European MonitoringBuilt, Run and Billed in Europe
Bleemeo is a French company. Your metrics and logs are stored in the European Union, in the Paris region. The agent that runs on your servers is open source, so what leaves your machines is something you can read rather than something you have to trust. That is the whole claim, and every part of it is checkable.
Founded in Toulouse in 2015 • Metrics stored in the EU • Apache 2.0 agent
Why it matters
"Hosted in Europe" Is the Easy Part
Every large monitoring vendor can point at a datacentre in Frankfurt or Dublin. Renting European capacity is a procurement decision, not a commitment — and it is why "EU data residency" has become a badge that tells you almost nothing.
The questions that actually change your exposure are different ones. Which legal entity do you contract with, and under which law? Which region, not which continent? Who are the processors behind the vendor, and where are they? And what exactly does the software you install on your own servers send back?
This page answers those four for Bleemeo. Some of the answers are less flattering than a badge would be — we say so rather than round them off.
The specifics
Four Answers, Not One Badge
Each of these is verifiable without taking our word for it.
A French company, not a European subsidiary
Bleemeo was founded in Toulouse in 2015 and is still run from there. You contract with a French company, you are invoiced in euros, French law applies, and the data protection officer is a person you can email. There is no US parent whose terms sit above the ones you signed.
One region, named
Metrics and logs are stored in the European Union, in the Paris region. Naming the region rather than the continent is the point: "European data centres" is compatible with almost any arrangement, whereas a region is a specific place with a specific legal regime.
An agent you can read
Glouton, the agent you install, is open source under the Apache 2.0 licence. What it collects, what it sends, and what it never touches are all readable in the source. For a vendor assessment, that is a stronger answer than any certification: you do not have to believe the data-handling description, you can check it.
Named processors, including the awkward ones
Hosting is in the EU. Transactional email, mobile push notifications and the federated sign-in providers are not, and they operate under Standard Contractual Clauses. We list them rather than hide behind an averaged claim, so you can check the chain yourself instead of finding it in a security review.
Comparison
What Usually Comes With a US Vendor
| Feature | A typical US monitoring SaaS | Bleemeo |
|---|---|---|
| Contracting entity | A US corporation, or its Irish subsidiary | A French company, French law |
| Where metrics are stored | An EU region, if you pick the right plan | EU, Paris region, on every plan |
| Agent source code | Proprietary, closed | Open source, Apache 2.0 |
| Support time zone | Follow-the-sun, often US hours for escalation | European hours, European team |
| Data protection officer | A privacy@ mailbox | A named, reachable person |
| Billing currency | Usually USD, with FX exposure | Euros |
| Processor list | Long, and frequently updated | Short, and available on request |
| Pricing model | Per host plus metrics, plus GB, plus seats | Per host |
Who asks for this
The Teams This Question Comes From
Public sector and local authorities
Procurement rules and digital sovereignty policies increasingly require an EU supplier and an EU processing location. Ametys, which builds and operates a CMS for French local authorities and universities, chose Bleemeo partly for this reason.
Healthcare and finance
Regulated sectors do not just need the data to sit in the EU; they need to describe the processing chain in an audit. A short processor list and an auditable agent make that a shorter conversation.
Education and research
Universities and research institutions answer to funding bodies with their own sovereignty requirements, and often run heterogeneous fleets that no single cloud console covers.
Anyone tired of FX surprises
A euro price from a European company is a budget line, not a currency position that moves under you between renewals.
What we do not claim
Where the Line Actually Sits
We do not claim sovereignty. Our metric storage runs on European infrastructure operated by a hyperscaler, and anyone selling you monitoring while claiming immunity from every extraterritorial regime is selling you something they cannot deliver. What we can say precisely is where your data is stored, which company you are contracting with, and what leaves your servers.
We also do not claim that nothing ever crosses a border. Alert emails, mobile push notifications and sign-in through Google, Microsoft, Apple or GitHub involve non-EU providers, each under Standard Contractual Clauses. If that matters for your assessment, ask us for the current processor list — it is short, and we would rather you saw it early than found it during a security review.
Frequently Asked Questions
The questions a procurement or security review usually asks
Is Bleemeo a European company?
Yes. Bleemeo is a French company, founded in Toulouse in 2015 and still headquartered and operated there. The contract you sign is with that French entity, under French law, invoiced in euros.
Where exactly is my monitoring data stored?
In the European Union, in the Paris region. We name the region rather than saying "European data centres", because a region is a specific place with a specific legal regime and a continent is not.
Does any of my data leave the EU?
Your metrics and logs do not. Some peripheral processing does: transactional email (alert notifications and invoices), mobile push notifications, and federated sign-in through Google, Microsoft, Apple or GitHub if you use it. Each of those providers operates under Standard Contractual Clauses. Ask us for the current processor list and we will send it.
What does the agent actually send back?
Infrastructure metrics, the status of discovered services, and the logs you explicitly point it at. It never reads application data, credentials or database contents. You do not have to take that on trust: Glouton is open source under Apache 2.0, so the collection code can be read and audited.
Are you GDPR compliant?
Yes, and the practical parts matter more than the sentence: data minimisation in what the agent collects, deletion on request, export at any time, a reachable data protection officer, and a processor list we will hand over. See our security practices for the detail.
Are you SOC 2 certified?
No. We are not SOC 2 certified today, and we would rather say so than let the acronym imply otherwise. Our infrastructure undergoes regular security audits, data is encrypted in transit with TLS 1.3 and at rest with AES-256, and access is controlled with RBAC, MFA and full audit logging.
Can I get an invoice in euros with a French VAT number?
Yes. Pricing is in euros, invoicing is from a French company with a French VAT number, and intra-EU reverse charge applies where relevant.