Server-side tagging solves part of the problem. Events leave the browser via your subdomain instead of the vendor’s domain. So far, so good.
But most server-side platforms then route those events through the vendor’s own multi-tenant SaaS infrastructure. Your customer data lands in their cloud account. Their certifications cover it. Their data residency rules apply. Their incident response plan is the one your security team has to trust at three in the morning.
Datafly Signal is customer-hosted by design. Signal deploys into your AWS, GCP, or Azure account using Helm charts and Kubernetes — or onto a virtual server using Docker Compose if a full Kubernetes deployment is more than your team needs. Your customer data never touches Datafly-controlled infrastructure. The certifications that already cover your cloud environment — SOC 2, ISO 27001, PCI-DSS, HIPAA, FedRAMP where applicable — apply to Signal because Signal runs inside that boundary.
This is the distinction that matters in every procurement, security, and legal conversation. Not server-side. Customer-hosted, server-side.