{
  "generated_from": "https://saas-ranking.com/content-management/sanity",
  "disclaimer": "Every result describes what we found at the addresses we checked on the date given. It is not a statement about what the vendor does or does not have. The score is a public transparency score, not a product or security rating.",
  "snapshot": "r7.74650",
  "snapshot_run": 7,
  "score_version": "v1",
  "vendor": {
    "name": "Sanity",
    "domain": "sanity.io"
  },
  "category": {
    "slug": "content-management",
    "name": "Content management systems"
  },
  "score": 78,
  "band": "B",
  "measured": 12,
  "of": 12,
  "criteria": [
    {
      "key": "dpa",
      "name": "Data processing agreement",
      "weight": 3,
      "result": "found",
      "source_url": "https://www.sanity.io/legal/dpa",
      "addresses_checked": [
        {
          "url": "https://sanity.io/legal/dpa",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.483Z"
    },
    {
      "key": "subprozessoren",
      "name": "Subprocessor list",
      "weight": 3,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://sanity.io/legal/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://sanity.io/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://sanity.io/sub-processors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://sanity.io/legal/sub-processors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://sanity.io/trust/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://sanity.io/privacy/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://sanity.io/legal/subprocessor-list",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.484Z"
    },
    {
      "key": "datenregion",
      "name": "Data location stated",
      "weight": 3,
      "result": "found",
      "source_url": "https://www.sanity.io/security",
      "addresses_checked": [
        {
          "url": "https://sanity.io/security",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.485Z"
    },
    {
      "key": "statusseite",
      "name": "Status page with history",
      "weight": 2,
      "result": "found",
      "source_url": "https://www.sanity-status.com/",
      "addresses_checked": [
        {
          "url": "https://status.sanity.io/",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.486Z"
    },
    {
      "key": "preise",
      "name": "Public pricing",
      "weight": 2,
      "result": "found",
      "source_url": "https://www.sanity.io/pricing",
      "addresses_checked": [
        {
          "url": "https://sanity.io/pricing",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.487Z"
    },
    {
      "key": "zertifizierungen",
      "name": "Certifications named",
      "weight": 1,
      "result": "found",
      "source_url": "https://www.sanity.io/security",
      "addresses_checked": [
        {
          "url": "https://sanity.io/security",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.488Z"
    },
    {
      "key": "sla",
      "name": "Uptime SLA with a figure",
      "weight": 1,
      "result": "found",
      "source_url": "https://www.sanity.io/legal/sla",
      "addresses_checked": [
        {
          "url": "https://sanity.io/legal/sla",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.490Z"
    },
    {
      "key": "transport",
      "name": "HTTPS enforced with HSTS",
      "weight": 2,
      "result": "found",
      "source_url": "https://sanity.io/",
      "addresses_checked": [
        {
          "url": "http://sanity.io/",
          "result": "redirects to https://sanity.io/"
        },
        {
          "url": "https://sanity.io/",
          "result": "HSTS max-age=63072000"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.492Z"
    },
    {
      "key": "tracker_vor_einwilligung",
      "name": "No third-party tracking before consent",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://sanity.io/",
          "result": "third-party requests before any interaction: cdn.usefathom.com, cmp.osano.com, o131006.ingest.us.sentry.io, pagead2.googlesyndication.com, www.googletagmanager.com"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.494Z"
    },
    {
      "key": "security_txt",
      "name": "security.txt (RFC 9116)",
      "weight": 1,
      "result": "found",
      "source_url": "https://www.sanity.io/.well-known/security.txt",
      "addresses_checked": [
        {
          "url": "https://sanity.io/.well-known/security.txt",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.496Z"
    },
    {
      "key": "subprozessor_meldung",
      "name": "Notice before subprocessors change",
      "weight": 2,
      "result": "found",
      "source_url": "https://www.sanity.io/legal/dpa",
      "addresses_checked": [
        {
          "url": "https://sanity.io/legal/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://sanity.io/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://sanity.io/sub-processors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://sanity.io/legal/dpa",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.497Z"
    },
    {
      "key": "datenschutzkontakt",
      "name": "Named privacy contact",
      "weight": 1,
      "result": "found",
      "source_url": "https://www.sanity.io/legal/privacy",
      "addresses_checked": [
        {
          "url": "https://sanity.io/legal/privacy",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T02:35:16.498Z"
    }
  ],
  "details": [
    {
      "key": "datenregion",
      "name": "Hosting location named",
      "value": "belgium",
      "subject": null,
      "quote": "b frontend systems are distributed across the world, our backend systems currently run across three data centers in a single EU region (Belgium) - we plan to implement a fully global backend infrastru...",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.485Z"
    },
    {
      "key": "datenregion",
      "name": "Hosting location named",
      "value": "european-economic-area",
      "subject": null,
      "quote": "Uploaded content will be stored in the EU/EEA, the US, or in regions where Sanity has an operational footprint, specific by customer.",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.485Z"
    },
    {
      "key": "datenregion",
      "name": "Hosting location named",
      "value": "european-union",
      "subject": null,
      "quote": "Uploaded content will be stored in the EU/EEA, the US, or in regions where Sanity has an operational footprint, specific by customer.",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.485Z"
    },
    {
      "key": "datenschutzkontakt_art",
      "name": "Privacy contact",
      "value": "data-protection-officer",
      "subject": null,
      "quote": "dpo",
      "source_url": "https://www.sanity.io/legal/privacy",
      "measured_on": "2026-09-05T02:35:16.499Z"
    },
    {
      "key": "datenschutzkontakt_art",
      "name": "Privacy contact",
      "value": "dedicated-address",
      "subject": null,
      "quote": "[address]@sanity.io",
      "source_url": "https://www.sanity.io/legal/privacy",
      "measured_on": "2026-09-05T02:35:16.499Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "googlesyndication.com",
      "subject": null,
      "quote": "pagead2.googlesyndication.com",
      "source_url": "https://sanity.io/",
      "measured_on": "2026-09-05T02:35:16.495Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "googletagmanager.com",
      "subject": null,
      "quote": "www.googletagmanager.com",
      "source_url": "https://sanity.io/",
      "measured_on": "2026-09-05T02:35:16.495Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "osano.com",
      "subject": null,
      "quote": "cmp.osano.com",
      "source_url": "https://sanity.io/",
      "measured_on": "2026-09-05T02:35:16.495Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "sentry.io",
      "subject": null,
      "quote": "o131006.ingest.us.sentry.io",
      "source_url": "https://sanity.io/",
      "measured_on": "2026-09-05T02:35:16.495Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "usefathom.com",
      "subject": null,
      "quote": "cdn.usefathom.com",
      "source_url": "https://sanity.io/",
      "measured_on": "2026-09-05T02:35:16.495Z"
    },
    {
      "key": "hsts_frist",
      "name": "HSTS max-age",
      "value": "63072000",
      "subject": null,
      "quote": "max-age=63072000",
      "source_url": "https://sanity.io/",
      "measured_on": "2026-09-05T02:35:16.493Z"
    },
    {
      "key": "sla_prozent",
      "name": "Uptime figure",
      "value": "99.95",
      "subject": null,
      "quote": "Enterprise Agreement Availability Calculation of Service Credit 99.9% - 99.95% 10% multiplied by the Annual Service Fee divided by 12 4.",
      "source_url": "https://www.sanity.io/legal/sla",
      "measured_on": "2026-09-05T02:35:16.491Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "csa-star",
      "subject": "erwaehnt",
      "quote": "ndependent audits for a range of standards including ISO 27001, ISO 27017, ISO 27018, SOC 2, SOC 3, CSA STAR, HIPAA, and PCI DSS.",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.489Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "hipaa",
      "subject": "erwaehnt",
      "quote": "audits for a range of standards including ISO 27001, ISO 27017, ISO 27018, SOC 2, SOC 3, CSA STAR, HIPAA, and PCI DSS.",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.489Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "iso-27001",
      "subject": "erwaehnt",
      "quote": "m , which hosts Sanity.io , undergoes regular independent audits for a range of standards including ISO 27001, ISO 27017, ISO 27018, SOC 2, SOC 3, CSA STAR, HIPAA, and PCI DSS.",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.489Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "iso-27017",
      "subject": "erwaehnt",
      "quote": "osts Sanity.io , undergoes regular independent audits for a range of standards including ISO 27001, ISO 27017, ISO 27018, SOC 2, SOC 3, CSA STAR, HIPAA, and PCI DSS.",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.489Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "iso-27018",
      "subject": "erwaehnt",
      "quote": ".io , undergoes regular independent audits for a range of standards including ISO 27001, ISO 27017, ISO 27018, SOC 2, SOC 3, CSA STAR, HIPAA, and PCI DSS.",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.489Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "pci-dss",
      "subject": "anbieter",
      "quote": "PCI DSS All credit card and payment information is handled by our payment processor, Stripe .",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.489Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "soc-2",
      "subject": "anbieter",
      "quote": "Our SOC 2 examination covers the Security principle in the Trust Services Criteria.",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.489Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "soc-2-type-2",
      "subject": "anbieter",
      "quote": "Compliance SOC 2 Type 2 Sanity.io is a SOC 2 Type 2 certified provider.",
      "source_url": "https://www.sanity.io/security",
      "measured_on": "2026-09-05T02:35:16.489Z"
    }
  ]
}