Security & Privacy Standards
Metrivo is built to minimize data collection and keep evidence scoped to the website and workspace that supplied it. Privacy and consent requirements still depend on your use case and jurisdiction.
Privacy-Friendly Web Tracking
Our embedded website tracker respects user choices and offers simple opt-out flags for your team and staging domains. It is separate from analytics used on Metrivo's own app and website.
Cryptographic Data Protections
We apply industry-standard security steps to sensitive customer identities and credential records.
Webhook Integrity
To prevent spoofing or replay attacks, Metrivo requires webhook payloads to be signed by the originating payment gateway (Stripe, Razorpay, or Dodo).
Signature Verification
When configuring webhook secrets, Metrivo validates the headers against each provider's cryptographic signing specifications. Any webhook containing an invalid or missing signature is immediately rejected with a `400 Bad Request` or `401 Unauthorized` status.
