Trust center

Everything a security review asks for, in one place, with the uncomfortable parts left in.

The short version

rtcStats analyzes WebRTC statistics, not media. We never receive the audio or video of a call, only numbers about it.

The collection layer is open source and self-hostable. If you do not want your session data on our servers, run the collector yourself and send us only what you choose. That path is free and it is not a downgrade.

We are not SOC 2 or ISO 27001 certified, and we say so on the compliance page rather than burying it.

Security

TLS on every connection, encrypted database backups, per-account application tokens you can revoke at any time, and a documented disclosure route.

Privacy

What we collect and why, when we access or disclose it, your rights over it, and what happens when you delete content.

Compliance and sub-processors

The vendor-review answers: what we hold, where it lives, how long we keep it, who processes it on our behalf, and which certifications we do and do not have.

Availability

The changelog of what actually shipped and when. A dedicated status page is being built and will live at status.rtcstats.com; until it is up we do not publish uptime, because we would rather show nothing than a number we do not measure.

API lifecycle

How we version the API, what we consider a breaking change, and the notice you get before anything is removed.

Commercial terms

Plans, what a credit buys, and the terms you are agreeing to.

For machines

The same facts, published so an agent or a procurement tool can read them without scraping this page.

Something here does not answer your question?

Ask us directly