Security & Compliance
Trust, engineered into every session
Mouseflow protects the visitors your customers trust you with — through data isolation, privacy-first defaults, and controls that are independently tested. The full picture lives in our Trust Center.
Privacy by design
Collect less, by default
Keystrokes in form fields are masked automatically. Customers extend that to any element on the page, keeping personal data out of Mouseflow before it ever reaches us.
Data protection
Isolated, encrypted, region-locked
EU account data is stored in EU infrastructure and US account data is stored in US infrastructure. TLS in transit, encryption at rest, and independently audited security controls protect every account.
Testing & response
Measured, not assumed
Continuous monitoring, regular vulnerability scans, annual third-party penetration testing, and a documented incident-response and business-continuity program reviewed each year.
Certifications and frameworks
Live status, scope, and reports are maintained on the Trust Center — accessible on request under NDA.
SOC 2 Type II Engagement Letter
ISO 27001 Certified GCP Infrastructure
PCI DSS Certified Payment Vendors
GDPR & EU-US DPF
CCPA / CPRA
HIPAA (US region)
Everything a security review needs, in one place
Controls, sub-processor list, DPA, and information security policy — all accessible in the Trust Center under NDA.
Open the Trust CenterEnterprise-level Security
Need something specific?
Enterprise plans layer on additional security controls — SSO, enforced 2FA, and more. Commercial terms are open to discussion, with room for a Business Associate Agreement or a DORA addendum where the industry requires one.
Book a demoResponsible disclosure
Found something? Report it to security@mouseflow.com and we’ll take it from there. Read about our Responsible Vulnerability Disclosure Program here.