AuditFile
auditfile.com · Accounting · checked 2026-09-13
Rank 15 of 67 in Accounting, where the median is 17.
- 3 found
- 9 not found
- 0 not measured
We measured 12 of 12 criteria for AuditFile on 2026-09-13. We found 3 with a source and did not find 9 at the addresses we checked. That is a transparency score of 22 out of 100, band F.
Overview
0 days since the newest finding, 0 since the oldest. 12 of 12 criteria measured in the last 30 days.
Evidence freshness is a statement about our measurement and is kept apart from the transparency score, which is frozen at v1. How good our own measurement is.
Transparency labelsaas-ranking.com
AuditFile
- A
- B
- C
- D
- E
- F
Published commitments2 of 9 found
- not foundData processing agreement×3
- not foundSubprocessor list×3
- not foundData location stated×3
- not foundStatus page with history×2
- foundPublic pricing×2
- not foundNotice before subprocessors change×2
- foundCertifications named×1
- not foundUptime SLA with a figure×1
- not foundNamed privacy contact×1
Measured behaviour1 of 3 found
- foundHTTPS enforced with HSTS×2
- not foundNo third-party tracking before consent×2
- not foundsecurity.txt (RFC 9116)×1
Checked 2026-09-13. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.
The evidence pack carries every criterion with its source, the addresses we checked, the date and the data snapshot id – the four things a procurement file needs and a screenshot loses. We do not issue badges: a badge is the first step towards a paid placement, and there is none here.
The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.
Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that AuditFile has no such document.
Where AuditFile sits in Accounting
- A0 0%
- B0 0%
- C1 1%
- D2 3%
- E11 16%
- F53 79%
The band of AuditFile is marked. Vendors without a score are the ones where we could measure too few criteria to rank them – a gap on our side, counted separately.
What they state
The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.
- Named on that page FedRAMP (not counted: the sentence does not carry it), HIPAA (not counted: the sentence does not carry it), ISO/IEC 27001 (not counted: the sentence does not carry it), PCI DSS (not counted: the sentence does not carry it), SOC 2 (a named provider of theirs), SOC 2 Type II. The sentence we kept does not carry this finding on its own, so it counts in no list and no figure.
Show the 6 exact wordings
vCloud (US) is continuously audited by an accredited Federal Risk Authorization Management Program (FedRAMP) independent third-party assessment organization (3PAO) and has been issued a FedRAMP Provis...
Read at https://auditfile.com/securityHIPAA AuditFile enables users to comply with HIPAA.
Read at https://auditfile.com/securityIn addition, AWS has achieved ISO 27001 certification, and has been successfully validated as a Level 1 service provider under the Payment
Read at https://auditfile.com/securityPCI DSS The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security st
Read at https://auditfile.com/securitythe SSAE 16 and the ISAE 3402 professional standards as well as a Service Organization Controls 2 (SOC 2) report.
Read at https://auditfile.com/securityCompliance Programs AICPA SOC AuditFile has successfully completed a SOC 2 Type II examination, performed by Johanson Group LLP.
Read at https://auditfile.com/security - Third-party hosts we saw on the first load 6 cloudflareinsights.com, doubleclick.net, google-analytics.com, google.com, google.de, googletagmanager.com.
Show the 6 exact wordings
static.cloudflareinsights.com
Read at https://auditfile.com/stats.g.doubleclick.net
Read at https://auditfile.com/www.google-analytics.com
Read at https://auditfile.com/region1.analytics.google.com
Read at https://auditfile.com/www.google.de
Read at https://auditfile.com/www.googletagmanager.com
Read at https://auditfile.com/ - HSTS max-age 63072000 seconds (730 days).
Show the exact wording
max-age=63072000; includeSubDomains
Read at https://auditfile.com/ - HSTS options includeSubDomains.
Show the exact wording
max-age=63072000; includeSubDomains
Read at https://auditfile.com/
Gaps, heaviest first
Data processing agreement
weight 3 of 3No data processing agreement found.
Checked 8 addresses on 2026-09-13.
Show the 8 addresses we checked
https://auditfile.com/legal/dpa– reached, no match (HTTP 404)https://auditfile.com/dpa– reached, no match (HTTP 404)https://auditfile.com/legal/data-processing-agreement– reached, no match (HTTP 404)https://auditfile.com/data-processing-agreement– reached, no match (HTTP 404)https://auditfile.com/legal/data-processing-addendum– reached, no match (HTTP 404)https://auditfile.com/legal/gdpr– reached, no match (HTTP 404)https://auditfile.com/trust/dpa– reached, no match (HTTP 404)https://auditfile.com/privacy/dpa– reached, no match (HTTP 404)
Subprocessor list
weight 3 of 3No subprocessor list found.
Checked 7 addresses on 2026-09-13.
Show the 7 addresses we checked
https://auditfile.com/legal/subprocessors– reached, no match (HTTP 404)https://auditfile.com/subprocessors– reached, no match (HTTP 404)https://auditfile.com/sub-processors– reached, no match (HTTP 404)https://auditfile.com/legal/sub-processors– reached, no match (HTTP 404)https://auditfile.com/trust/subprocessors– reached, no match (HTTP 404)https://auditfile.com/privacy/subprocessors– reached, no match (HTTP 404)https://auditfile.com/legal/subprocessor-list– reached, no match (HTTP 404)
Data location stated
weight 3 of 3No statement about data location found.
Checked 7 addresses on 2026-09-13.
Show the 7 addresses we checked
https://auditfile.com/security– reached, no match (HTTP 200)https://auditfile.com/trust– reached, no match (HTTP 404)https://auditfile.com/legal/privacy– reached, no match (HTTP 404)https://auditfile.com/privacy– reached, no match (HTTP 404)https://auditfile.com/privacy-policy– reached, no match (HTTP 404)https://auditfile.com/compliance– reached, no match (HTTP 404)https://auditfile.com/legal/privacy-policy– reached, no match (HTTP 404)
Status page with history
weight 2 of 3No public status page found.
Checked 3 addresses on 2026-09-13.
Show the 3 addresses we checked
https://status.auditfile.com/– reached, no match (HTTP 200)https://auditfile.com/status– No answer within 10 seconds.https://auditfile.com.statuspage.io/– Could not be fetched: fetch failed.
No third-party tracking before consent
weight 2 of 3Third-party requests seen on the first load, before any interaction.
- Third-party hosts we saw on the first load 6 cloudflareinsights.com, doubleclick.net, google-analytics.com, google.com, google.de, googletagmanager.com.
Show the 6 exact wordings
static.cloudflareinsights.com
Read at https://auditfile.com/stats.g.doubleclick.net
Read at https://auditfile.com/www.google-analytics.com
Read at https://auditfile.com/region1.analytics.google.com
Read at https://auditfile.com/www.google.de
Read at https://auditfile.com/www.googletagmanager.com
Read at https://auditfile.com/
Checked 1 address on 2026-09-13.
Show the 1 address we checked
https://auditfile.com/– third-party requests before any interaction: region1.analytics.google.com, static.cloudflareinsights.com, stats.g.doubleclick.net, www.google-analytics.com, www.google.de, www.googletagmanager.com
Notice before subprocessors change
weight 2 of 3No commitment to give notice before subprocessors change found.
Checked 8 addresses on 2026-09-13.
Show the 8 addresses we checked
https://auditfile.com/legal/subprocessors– reached, no match (HTTP 404)https://auditfile.com/subprocessors– reached, no match (HTTP 404)https://auditfile.com/sub-processors– reached, no match (HTTP 404)https://auditfile.com/legal/dpa– reached, no match (HTTP 404)https://auditfile.com/dpa– reached, no match (HTTP 404)https://auditfile.com/legal/data-processing-agreement– reached, no match (HTTP 404)https://auditfile.com/trust/subprocessors– reached, no match (HTTP 404)https://auditfile.com/legal/sub-processors– reached, no match (HTTP 404)
Uptime SLA with a figure
weight 1 of 3No uptime figure found.
Checked 6 addresses on 2026-09-13.
Show the 6 addresses we checked
https://auditfile.com/legal/sla– reached, no match (HTTP 404)https://auditfile.com/sla– reached, no match (HTTP 404)https://auditfile.com/legal/service-level-agreement– reached, no match (HTTP 404)https://auditfile.com/trust/sla– reached, no match (HTTP 404)https://auditfile.com/uptime– reached, no match (HTTP 404)https://auditfile.com/legal/uptime-sla– reached, no match (HTTP 404)
security.txt (RFC 9116)
weight 1 of 3No security.txt found.
Checked 1 address on 2026-09-13.
Show the 1 address we checked
https://auditfile.com/.well-known/security.txt– reached, no match (HTTP 404)
Named privacy contact
weight 1 of 3No named privacy contact found.
Checked 7 addresses on 2026-09-13.
Show the 7 addresses we checked
https://auditfile.com/legal/privacy– reached, no match (HTTP 404)https://auditfile.com/privacy– reached, no match (HTTP 404)https://auditfile.com/privacy-policy– reached, no match (HTTP 404)https://auditfile.com/legal/privacy-policy– reached, no match (HTTP 404)https://auditfile.com/legal/privacy-notice– reached, no match (HTTP 404)https://auditfile.com/trust/privacy– reached, no match (HTTP 404)https://auditfile.com/datenschutz– reached, no match (HTTP 404)
Evidence
The full source lists sit behind these two groups, so that the answer above stays readable.
Published, with a source 3
Public pricing
weight 2 of 3Actual numbers on a public page.
Source: https://auditfile.com/pricing · checked 2026-09-13
HTTPS enforced with HSTS
weight 2 of 3HTTP redirects to HTTPS and the HSTS header is set.
- HSTS max-age 63072000 seconds (730 days).
Show the exact wording
max-age=63072000; includeSubDomains
Read at https://auditfile.com/ - HSTS options includeSubDomains.
Show the exact wording
max-age=63072000; includeSubDomains
Read at https://auditfile.com/
Source: https://auditfile.com/ · checked 2026-09-13
Certifications named
weight 1 of 3SOC 2 or ISO 27001 named on a public page.
- Named on that page FedRAMP (not counted: the sentence does not carry it), HIPAA (not counted: the sentence does not carry it), ISO/IEC 27001 (not counted: the sentence does not carry it), PCI DSS (not counted: the sentence does not carry it), SOC 2 (a named provider of theirs), SOC 2 Type II. The sentence we kept does not carry this finding on its own, so it counts in no list and no figure.
Show the 6 exact wordings
vCloud (US) is continuously audited by an accredited Federal Risk Authorization Management Program (FedRAMP) independent third-party assessment organization (3PAO) and has been issued a FedRAMP Provis...
Read at https://auditfile.com/securityHIPAA AuditFile enables users to comply with HIPAA.
Read at https://auditfile.com/securityIn addition, AWS has achieved ISO 27001 certification, and has been successfully validated as a Level 1 service provider under the Payment
Read at https://auditfile.com/securityPCI DSS The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security st
Read at https://auditfile.com/securitythe SSAE 16 and the ISAE 3402 professional standards as well as a Service Organization Controls 2 (SOC 2) report.
Read at https://auditfile.com/securityCompliance Programs AICPA SOC AuditFile has successfully completed a SOC 2 Type II examination, performed by Johanson Group LLP.
Read at https://auditfile.com/security
Source: https://auditfile.com/security · checked 2026-09-13
History
Not enough completed runs yet to draw a line. The next runs fill this in.
Compare
A shortlist holds up to six vendors across categories and lives entirely in the address of its page: share the link, bookmark it, put it in a ticket. Nothing is stored, so we do not know it exists.