Security
How MetriXs protects your data and the service.
Encryption in transit
TLS everywhere, HSTS enforced
All traffic is served over TLS (Let’s Encrypt). HSTS is enabled with includeSubDomains and preload. No plaintext connections are accepted.
Authentication & access control
Passwords
Securely hashed. Passwords are never stored or logged in plaintext.
Time-limited tokens
Session and reset tokens are time-limited and expire automatically.
Secrets management
All secrets are environment-bound and enforced in production. No secrets are stored in the codebase.
Abuse & attack prevention
Bot detection
Known bots, scrapers, and abuse patterns are filtered out before they reach your analytics.
Rate limiting
Incoming traffic is rate-limited to cap flood attacks before they reach the database.
Input validation
Every request is strictly schema-validated and size-limited. Abnormal or malformed payloads are rejected.
Network firewall
A host-level firewall restricts incoming traffic to only what the service needs. Administrative access is tightly controlled and authenticated.
Backups & disaster recovery
Daily off-site backups
Databases are backed up daily to off-site storage in the EU, with tested recovery procedures in place.
Infrastructure
Hosted in the EU
MetriXs runs on Hetzner infrastructure in Germany. No CDN or US provider sits in the visitor traffic path. See Subprocessors for the full list of providers.
Reporting a vulnerability
If you believe you’ve found a security issue, please email info@metrixs.eu with details. We acknowledge reports promptly and work with researchers to resolve issues. Please do not publicly disclose a vulnerability before it has been fixed.
Last updated: July 2026