SaaS Ranking

Zimbra: what they publish

zimbra.com · Email hosting · checked 2026-09-28

Not enough data: 2 of 12 criteria measured, so no transparency score

Public transparency score, not a product or security rating. Latest check: 2026-09-28. How the score works.

Evidence at a glance

Choose a check to see its source, date and scope.

Not found means not found at the addresses we checked. Not measured means we could not complete the check.

Start a vendor reviewDownload evidence (CSV)

Overview

5 days since the newest dated result, 5 since the oldest. 2 of 12 criteria have a measured result in the last 30 days. Failed checks and undated results are excluded.

Evidence freshness is a statement about our measurement and is kept apart from the transparency score, which is frozen at v1. How good our own measurement is.

Transparency labelsaas-ranking.com

Zimbra

zimbra.com · Email hosting

  1. A
  2. B
  3. C
  4. D
  5. E
  6. F
Not enough data2 of 12 measured, no score

Published commitments9 not measured

Measured behaviour0 of 2 found, 1 not measured

Checked 2026-09-28. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.

Downloads include all checks, source URLs, dates and the snapshot ID for your procurement file. We do not issue badges.

The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating. We could measure 2 of 12 criteria, which is below our threshold, so there is no rank. That is a statement about our measurement, not about Zimbra.

Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that Zimbra has no such document.

What Zimbra states

The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.

Gaps, heaviest first

✗

HTTPS enforced with HSTS

weight 2 of 3

No enforced HTTPS with HSTS found.

  • HSTS max-age 300 seconds.
    Show the exact wording

    max-age=300; includeSubDomains;

    Read at https://zimbra.com/
  • HSTS options includeSubDomains.
    Show the exact wording

    max-age=300; includeSubDomains;

    Read at https://zimbra.com/

Checked 2 addresses on 2026-09-28.

Show the 2 addresses we checked
  1. http://zimbra.com/ – redirects to https://www.zimbra.com/
  2. https://zimbra.com/ – HSTS max-age=300

Is this wrong? Send us the URL

Across the market: HTTPS enforced with HSTS in Email hosting: 23 of 42 companies

✗weight 2 of 3

Third-party requests seen on the first load, before any interaction.

Checked 1 address on 2026-09-28.

Show the 1 address we checked
  1. https://zimbra.com/ – third-party requests before any interaction: acsbapp.com, api.hubapi.com, bam.nr-data.net, cdn.acsbapp.com, consent.trustarc.com, cta-service-cms2.hubspot.com, fonts.googleapis.com, fonts.gstatic.com, forms-na1.hsforms.com, forms.hsforms.com, js-agent.newrelic.com, js.hs-analytics.net, js.hs-banner.com, js.hs-scripts.com, js.hsadspixel.net, js.hsforms.net, js.hubspot.com, perf-na1.hsforms.com, privacy-policy.truste.com, px.ads.linkedin.com, region1.analytics.google.com, snap.licdn.com, stats.g.doubleclick.net, track.hubspot.com, www.google.de, www.googletagmanager.com

Is this wrong? Send us the URL

Across the market: No third-party tracking before consent in Email hosting: 16 of 42 companies

Evidence

The full source lists sit behind these two groups, so that the answer above stays readable.

Not measured by us 10
–

Data processing agreement (DPA)

weight 3 of 3

Not measured. The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Show the 8 addresses we checked
  1. https://zimbra.com/legal/dpa – excluded by robots.txt
  2. https://zimbra.com/dpa – excluded by robots.txt
  3. https://zimbra.com/legal/data-processing-agreement – excluded by robots.txt
  4. https://zimbra.com/data-processing-agreement – excluded by robots.txt
  5. https://zimbra.com/legal/data-processing-addendum – excluded by robots.txt
  6. https://zimbra.com/legal/gdpr – excluded by robots.txt
  7. https://zimbra.com/trust/dpa – excluded by robots.txt
  8. https://zimbra.com/privacy/dpa – excluded by robots.txt

Is this wrong? Send us the URL

Across the market: Data processing agreement in Email hosting: 2 of 37 companies

–

Subprocessors: the published list

weight 3 of 3

Not measured. The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Show the 7 addresses we checked
  1. https://zimbra.com/legal/subprocessors – excluded by robots.txt
  2. https://zimbra.com/subprocessors – excluded by robots.txt
  3. https://zimbra.com/sub-processors – excluded by robots.txt
  4. https://zimbra.com/legal/sub-processors – excluded by robots.txt
  5. https://zimbra.com/trust/subprocessors – excluded by robots.txt
  6. https://zimbra.com/privacy/subprocessors – excluded by robots.txt
  7. https://zimbra.com/legal/subprocessor-list – excluded by robots.txt

Is this wrong? Send us the URL

Across the market: Subprocessor list in Email hosting: 0 of 37 companies

–

Data location: where they say data is hosted

weight 3 of 3

Not measured. The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Show the 7 addresses we checked
  1. https://zimbra.com/security – excluded by robots.txt
  2. https://zimbra.com/trust – excluded by robots.txt
  3. https://zimbra.com/legal/privacy – excluded by robots.txt
  4. https://zimbra.com/privacy – excluded by robots.txt
  5. https://zimbra.com/privacy-policy – excluded by robots.txt
  6. https://zimbra.com/compliance – excluded by robots.txt
  7. https://zimbra.com/legal/privacy-policy – excluded by robots.txt

Is this wrong? Send us the URL

Across the market: Data location stated in Email hosting: 6 of 37 companies

–

Status page with incident history

weight 2 of 3

Not measured. The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Show the 3 addresses we checked
  1. https://status.zimbra.com/ – excluded by robots.txt
  2. https://zimbra.com/status – excluded by robots.txt
  3. https://zimbra.com.statuspage.io/ – excluded by robots.txt

Is this wrong? Send us the URL

Across the market: Status page with history in Email hosting: 7 of 39 companies

–

Public pricing with figures

weight 2 of 3

Not measured. The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Show the 5 addresses we checked
  1. https://zimbra.com/pricing – excluded by robots.txt
  2. https://zimbra.com/pricing/ – excluded by robots.txt
  3. https://zimbra.com/plans – excluded by robots.txt
  4. https://zimbra.com/en/pricing – excluded by robots.txt
  5. https://zimbra.com/pricing-plans – excluded by robots.txt

Is this wrong? Send us the URL

Across the market: Public pricing in Email hosting: 11 of 37 companies

–

Notice before subprocessors change

weight 2 of 3

Not measured. The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Show the 8 addresses we checked
  1. https://zimbra.com/legal/subprocessors – excluded by robots.txt
  2. https://zimbra.com/subprocessors – excluded by robots.txt
  3. https://zimbra.com/sub-processors – excluded by robots.txt
  4. https://zimbra.com/legal/dpa – excluded by robots.txt
  5. https://zimbra.com/dpa – excluded by robots.txt
  6. https://zimbra.com/legal/data-processing-agreement – excluded by robots.txt
  7. https://zimbra.com/trust/subprocessors – excluded by robots.txt
  8. https://zimbra.com/legal/sub-processors – excluded by robots.txt

Is this wrong? Send us the URL

Across the market: Notice before subprocessors change in Email hosting: 0 of 37 companies

–

Certifications named (SOC 2, ISO 27001)

weight 1 of 3

Not measured. The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Show the 6 addresses we checked
  1. https://zimbra.com/security – excluded by robots.txt
  2. https://zimbra.com/trust – excluded by robots.txt
  3. https://zimbra.com/trust-center – excluded by robots.txt
  4. https://zimbra.com/compliance – excluded by robots.txt
  5. https://zimbra.com/legal/security – excluded by robots.txt
  6. https://trust.zimbra.com/ – excluded by robots.txt

Is this wrong? Send us the URL

Across the market: Certifications named in Email hosting: 4 of 38 companies

–

Uptime SLA with a figure

weight 1 of 3

Not measured. The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Show the 6 addresses we checked
  1. https://zimbra.com/legal/sla – excluded by robots.txt
  2. https://zimbra.com/sla – excluded by robots.txt
  3. https://zimbra.com/legal/service-level-agreement – excluded by robots.txt
  4. https://zimbra.com/trust/sla – excluded by robots.txt
  5. https://zimbra.com/uptime – excluded by robots.txt
  6. https://zimbra.com/legal/uptime-sla – excluded by robots.txt

Is this wrong? Send us the URL

Across the market: Uptime SLA with a figure in Email hosting: 0 of 37 companies

–

security.txt (RFC 9116)

weight 1 of 3

Not measured. The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Show the 1 address we checked
  1. https://zimbra.com/.well-known/security.txt – excluded by robots.txt

Is this wrong? Send us the URL

Across the market: security.txt (RFC 9116) in Email hosting: 14 of 38 companies

–

Named privacy contact (DPO or privacy address)

weight 1 of 3

Not measured. The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Show the 7 addresses we checked
  1. https://zimbra.com/legal/privacy – excluded by robots.txt
  2. https://zimbra.com/privacy – excluded by robots.txt
  3. https://zimbra.com/privacy-policy – excluded by robots.txt
  4. https://zimbra.com/legal/privacy-policy – excluded by robots.txt
  5. https://zimbra.com/legal/privacy-notice – excluded by robots.txt
  6. https://zimbra.com/trust/privacy – excluded by robots.txt
  7. https://zimbra.com/datenschutz – excluded by robots.txt

Is this wrong? Send us the URL

Across the market: Named privacy contact in Email hosting: 13 of 37 companies

History

Not enough completed runs yet to draw a line. The next runs fill this in.

Prepare your vendor review

A source is a starting point. Check the product, plan, legal entity and date before treating it as evidence for your purchase. These questions do not change the transparency score.

Zimbra

0 found · 2 not found · 10 not measured across 12 public checks.

2 of 12 criteria have a measured result from the last 30 days. Oldest dated result: 2026-09-28.

Investigate 12 open evidence questions
  1. Data processing agreement

    Please share the current data processing agreement for the product and plan we are considering, including its annexes and signing process.

    Inspect this check
  2. Subprocessor list

    Which subprocessors apply to our product, what does each process, and in which countries? Please share the current list.

    Inspect this check
  3. Data location stated

    Which locations apply to our primary data, backups and support access? Which region can we select for this plan?

    Inspect this check
  4. Status page with history

    Where can we review incident history for the service we will use, and how do we subscribe to incident updates?

    Inspect this check
  5. Public pricing

    Please confirm the total cost for our seats and usage, including minimum commitments, add-ons, overages and renewal terms.

    Inspect this check
  6. Certifications named

    Please share the current certificate or audit report and its scope, covered legal entity, products and validity period.

    Inspect this check
  7. Uptime SLA with a figure

    Which availability commitment applies to our plan? Please include the measurement window, exclusions and credit claim process.

    Inspect this check
  8. HTTPS enforced with HSTS

    How is HTTPS enforced on the product and sign-in domains we will use? Please distinguish those domains from the public website.

    Inspect this check
  9. No third-party tracking before consent

    Which third-party requests occur before a visitor makes a choice, and for what purpose? Please distinguish the public website from the product.

    Inspect this check
  10. security.txt (RFC 9116)

    Where should we report a vulnerability, and what acknowledgement and follow-up process should we expect?

    Inspect this check
  11. Notice before subprocessors change

    How will you notify us before a subprocessor changes, with how much notice, and what response options apply to our contract?

    Inspect this check
  12. Named privacy contact

    Which privacy contact handles requests for our account, and what escalation path should we use?

    Inspect this check

Compare

A shortlist holds up to six vendors across categories and lives entirely in the address of its page: share the link, bookmark it, put it in a ticket. Nothing is stored, so we do not know it exists.