Compliance, Data Privacy and Security

🛡️ GermainUX Overview

GermainUX provides enterprise-grade deployment, privacy, and access-control options designed to support the security and compliance requirements of regulated organizations, including healthcare and financial-services companies.

Organizations can choose how GermainUX is deployed, what information it collects, how sensitive data is protected, who can access collected data, and whether Germain Software personnel can access the platform for support.

Download the Compliance, Security, and Privacy Overview.

✅ Compliance Program and Certifications

Germain Software maintains policies, controls, audits, and operational processes designed to support recognized security frameworks and client-specific regulatory requirements.

The compliance program includes:

Program item

Independent assessments and certifications

Security and privacy policies

Internal control monitoring

Risk-management processes

Audit documentation

Ongoing compliance reviews

See Certifications and Policies for current certification status, available reports, and security-policy information.

🔒 Privacy Capabilities

GermainUX provides complementary controls for managing sensitive information throughout the monitoring lifecycle.

Capability

Purpose

Cookie-consent integration

Coordinates Real User Monitoring with an organization’s approved Cookie Consent Management Platform.

Masking

Hides sensitive values while optionally preserving their structure.

Anonymization

Replaces original values with hashed representations that support analysis without exposing the source content.

Exclusion

Prevents selected information from being collected, transmitted, or stored.

AI-driven PII detection

Identifies fields that may contain personal or sensitive information and flags them for review.

Form Privacy

Protects user-entered form values from appearing in Session Replay recordings.

See:

Topic

Link

Cookie Consent and User Privacy

Cookie Consent and User Privacy

Data Privacy

Data Privacy

These capabilities support an organization’s privacy and compliance program but should be configured and reviewed according to its specific legal, regulatory, security, and data-retention requirements.

👀 Data Security and Visibility

GermainUX provides dynamic access controls that determine which users and teams can view dashboards, facts, and Session Replay recordings.

Access can be controlled according to:

Control

User role

GermainUX team

Dashboard

Data type

Application

Transaction context

Business-specific visibility rules

Custom logic can assign access metadata as data is collected, enabling context-aware restrictions at the Session Replay or individual-fact level.

See Data Security for configuration details.

🔑 Authentication and Access Control

GermainUX can integrate with an organization’s identity and access-management environment.

Supported controls include:

Control

Description

Enterprise authentication

Integration with supported organizational authentication systems, including LDAP-based environments.

Multi-factor authentication

Additional authentication through supported email, SMS, authenticator, or identity-provider mechanisms.

Role- and team-based access

Permissions based on assigned roles and GermainUX teams.

Dashboard permissions

Controls which dashboards a user can access.

Data-type permissions

Restricts access to selected types of monitored data.

IP restrictions

Limits access according to approved network addresses or ranges.

We recommend integrating GermainUX with the organization’s approved authentication system to centralize account management, password policies, access revocation, and authentication controls.

🛰 Deployment Options

Organizations can select the deployment model that best aligns with their infrastructure and security requirements.

Deployment model

Description

Client-hosted

GermainUX is deployed in the organization’s cloud environment or on-premises data center.

Germain-hosted

GermainUX runs in a dedicated client instance with a dedicated data store in the Germain-managed cloud environment.

🔧 Germain Support-Access Levels

Organizations control whether Germain Software personnel can access the deployed platform or its data for support and optimization.

Access level

Germain Software access

Strict Safety Clearance

No access to the GermainUX platform or collected data. The organization operates in full-isolation mode.

Medium Safety Clearance

Access is limited to software components and binaries. Germain Software cannot access business data.

Low Safety Clearance

Authorized access to software components and relevant business data can be provided for proactive support and optimization.

These settings are configurable and can be changed as the organization’s operational, security, and support requirements evolve.

Access should always follow the organization’s authorization, confidentiality, and change-management policies.

📖 Detailed Documentation

Topic

Documentation

Certifications and policies

Certifications and Policies

Cookie consent

Cookie Consent and User Privacy

Data privacy controls

Data Privacy

Data visibility and access rules

Data Security


Service: Management

Feature Availability: 2021.2 or later