Encrypted end to end
TLS 1.3 in transit with HSTS preload, AES-256 at rest on every volume and backup. Keys are managed in a hardware security module and rotated every 90 days.
Security
We hold product analytics data, which means we hold behavioural data about your customers. Here is exactly what we do with it, and what we let you verify.
Six practices that matter more than a badge.
TLS 1.3 in transit with HSTS preload, AES-256 at rest on every volume and backup. Keys are managed in a hardware security module and rotated every 90 days.
Properties you mark sensitive are hashed or dropped before they reach storage. We also scan for email, card and token patterns and quarantine matches automatically.
EU workspaces are processed and stored entirely in Frankfurt; US workspaces in Virginia. Nothing crosses regions, including backups, logs and support tooling.
No standing production access. Engineers request time-boxed, approved, fully logged sessions, and customer data access outside an open ticket raises an alert.
Third-party penetration test twice a year, continuous dependency and container scanning, and a 24/7 on-call rotation with a 15-minute acknowledgement target.
Background checks on hire, mandatory security training twice a year, hardware keys for every employee, and managed devices with enforced disk encryption.
The full list, kept current. We give 30 days' notice before adding one, and you can subscribe to that notice.
| Provider | Purpose | Location | Data |
|---|---|---|---|
| Amazon Web Services | Primary hosting and storage | eu-central-1, us-east-1 | All customer data |
| Cloudflare | CDN, WAF and edge ingest | Global, regionally pinned | Event payloads in transit |
| Stripe | Billing and payments | US, EU | Billing contacts only |
| Postmark | Transactional email | US | Email addresses |
| Zendesk | Support ticketing | EU | Support correspondence |
| Datadog | Infrastructure monitoring | EU | Operational metrics, no event bodies |
Disclosure
Report to security@cadence.dev, encrypted with the PGP key published at /.well-known/security.txt. We acknowledge within one business day and aim to have a fix or a mitigation plan within ten.
Yes on Business and Enterprise. Our standard DPA includes the 2021 SCCs and a UK addendum, and we'll review redlines. On Free and Team the standard DPA applies as written.
No. The plain-English query feature translates your question into SQL using the schema of your workspace — event names and property names only. No event values, no user records, and nothing is used to train a shared model.
Encrypted snapshots for 35 days, in the same region as the primary data. Deleting a workspace removes it from primary storage immediately and from backups within 35 days.
RTO four hours, RPO fifteen minutes, verified in a quarterly restore drill. The drill result is included in the annual SOC 2 report.
Not the full product. Enterprise customers can run ingest inside their own VPC so raw payloads never leave their network, with only aggregated results forwarded to Cadence.
Call DELETE /v1/users/{id} or use the workspace UI. Records are removed from primary storage within 24 hours and from backups within 35 days, and you get a completion receipt for your own records.
Get started
Free for 30 days on the full product. Five-minute install, no card, no onboarding call unless you want one.