Security

Locked down, minus the theater.

No badge wall, no alphabet soup. Here is what we actually do to protect your data — and, because honesty is the policy, what we will not pretend to.

  1. 01

    Collect almost nothing

    The strongest security posture is having little worth stealing. Page, referrer, country, city and region, browser and device type, your own campaign tags, events you define. No cookies, no fingerprints, no stored IP addresses.

  2. 02

    Hash the secrets

    Dashboard passwords are stored as bcrypt hashes — never readable, never reversible. Login sessions are short-lived signed tokens, and only ever set for your own dashboard.

  3. 03

    Your account is yours alone

    Analytics are visible only to the account that collected them. There is no shared pool, no cross-customer anything, no advertiser access.

  4. 04

    Boring infrastructure

    Tarsier runs on Cloudflare's edge network — the same machinery that absorbs some of the largest attacks on the internet — rather than a server under somebody's desk.

Compliance, honestly

Tarsier is designed for data minimization: no personal identifiers, no cross-site tracking, coarse location (country, city, region — never precise) at most. That posture keeps most obligations small by construction. What we do not have — and will not claim — are formal certifications like SOC 2 or ISO 27001. We are a small operation; our compliance story is the boring, verifiable kind: collect almost nothing, guard what remains. If your organization needs a review or paperwork, reach out via the contact page and we will deal with it like adults.