (Frankfurt).
What a scan touches
The scanner visits the public pages of a website the way a first-time visitor does. It needs no installation, no login and no access to your servers, and it cannot see anything behind a sign-in. What it keeps is what any visitor could observe: cookies, network requests, the consent banner and screenshots of the page.
Encryption
All traffic to CookieInspector is encrypted with TLS, and the site tells browsers to accept nothing else (HSTS, on the browser preload list). The database is encrypted at rest with AES-256, and files such as screenshots and PDF reports are encrypted at rest by Azure Storage.
Accounts and access
Passwords are stored only as salted PBKDF2 hashes. Session refresh tokens and API tokens are stored as hashes too, so a copy of the database would not let anyone sign in as you. Every report request is checked against the account, or the agency team, that owns the scan; a report is only visible to others if you create a share link for it. Only the founder has access to production systems.
Backups
The database can be restored to any point in the last 7 days. Weekly backups are kept for 4 weeks and monthly backups for 12 months.
Payments
Payments are handled by Stripe. Card numbers go to Stripe directly and never reach our servers.
Deleting your account
Ask us and we delete your account together with its scans, reports, screenshots, exported files and How to fix guides. We keep billing records, as tax rules require. Deleted data can remain inside encrypted database backups until those backups expire, at most 12 months later, and is not restored from them into the service.

Subprocessors

These providers process data on our behalf to run the service. We do not sell personal data to anyone.

ProviderWhat it does for usWhere
Microsoft AzureHosting, database, file storage, scan workers, and Azure OpenAI, which writes the How to fix guide from the scan resultsUnited States; Germany for scans run from Frankfurt
StripePayments and invoicesUnited States
ResendAccount and report emailsUnited States
HostGatorSupport mailboxUnited States
Better StackApplication logsEuropean Union
GoogleSign in with Google (optional), reCAPTCHA on sign-up, and analytics and advertising measurement on our website, only after you accept cookiesUnited States

If your organization needs a data processing agreement, email us and we will work one out with you.

Report a vulnerability

If you find a security problem in CookieInspector, email support@cookieinspector.com with “Security” in the subject. Include what you found and how to reproduce it. We read every report and will tell you what we do about it. Please do not access other customers' data or disrupt the service while testing.

Related

How we use personal data is in our privacy policy, and California residents' rights are in our California privacy notice.