EU-owned. EU-hosted. Built for regulated organisations.
Your site's content and scan data never leave the EU. Here's exactly how we handle it.
EU data residency
Your data stays in Europe — end to end.
SitePrimed is operated by ITML, an EU-based company. Your site content and scan results are processed and stored inside the EU. There is no US cloud in the path.
Hosted in the EU
EU regions only. Content and scan data never transit or rest outside the EU.
No US cloud
The whole processing chain is EU-based — no transfer to US-operated infrastructure, no reliance on adequacy workarounds.
EU legal entity
ITML is the data controller/processor of record — an EU-based company (Athens · Limassol · Norwich), contracting under EU law.
Why this matters for public-sector and regulated buyers
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.
EU data residency
What SitePrimed can — and can't — do to your site.
Straight answers to the questions IT and security teams ask.
Why this matters for public-sector and regulated buyers
By default, we read your site to scan it. Applying a fix is a separate, scoped permission you grant — via the WordPress plugin, or (Enterprise) your CMS. It covers only the approved fields (meta titles, descriptions, alt text), never your theme, never arbitrary database access. You can revoke it at any time.
What about Enterprise CMS auto-fix?
Write-back to a CMS (for example Strapi or Drupal) is an explicit, separately-scoped opt-in, set up with our technical team. It is off by default and never bundled with read access — read and write are always separate grants.
Where are credentials handled?
API / CMS connections are provisioned with our team. Tokens are scoped to the minimum required role, encrypted at rest, masked in the UI and revocable — and they are never entered into a public form.
Compliance & standards
Precise about what we comply with.
GDPR
We process personal data in line with the GDPR as an EU-based processor, under a Data Processing Agreement available to every customer.
Data Processing Agreement
A DPA is available on request and forms part of every paid contract, alongside our sub-processor list.
Sub-processors & retention
We publish the sub-processors we rely on and our data-retention policy — how long scan data is kept and when it's deleted.
Helping you meet the EAA
SitePrimed measures your site against WCAG 2.1 AA / EN 301 549 — the standards behind the European Accessibility Act — so you can evidence conformance.
Security practices
How we protect your data day to day.
How we protect your data day to day.
Traffic is encrypted with TLS; stored scan data and credentials are encrypted at rest.
Access controls
Least-privilege access for staff, with team roles (Admin / Editor / Viewer) inside your account.
Audit trail
Fixes applied and connection changes are logged, so you can see who did what and when.
Responsible disclosure
A security contact for reporting vulnerabilities, with a coordinated-disclosure process.
We don't claim certifications we don't hold. If a formal certification (e.g. ISO 27001) is required for your procurement, talk to our team about current status.
Talk to our team
Need our security pack for procurement, a signed DPA, or answers for your IT review? We'll get you what you need.
Run a free audit
See your four-lens health in seconds. Then start free to unlock the full report and your first fixes.
Anonymous · desktop preview · no account needed.