Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Umami

VERIFIED
Web analytics · United States
Founded 2020 · umami.is ↗

MIT-licensed open-source web analytics (Umami Software Inc., US); EU region on managed cloud, self-host on any EU infrastructure.

Why this score?

Umami Software, Inc. (Delaware C-Corp, San Francisco, USA) maintains the MIT-licensed open-source web-analytics platform with EU (Germany) hosting region available on the managed Umami Cloud tier; vendor-level CLOUD Act exposure is direct (US-incorporated company), but the MIT-licensed self-host path lets EU buyers deploy on EU infrastructure for full sovereignty — score 3/5 reflects the viable self-host path that justifies inclusion despite the US-incorporated cloud vendor.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About Umami

Umami is the open-source web-analytics platform built and maintained by **Umami Software, Inc.** — a Delaware C-Corporation headquartered in San Francisco, USA. The codebase is licensed under the **MIT License** (one of the most permissive open-source licences available) with the full server stack on GitHub, deployable as a single Docker container backed by PostgreSQL or MySQL, or to Vercel / any Node.js-compatible serverless platform in under ten minutes. The product is positioned as the lightweight Google Analytics alternative with no cookies, no personal data collection, and a clean dashboard UX. For an EU-sovereignty audit Umami is in the same structural position as Outline (also US-incorporated): the managed **Umami Cloud** tier has both **US and EU (Germany)** hosting regions and customers can pick at signup, but the operating entity (Umami Software Inc., Delaware/San Francisco) is directly subject to the **US CLOUD Act and FISA Section 702** regardless of which region the customer picks — making the vendor-level CLOUD Act flag `direct` for the managed cloud. The **MIT-licensed self-host edition** is the EU-sovereignty path: deploy on Hetzner / OVHcloud / Scaleway / STACKIT / private EU DC and the customer becomes the sole data controller. The directory includes Umami specifically because the self-host path is well-supported, MIT-permissive, and the operational footprint is small (one container + one database). Pricing on the managed cloud: free tier with limited views/sites; paid tiers from approximately $9/month (~€8) scaling by event volume. Self-host: free under MIT. Best fit: engineering teams that already operate EU infrastructure and want a Plausible-class GA replacement under permissive licensing, or organisations that need the EU-region managed cloud and accept the US-vendor jurisdiction risk. Buyers needing a fully EU-incorporated vendor should prefer Plausible (EE) or Simple Analytics (NL) in the same category.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-11).
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option Yes
PRICING

Pricing & tiers

FREEMIUM
from €9/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternatives in this category