SaaS Ranking

Instabase

instabase.com · Document AI and data capture · checked 2026-09-04

30/100EBand E

Rank 11 of 26 in Document AI and data capture, where the median is 23.5.

We measured 12 of 12 criteria for Instabase on 2026-09-04. We found 4 with a source and did not find 8 at the addresses we checked. That is a transparency score of 30 out of 100, band E.

Overview

Transparency labelsaas-ranking.com

Instabase

instabase.com · Document AI and data capture

  1. A
  2. B
  3. C
  4. D
  5. E
  6. F
E 30of 100 Rank 11 of 26

Published commitments4 of 9 found

Measured behaviour0 of 3 found

Checked 2026-09-04. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.

We do not issue badges: a badge is the first step towards a paid placement, and there is none here. The SVG is a document with the date in it, for your own files.

The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.

Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that Instabase has no such document.

What they state

The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.

Gaps, heaviest first

Data processing agreement

weight 3 of 3

No data processing agreement found.

Checked 8 addresses on 2026-09-04.

Show the 8 addresses we checked
  1. https://instabase.com/legal/dpa – reached, no match (HTTP 404)
  2. https://instabase.com/dpa – reached, no match (HTTP 404)
  3. https://instabase.com/legal/data-processing-agreement – reached, no match (HTTP 404)
  4. https://instabase.com/data-processing-agreement – reached, no match (HTTP 404)
  5. https://instabase.com/legal/data-processing-addendum – reached, no match (HTTP 404)
  6. https://instabase.com/legal/gdpr – reached, no match (HTTP 404)
  7. https://instabase.com/trust/dpa – Not the expected content type but "application/pdf".
  8. https://instabase.com/privacy/dpa – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Data location stated

weight 3 of 3

No statement about data location found.

Checked 7 addresses on 2026-09-04.

Show the 7 addresses we checked
  1. https://instabase.com/security – reached, no match (HTTP 404)
  2. https://instabase.com/trust – reached, no match (HTTP 200)
  3. https://instabase.com/legal/privacy – reached, no match (HTTP 404)
  4. https://instabase.com/privacy – reached, no match (HTTP 404)
  5. https://instabase.com/privacy-policy – reached, no match (HTTP 200)
  6. https://instabase.com/compliance – reached, no match (HTTP 404)
  7. https://instabase.com/legal/privacy-policy – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Status page with history

weight 2 of 3

No public status page found.

Checked 3 addresses on 2026-09-04.

Show the 3 addresses we checked
  1. https://status.instabase.com/ – The name "status.instabase.com" could not be resolved.
  2. https://instabase.com/status – reached, no match (HTTP 404)
  3. https://instabase.com.statuspage.io/ – Could not be fetched: fetch failed.

Is this wrong? Send us the URL

Public pricing

weight 2 of 3

No public pricing with figures found.

Checked 5 addresses on 2026-09-04.

Show the 5 addresses we checked
  1. https://instabase.com/pricing – reached and rendered, no match
  2. https://instabase.com/pricing/ – reached, no match (HTTP 200)
  3. https://instabase.com/plans – reached, no match (HTTP 404)
  4. https://instabase.com/en/pricing – reached, no match (HTTP 404)
  5. https://instabase.com/pricing-plans – reached, no match (HTTP 404)

Is this wrong? Send us the URL

HTTPS enforced with HSTS

weight 2 of 3

No enforced HTTPS with HSTS found.

Checked 2 addresses on 2026-09-04.

Show the 2 addresses we checked
  1. http://instabase.com/ – redirects to https://instabase.com/
  2. https://instabase.com/ – no HSTS header

Is this wrong? Send us the URL

No third-party tracking before consent

weight 2 of 3

No consent-free first load found.

Checked 1 address on 2026-09-04.

Show the 1 address we checked
  1. https://instabase.com/ – third-party requests before any interaction: cdn.jsdelivr.net, cdn.prod.website-files.com, cookie-cdn.cookiepro.com, d3e54v103j8qbb.cloudfront.net, pagead2.googlesyndication.com, region1.google-analytics.com, www.googletagmanager.com

Is this wrong? Send us the URL

Uptime SLA with a figure

weight 1 of 3

No uptime figure found.

Checked 6 addresses on 2026-09-04.

Show the 6 addresses we checked
  1. https://instabase.com/legal/sla – reached, no match (HTTP 404)
  2. https://instabase.com/sla – reached, no match (HTTP 404)
  3. https://instabase.com/legal/service-level-agreement – reached, no match (HTTP 404)
  4. https://instabase.com/trust/sla – reached, no match (HTTP 404)
  5. https://instabase.com/uptime – reached, no match (HTTP 404)
  6. https://instabase.com/legal/uptime-sla – reached, no match (HTTP 404)

Is this wrong? Send us the URL

security.txt (RFC 9116)

weight 1 of 3

No security.txt found.

Checked 1 address on 2026-09-04.

Show the 1 address we checked
  1. https://instabase.com/.well-known/security.txt – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Evidence

The full source lists sit behind these two groups, so that the answer above stays readable.

Published, with a source 4

Subprocessor list

weight 3 of 3

The actual list is published, not just a promise to keep one.

Source: https://www.instabase.com/trust/subprocessors · checked 2026-09-04

Notice before subprocessors change

weight 2 of 3

The vendor commits publicly to giving notice before the list changes.

  • Notice promised before the list changes 30 days.
    Show the exact wording

    Instabase shall provide at least 30 days (email) notice to its customers, before a new Subprocessor begins processing Customer Data.

    Read at https://www.instabase.com/trust/subprocessors

Source: https://www.instabase.com/trust/subprocessors · checked 2026-09-04

Certifications named

weight 1 of 3

SOC 2 or ISO 27001 named on a public page.

  • Named on that page HIPAA, SOC 2 Type II.
    Show the 2 exact wordings

    ‍ Instabase holds certifications and attestations for SOC 2 Type II and HIPAA and is designed to comply with GDPR and CCPA.

    Read at https://www.instabase.com/trust

    ‍ Instabase holds certifications and attestations for SOC 2 Type II and HIPAA and is designed to comply with GDPR and CCPA.

    Read at https://www.instabase.com/trust

Source: https://www.instabase.com/trust · checked 2026-09-04

Named privacy contact

weight 1 of 3

A data protection officer or a dedicated privacy address is named.

Source: https://www.instabase.com/privacy-policy · checked 2026-09-04

History

Not enough completed runs yet to draw a line. The next runs fill this in.

Compare