MetricSign
Start free
compliance

Is MetricSign GDPR compliant? Where is customer data hosted?

MetricSign GDPR compliance and data hosting

Where is data hosted?

All MetricSign infrastructure runs on Amazon Web Services in the eu-west-1 region (Ireland). No customer data is processed or stored outside the European Union. There is no fallback to US regions.

What data does MetricSign store?

MetricSign connects to your data tools via their official APIs and reads metadata only. Specifically, MetricSign stores:

  • Pipeline and dataset refresh timestamps (start time, end time)
  • Run durations and latency metrics
  • Error codes and error messages from failed pipeline runs
  • Workspace and pipeline names (for display in the monitoring UI)
  • Connector configuration (OAuth tokens, encrypted at rest)

What MetricSign does NOT store

MetricSign never accesses or stores:

  • Report content or dashboard visuals
  • Query results or data values
  • Rows, columns, or any content from your databases or data warehouses
  • Personal data of your end users or data consumers
  • Credentials or passwords (OAuth tokens are used instead and can be revoked at any time)

This metadata-only approach is fundamental to MetricSign's architecture. Because MetricSign reads pipeline health signals rather than data content, it never becomes a secondary copy of your sensitive data.

GDPR compliance measures

  • Data minimisation: Only the metadata required to detect and diagnose pipeline incidents is collected
  • EU data residency: All storage and processing in AWS eu-west-1 (Ireland)
  • Encryption at rest and in transit: OAuth tokens and configuration data are encrypted at rest; all API communication uses TLS
  • Right to erasure: Customer data can be deleted on request; account deletion removes all associated metadata
  • Data Processing Agreement: A DPA is available on request for customers who require it for their own compliance documentation
  • No sub-processors outside the EU: MetricSign's primary infrastructure sub-processors are AWS EU regions only

SOC 2

MetricSign's SOC 2 Type II audit is currently in progress. If your procurement process requires a SOC 2 report, contact the MetricSign team for an update on the expected availability.

No AI, no model training

MetricSign does not use AI or machine learning to process customer data, and customer metadata is never used to train models. All incident detection is deterministic and rule-based — threshold breaches, failure patterns, and duration anomalies are computed algorithmically.

For security and compliance teams

If you need additional documentation for a vendor assessment — such as a completed security questionnaire, architecture diagram, or sub-processor list — contact MetricSign directly. A DPA can be countersigned as part of the onboarding process.

Related questions

← All questions