Piwik PRO Review (2026)
Enterprise GDPR-strict analytics suite — ISO 27001 + SOC 2 Type II + HIPAA BAA, multi-region SaaS, Polish closed-source (forked from Matomo 2016)
Piwik PRO is the only privacy-first analytics vendor in this directory with a signed HIPAA BAA, SOC 2 Type II across all five trust principles, and ISO 27001 in production. That trio matters when you're a hospital, a bank, or a public-sector department where the security questionnaire alone is a 200-row spreadsheet.
Piwik PRO compliance at a glance
GDPR posture, sub-processors under DPA, per-jurisdiction stance, and encryption — everything a procurement team checks.
Per-jurisdiction posture
Sub-processors (10)
GDPR Art. 28 disclosure — third parties under DPA that may receive data.
● Collected
- URLs visited and page titles
- HTTP referrer + UTM parameters
- Browser, OS, device type, screen resolution
- Country / region / city geolocation
- Custom events with properties
- Cookie identifiers (default mode) — disable via Anonymous Tracking Mode
- IP address (default mode, configurable masking)
● Explicitly NOT collected
- (in Anonymous Tracking Mode) cookies, session data, fingerprints
- Default visitor-level PII unless customer enables it
Default 60 months for website analytics. Configurable to 14/25 months on lower tiers. Business plan retains 25 months.
- In transit: HTTPS, dedicated firewalls, cryptographically secure key pairs
- At rest: AES-256 (explicitly stated for HIPAA hosting; standard for all tiers)
How Piwik PRO works with AI agents
Tier 2 — AI add-ons — 2 available + 1 beta. Selective AI footprint vs full suite.
Conversational natural-language interface
Natural-language access via external MCP clients only
Model Context Protocol — Claude / Cursor / Codex
Official PiwikPRO/mcp Python server on GitHub + PyPI — controls Analytics/CDP/Tag Manager via Claude/Cursor Source ↗
Programmatic AI-agent endpoints
Not advertised by vendor
Anomaly detection / hypothesis / summaries
Anomaly-detection experiment opt-in via Settings (recruiting closed but feature exists) Source ↗
Structured export formatted for LLM ingestion
"AI-ready data" structured/timestamped/session-scoped exports formatted for AI pipelines Source ↗
Strengths & weaknesses
What makes Piwik PRO worth a look — and where it falls short.
Strengths 8
- ISO 27001 + SOC 2 Type II (all 5 trust principles) + HIPAA BAA
- Multi-region pinning at provisioning (SE / DE / NL / FR / US / HK)
- Integrated suite — Analytics + Tag Manager + Consent Manager + CDP
- Healthcare-credible — Boston Children's, Rochester Regional, Children's Nebraska as named customers
- On-premises deployment available (Docker / Kubernetes)
- GA4-shaped UX — low migration cost for analysts
- Three configurable privacy modes (cookies / no-cookies-with-session / fully anonymous)
- Multi-language support (English / Polish / German / French)
Weaknesses 6
- Closed-source — not auditable like Matomo
- No free tier as of 2025 (Core plan discontinued)
- Heavy ~86 KB gzipped tracker (3-4× Plausible)
- Default mode requires consent banner (Anonymous Mode is a downgrade)
- Pricing opacity at Enterprise — three of four tiers are "contact sales"
- DNT signal not addressed publicly by vendor
Feature matrix
All 38 verified checks across 4 categories. Hover any row for the editor's note.
Tracking & Reporting 15
- Pageviews & visitors ✓Yes
- Live visitor count ✓Yes
- Top pages report ✓Yes
- Top referrers ✓Yes
- UTM campaign tracking ✓Yes
- Country & city breakdown ✓Yes
- Device, browser, OS ✓Yes
- Bounce / engagement ✓Yes
- Time on site ✓Yes
- Custom events ✓Yes
- Goals / conversions ✓Yes
- Funnels ✓Yes
- Outbound link tracking ✓Yes
- File download tracking ✓Yes
- 404 / error tracking ✓Yes
Privacy & Compliance 9
- Cookieless by default ~Partial
- No personal data collected ~Partial
- GDPR-compliant out of the box ~Partial
- Data hosted in EU ✓Yes
- Data hosted in US ✓Yes
- Self-hostable ~Partial
- Open source —No
- Data retention period 60
- Bot & spam filtering ✓Yes
Setup & Integrations 10
- Script weight (KB) 86
- Single-snippet install ✓Yes
- WordPress plugin ✓Yes
- Proxy / first-party domain ✓Yes
- Public API ✓Yes
- Data export (CSV/JSON) ✓Yes
- Google Search Console connector ~Partial
- Email digests ✓Yes
- Slack / webhook alerts ✓Yes
- Public shareable dashboard ✓Yes
Pricing & Plans 4
- Free tier exists —No
- Entry price ($/mo) $38/mo
- Price at 100k pageviews $38/mo
- Unlimited sites on entry plan ~Partial
Piwik PRO vs alternatives
How it compares to the closest 3 rivals on key buyer-decision fields.
Matomo
Open-source self-hosted analytics, formerly Piwik
- From$29/mo
- HostingSelf-host ✓
- EU-hostedYes
- Cookieless—
Pirsch
Cookieless EU-hosted analytics built in Germany, with open-source AGPLv3 core
- From$6/mo
- HostingSaaS only
- EU-hostedYes
- CookielessYes
Plausible
Privacy-first GA alternative, EU-hosted, simple dashboard
- From$9/mo
- HostingSelf-host ✓
- EU-hostedYes
- CookielessYes
Compare Piwik PRO against
Side-by-side comparisons with other tools in the directory.
Pricing tiers
Real plans, real numbers — pulled from piwik.pro (verified May 2026).
Trial/30 days
Full Business access
- ✓ No card required
$38/mo
up to 2M actions
- ✓ EU-only Sweden (Elastx)
- ✓ 25-month retention
- ✓ DPA included
- ✓ SOC 2 NOT included
- ✓ HIPAA NOT supported
$396/mo
1M-100M actions
- ✓ Multi-region
- ✓ SOC 2 included
- ✓ HIPAA NOT supported
- ✓ Annual contract
Custom
1M-500M actions
- ✓ SOC 2 included
- ✓ HIPAA BAA supported
- ✓ Multi-region
- ✓ CDP unlocked
- ✓ Contact sales
Custom
2M+ unlimited
- ✓ Private cloud
- ✓ SOC 2 + BAA
- ✓ 60+ regions
- ✓ Custom SLA
- ✓ Contact sales
Tech specs
Stack, repo health, deployment options — for engineers evaluating self-host.
Stack
- Written inClosed-source (no public stack disclosure)
- HostingMicrosoft Azure (multi-region) · Elastx SE · Orange Flexible Engine FR
- CDNNot disclosed
- Tag layerBuilt-in Tag Manager + Consent Manager + CDP
- LicenseCommercial (closed-source SaaS / on-premises)
- Min specsOn-premises specs per quote
GitHub github.com/PiwikPRO
- Stars★ 0
- Forks0
- Open issues0
- Last commit—
Deploy
- · Cloud SaaS (multi-region pinning)
- · On-premises Analytics Suite (Docker / Kubernetes, commercial agreement)
Used by
Companies and projects that publicly trust Piwik PRO.
Editor review
Independently reviewed by Mark Sutton, cross-checked against vendor documentation. Click any panel to expand.
+ What it does well
Piwik PRO is the only privacy-first analytics vendor in this directory with a signed HIPAA BAA, SOC 2 Type II across all five trust principles, and ISO 27001 in production. That trio matters when you're a hospital, a bank, or a public-sector department where the security questionnaire alone is a 200-row spreadsheet.
Official MCP server published on GitHub + PyPI (PiwikPRO/mcp) — controls Analytics, CDP, and Tag Manager via Claude or Cursor with natural-language queries. Plus a dedicated "AI-ready data" export pipeline (piwik.pro/ai-ready-data) that ships structured, timestamped, session-scoped data formatted for AI consumption. Plus opt-in beta anomaly detection inside Settings. Three AI/MCP capabilities — most in the directory.
Integrated suite (Analytics + Tag Manager + Consent Manager + Customer Data Platform) means one vendor, one DPA, one invoice. Most rivals make you stitch together three.
Multi-region data residency is real and customer-selectable: Sweden, Germany, Netherlands, France for the EU; US Azure for HIPAA; Hong Kong for APAC. You pin where the data lives at provisioning, not after a support ticket.
The GA4-shaped UX trims migration cost — analysts who used GA4 last week can run reports on day one.
− Weaknesses & gotchas
Piwik PRO is closed-source and priced for enterprise. The freemium Core plan was discontinued in 2025, so the floor is €35/mo Business or €366/mo for SOC 2 / multi-region, with three of four tiers gated behind sales calls. If you're an indie blog or a 50k-pageview SaaS, this is not your tool.
The tracking script is heavy — ~86 KB gzipped, ~40-80× the size of Plausible (~1KB) or Fathom (~2KB) — which dents Core Web Vitals on slow connections.
The default mode still uses cookies and session fingerprints, so unlike Plausible or Fathom you typically still need a consent banner. (The Anonymous Mode exists, but it's a deliberate downgrade.)
The DNT browser signal is not addressed publicly by the vendor — verify behaviour during procurement.
★ Best for
Best for: regulated enterprises that need a signed BAA or SOC 2 evidence in a vendor questionnaire. Healthcare systems (Boston Children's, Rochester Regional, Children's Nebraska are public references), banks under DORA/EBA, insurers, government departments, EU-only B2B with strict Schrems II posture.
Real value at the Trusted Insights tier (~€800-2k+/mo). That's where you unlock HIPAA BAA, SOC 2 evidence, multi-region pinning, and the CDP. Below that you're paying for Tag Manager + Analytics that other privacy vendors give you cheaper.
Not for indie sites, side projects, blogs, or anything under ~€20k ARR. The €35/mo Business floor is technically reachable, but you'd see better value in Plausible or Umami. The Piwik PRO sales cycle, security questionnaire, and onboarding workflow are designed for procurement, not solo founders.
⚡ Setup walkthrough
Piwik PRO ships as a single Tag Manager container snippet that you paste once; everything else (Analytics, Consent Manager, custom events) is configured inside the Tag Manager UI. Expect ~86 KB gzipped on first paint — async, but worth measuring on mobile LCP.
WordPress: official plugin handles the snippet, opt-out, and Consent Manager hand-off. GTM users: Piwik PRO publishes a GTM template so you can fire it as a tag inside an existing Google Tag Manager container — useful during migration.
Server-side / first-party proxy: Enterprise tiers include a server-side container (CNAME + custom domain) so the tracker loads from yourdomain.com — bypasses ad blockers and improves data accuracy.
Mobile: native SDKs for iOS, Android, Flutter, React Native are published on github.com/PiwikPRO. HIPAA setup: sign BAA first → vendor provisions Azure US workspace → activate before any patient data is collected.
↔ Migrating from GA4
From GA4: the data model maps almost 1:1 (events, parameters, user properties, custom dimensions). Piwik PRO publishes a migration guide; in practice, ship Piwik PRO in parallel for 30-60 days, reconcile core KPIs, then sunset GA4. Many teams keep GA4 running for Google Ads attribution while Piwik PRO becomes the source of truth — Piwik PRO's BigQuery export covers the analytics warehouse half.
From Matomo Cloud or Matomo On-Prem: the harder migration despite the shared lineage — Piwik PRO's data model diverged after the 2016 fork and event schemas don't translate cleanly. Expect to redefine goals, custom variables, and segment definitions. The win is the compliance package (HIPAA BAA, SOC 2) you can't get from Matomo. If you're moving because Matomo Cloud's pricing scaled poorly above 5-10M actions or because you need a BAA, the migration cost is justified at Trusted Insights tier and above.
Help & FAQ
Where to get help with Piwik PRO and the questions buyers email us about.
Support
FAQ (7)
Will Piwik PRO sign a Business Associate Agreement for HIPAA workloads?
Yes, on the Trusted Insights and Secure Intelligence Enterprise tiers. The BAA is customised and signed before any patient data is collected; HIPAA workloads run on Microsoft Azure US with AES-256 encryption. Business and Data Fundamentals tiers do NOT support BAAs.
Can we keep all customer data inside the EU?
Yes. Choose Sweden (Elastx), Netherlands (Azure), Germany (Azure), or France (Orange Flexible Engine) at provisioning. Business tier is EU-only Sweden by default. Some support tooling (Intercom) is US-hosted under SCCs.
What certifications can we verify in our vendor risk review?
ISO 27001 (August 2024), SOC 2 Type II (September 2022, all five trust principles, 107-page report on 129 controls), and HIPAA self-attestation with BAA. SOC 2 report available under NDA from your account executive.
Is Piwik PRO related to Matomo / Piwik open source?
No, separately operated. Piwik PRO is a Polish company founded 2013 that started as consulting around the open-source Piwik project. In 2016 it forked off and built its own proprietary suite. Piwik PRO is closed-source enterprise SaaS; Matomo (InnoCraft NZ) is the GPL-3.0 open-source line.
Can we deploy on-premises on our own Kubernetes cluster?
Yes. The Piwik PRO Analytics Suite is offered as an on-premises deployment (Docker / Kubernetes). Separate DPA applies, pricing is per-quote, includes dedicated technical contact.
What happens to our data on contract termination?
Per the standard DPA, customer data is exported in JSON/CSV/XML on request and deleted from production systems within the contractual window. Default analytics retention is configurable (14, 25, or 60 months); Business tier retains 25 months.
Does Piwik PRO honour the Do Not Track browser signal?
Not disclosed by vendor. Neither the privacy policy nor privacy-security page explicitly addresses DNT. Anonymous Tracking Mode and the in-house Consent Manager are the recommended privacy controls; verify DNT behaviour via account executive.