SaaS Ranking

Lyra Health

lyrahealth.com · Employee benefits · checked 2026-09-04

26/100EBand E

Rank 11 of 28 in Employee benefits, where the median is 19.5.

We measured 12 of 12 criteria for Lyra Health on 2026-09-04. We found 3 with a source and did not find 9 at the addresses we checked. That is a transparency score of 26 out of 100, band E.

Overview

Transparency labelsaas-ranking.com

Lyra Health

lyrahealth.com · Employee benefits

  1. A
  2. B
  3. C
  4. D
  5. E
  6. F
E 26of 100 Rank 11 of 28

Published commitments2 of 9 found

Measured behaviour1 of 3 found

Checked 2026-09-04. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.

We do not issue badges: a badge is the first step towards a paid placement, and there is none here. The SVG is a document with the date in it, for your own files.

The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.

Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that Lyra Health has no such document.

What they state

The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.

Gaps, heaviest first

Data processing agreement

weight 3 of 3

No data processing agreement found.

Checked 8 addresses on 2026-09-04.

Show the 8 addresses we checked
  1. https://lyrahealth.com/legal/dpa – reached, no match (HTTP 404)
  2. https://lyrahealth.com/dpa – reached, no match (HTTP 404)
  3. https://lyrahealth.com/legal/data-processing-agreement – reached, no match (HTTP 404)
  4. https://lyrahealth.com/data-processing-agreement – reached, no match (HTTP 404)
  5. https://lyrahealth.com/legal/data-processing-addendum – reached, no match (HTTP 404)
  6. https://lyrahealth.com/legal/gdpr – reached, no match (HTTP 404)
  7. https://lyrahealth.com/trust/dpa – reached, no match (HTTP 404)
  8. https://lyrahealth.com/privacy/dpa – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Subprocessor list

weight 3 of 3

No subprocessor list found.

Checked 7 addresses on 2026-09-04.

Show the 7 addresses we checked
  1. https://lyrahealth.com/legal/subprocessors – reached, no match (HTTP 404)
  2. https://lyrahealth.com/subprocessors – reached, no match (HTTP 404)
  3. https://lyrahealth.com/sub-processors – reached, no match (HTTP 404)
  4. https://lyrahealth.com/legal/sub-processors – reached, no match (HTTP 404)
  5. https://lyrahealth.com/trust/subprocessors – reached, no match (HTTP 404)
  6. https://lyrahealth.com/privacy/subprocessors – reached, no match (HTTP 404)
  7. https://lyrahealth.com/legal/subprocessor-list – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Status page with history

weight 2 of 3

No public status page found.

Checked 3 addresses on 2026-09-04.

Show the 3 addresses we checked
  1. https://status.lyrahealth.com/ – reached, no match (HTTP 200)
  2. https://lyrahealth.com/status – reached, no match (HTTP 404)
  3. https://lyrahealth.com.statuspage.io/ – Could not be fetched: fetch failed.

Is this wrong? Send us the URL

Public pricing

weight 2 of 3

No public pricing with figures found.

Checked 5 addresses on 2026-09-04.

Show the 5 addresses we checked
  1. https://lyrahealth.com/pricing – reached, no match (HTTP 404)
  2. https://lyrahealth.com/pricing/ – reached, no match (HTTP 404)
  3. https://lyrahealth.com/plans – reached, no match (HTTP 404)
  4. https://lyrahealth.com/en/pricing – reached, no match (HTTP 404)
  5. https://lyrahealth.com/pricing-plans – reached, no match (HTTP 404)

Is this wrong? Send us the URL

No third-party tracking before consent

weight 2 of 3

No consent-free first load found.

Checked 1 address on 2026-09-04.

Show the 1 address we checked
  1. https://lyrahealth.com/ – third-party requests before any interaction: cdn.cookielaw.org, cdn.vidyard.com, geolocation.onetrust.com, play.vidyard.com, www.googletagmanager.com

Is this wrong? Send us the URL

Notice before subprocessors change

weight 2 of 3

No commitment to give notice before subprocessors change found.

Checked 8 addresses on 2026-09-04.

Show the 8 addresses we checked
  1. https://lyrahealth.com/legal/subprocessors – reached, no match (HTTP 404)
  2. https://lyrahealth.com/subprocessors – reached, no match (HTTP 404)
  3. https://lyrahealth.com/sub-processors – reached, no match (HTTP 404)
  4. https://lyrahealth.com/legal/dpa – reached, no match (HTTP 404)
  5. https://lyrahealth.com/dpa – reached, no match (HTTP 404)
  6. https://lyrahealth.com/legal/data-processing-agreement – reached, no match (HTTP 404)
  7. https://lyrahealth.com/trust/subprocessors – reached, no match (HTTP 404)
  8. https://lyrahealth.com/legal/sub-processors – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Uptime SLA with a figure

weight 1 of 3

No uptime figure found.

Checked 6 addresses on 2026-09-04.

Show the 6 addresses we checked
  1. https://lyrahealth.com/legal/sla – reached, no match (HTTP 404)
  2. https://lyrahealth.com/sla – reached, no match (HTTP 404)
  3. https://lyrahealth.com/legal/service-level-agreement – reached, no match (HTTP 404)
  4. https://lyrahealth.com/trust/sla – reached, no match (HTTP 404)
  5. https://lyrahealth.com/uptime – reached, no match (HTTP 404)
  6. https://lyrahealth.com/legal/uptime-sla – reached, no match (HTTP 404)

Is this wrong? Send us the URL

security.txt (RFC 9116)

weight 1 of 3

No security.txt found.

Checked 1 address on 2026-09-04.

Show the 1 address we checked
  1. https://lyrahealth.com/.well-known/security.txt – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Named privacy contact

weight 1 of 3

We found this behind a sign-in, so it is not published openly.

Seen at https://www.lyrahealth.com/privacy-policy/ · checked 2026-09-04

Show the 7 addresses we checked
  1. https://lyrahealth.com/legal/privacy – reached, no match (HTTP 404)
  2. https://lyrahealth.com/privacy – reached, no match (HTTP 404)
  3. https://lyrahealth.com/privacy-policy – found, but behind a sign-in
  4. https://lyrahealth.com/legal/privacy-policy – reached, no match (HTTP 404)
  5. https://lyrahealth.com/legal/privacy-notice – reached, no match (HTTP 404)
  6. https://lyrahealth.com/trust/privacy – reached, no match (HTTP 404)
  7. https://lyrahealth.com/datenschutz – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Evidence

The full source lists sit behind these two groups, so that the answer above stays readable.

Published, with a source 3

Data location stated

weight 3 of 3

The hosting location is stated on a public page.

  • Locations named next to the hosting wording Canada, United States.
    Show the 2 exact wordings

    tion, will be transferred outside of the Canadian province in which it was collected and outside of Canada, and will be stored on servers in the United States or other countries.

    Read at https://www.lyrahealth.com/privacy-policy/

    Please note that, if you are using the Lyra Platform, your personal information will be stored within the United States, where privacy rules differ and may be less stringent than those of the country....

    Read at https://www.lyrahealth.com/privacy-policy/

Source: https://www.lyrahealth.com/privacy-policy/ · checked 2026-09-04

HTTPS enforced with HSTS

weight 2 of 3

HTTP redirects to HTTPS and the HSTS header is set.

  • HSTS max-age 63072000 seconds (730 days).
    Show the exact wording

    max-age=63072000; includeSubDomains;

    Read at https://lyrahealth.com/
  • HSTS options includeSubDomains.
    Show the exact wording

    max-age=63072000; includeSubDomains;

    Read at https://lyrahealth.com/

Source: https://lyrahealth.com/ · checked 2026-09-04

Certifications named

weight 1 of 3

SOC 2 or ISO 27001 named on a public page.

  • Named on that page HITRUST CSF, ISO/IEC 27001, SOC 2, SOC 2 Type II.
    Show the 4 exact wordings

    See Resources Resources Request all documents Hitrust Request SOC2 Type II Request ISO27001 Request Lyra Health Pen-test Summary Request Privacy Policy T

    Read at https://trust.lyrahealth.com/

    See Resources Resources Request all documents Hitrust Request SOC2 Type II Request ISO27001 Request Lyra Health Pen-test Summary Request Privacy Policy To learn more about our privacy click b

    Read at https://trust.lyrahealth.com/

    Vendor Due Diligence Review Vendor SOC 2 reports (or equivalent) are collected and reviewed on at least an annual basis.

    Read at https://trust.lyrahealth.com/

    See Resources Resources Request all documents Hitrust Request SOC2 Type II Request ISO27001 Request Lyra Health Pen-test Summary Request Privacy Policy To learn more

    Read at https://trust.lyrahealth.com/

Source: https://trust.lyrahealth.com/ · checked 2026-09-04

History

Not enough completed runs yet to draw a line. The next runs fill this in.

Compare