What we check, and who passes
We check 10 things a buyer needs before signing. Each one has its own page listing every vendor we measured, with the source for each result.
Last full check: 2026-08-31.
Data processing agreement
46 of 168 publish it
Without a published DPA you cannot review the contract before you talk to sales.
Subprocessor list
30 of 166 publish it
Naming the actual subprocessors is what turns a privacy promise into something you can check.
Data location stated
103 of 168 publish it
Where the data physically sits decides which law applies to it.
Status page with history
109 of 178 publish it
A status page without past incidents tells you nothing about reliability.
Public pricing
131 of 170 publish it
Hidden pricing moves the first comparison into a sales call.
Certifications named
96 of 176 publish it
Naming SOC 2 or ISO 27001 publicly is the low bar; not naming them is a signal.
Uptime SLA with a figure
16 of 166 publish it
"High availability" is marketing. "99.9 %" is a commitment.
HTTPS enforced with HSTS
143 of 185 publish it
We measure this ourselves on their own site. It is the cheapest security control there is.
No third-party tracking before consent
16 of 187 publish it
We load their front page and count third-party requests before anything is clicked.
security.txt (RFC 9116)
54 of 162 publish it
It tells a researcher where to report a vulnerability instead of guessing.