incident.io
incident.io · Incident management · checked 2026-09-04
Rank 2 of 23 in Incident management, where the median is 30.
- 8 found
- 4 not found
- 0 not measured
We measured 12 of 12 criteria for incident.io on 2026-09-04. We found 8 with a source and did not find 4 at the addresses we checked. That is a transparency score of 65 out of 100, band C.
Overview
Transparency labelsaas-ranking.com
incident.io
- A
- B
- C
- D
- E
- F
Published commitments6 of 9 found
- foundData processing agreement×3
- foundSubprocessor list×3
- not foundData location stated×3
- not foundStatus page with history×2
- foundPublic pricing×2
- foundNotice before subprocessors change×2
- foundCertifications named×1
- foundUptime SLA with a figure×1
- not foundNamed privacy contact×1
Measured behaviour2 of 3 found
- foundHTTPS enforced with HSTS×2
- not foundNo third-party tracking before consent×2
- foundsecurity.txt (RFC 9116)×1
Checked 2026-09-04. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.
We do not issue badges: a badge is the first step towards a paid placement, and there is none here. The SVG is a document with the date in it, for your own files.
The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.
Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that incident.io has no such document.
What they state
The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.
- Named on that page SOC 2.
Show the exact wording
We're SOC 2 Type I & II and GDPR compliant to ensure your data stays safe.
Read at https://incident.io/security - Highest uptime figure on that page 99.99 %.
Show the exact wording
rm Availability 99.9% 99.9% (b) Triggering of Notification following Ingestion of an Incident 99.9% 99.99% 3.1.1.
Read at https://incident.io/legal/sla - Infrastructure providers named on that list Sentry, Slack, Twilio.
Show the 3 exact wordings
Sentry
Read at https://incident.io/legal/sub-processorsSlack
Read at https://incident.io/legal/sub-processorsTwilio
Read at https://incident.io/legal/sub-processors - Third-party hosts we saw on the first load 12 amazonaws.com, doubleclick.net, google.com, google.de, googleapis.com, googlesyndication.com, googletagmanager.com, iubenda.com, lfeeder.com, noembed.com, onescreen.ai, redditstatic.com.
Show the 12 exact wordings
s3-us-west-2.amazonaws.com
Read at https://incident.io/stats.g.doubleclick.net
Read at https://incident.io/region1.analytics.google.com
Read at https://incident.io/www.google.de
Read at https://incident.io/ajax.googleapis.com
Read at https://incident.io/pagead2.googlesyndication.com
Read at https://incident.io/www.googletagmanager.com
Read at https://incident.io/cdn.iubenda.com, embeds.iubenda.com
Read at https://incident.io/sc.lfeeder.com
Read at https://incident.io/noembed.com
Read at https://incident.io/osai-cdn.onescreen.ai
Read at https://incident.io/www.redditstatic.com
Read at https://incident.io/ - HSTS max-age 63072000 seconds (730 days).
Show the exact wording
max-age=63072000; includeSubDomains; preload
Read at https://incident.io/ - HSTS options includeSubDomains, preload.
Show the 2 exact wordings
max-age=63072000; includeSubDomains; preload
Read at https://incident.io/max-age=63072000; includeSubDomains; preload
Read at https://incident.io/ - The file expires 2027-07-15. It was still valid when we checked on 2026-09-04.
Show the exact wording
Expires: 2027-07-15T12:00:00Z
Read at https://incident.io/.well-known/security.txt
Gaps, heaviest first
Data location stated
weight 3 of 3We found this behind a sign-in, so it is not published openly.
Seen at https://incident.io/legal/privacy · checked 2026-09-04
Show the 7 addresses we checked
https://incident.io/security– reached, no match (HTTP 200)https://incident.io/trust– reached, no match (HTTP 404)https://incident.io/legal/privacy– found, but behind a sign-inhttps://incident.io/privacy– found, but behind a sign-inhttps://incident.io/privacy-policy– reached, no match (HTTP 404)https://incident.io/compliance– reached, no match (HTTP 404)https://incident.io/legal/privacy-policy– reached, no match (HTTP 404)
Status page with history
weight 2 of 3No public status page found.
Checked 3 addresses on 2026-09-04.
Show the 3 addresses we checked
https://status.incident.io/– reached, no match (HTTP 200)https://incident.io/status– reached, no match (HTTP 404)https://incident.io.statuspage.io/– Could not be fetched: fetch failed.
No third-party tracking before consent
weight 2 of 3No consent-free first load found.
- Third-party hosts we saw on the first load 12 amazonaws.com, doubleclick.net, google.com, google.de, googleapis.com, googlesyndication.com, googletagmanager.com, iubenda.com, lfeeder.com, noembed.com, onescreen.ai, redditstatic.com.
Show the 12 exact wordings
s3-us-west-2.amazonaws.com
Read at https://incident.io/stats.g.doubleclick.net
Read at https://incident.io/region1.analytics.google.com
Read at https://incident.io/www.google.de
Read at https://incident.io/ajax.googleapis.com
Read at https://incident.io/pagead2.googlesyndication.com
Read at https://incident.io/www.googletagmanager.com
Read at https://incident.io/cdn.iubenda.com, embeds.iubenda.com
Read at https://incident.io/sc.lfeeder.com
Read at https://incident.io/noembed.com
Read at https://incident.io/osai-cdn.onescreen.ai
Read at https://incident.io/www.redditstatic.com
Read at https://incident.io/
Checked 1 address on 2026-09-04.
Show the 1 address we checked
https://incident.io/– third-party requests before any interaction: ajax.googleapis.com, cdn.iubenda.com, embeds.iubenda.com, noembed.com, osai-cdn.onescreen.ai, pagead2.googlesyndication.com, region1.analytics.google.com, s3-us-west-2.amazonaws.com, sc.lfeeder.com, stats.g.doubleclick.net, www.google.de, www.googletagmanager.com, www.redditstatic.com
Named privacy contact
weight 1 of 3We found this behind a sign-in, so it is not published openly.
Seen at https://incident.io/legal/privacy · checked 2026-09-04
Show the 7 addresses we checked
https://incident.io/legal/privacy– found, but behind a sign-inhttps://incident.io/privacy– found, but behind a sign-inhttps://incident.io/privacy-policy– reached, no match (HTTP 404)https://incident.io/legal/privacy-policy– reached, no match (HTTP 404)https://incident.io/legal/privacy-notice– reached, no match (HTTP 404)https://incident.io/trust/privacy– reached, no match (HTTP 404)https://incident.io/datenschutz– reached, no match (HTTP 404)
Evidence
The full source lists sit behind these two groups, so that the answer above stays readable.
Published, with a source 8
Data processing agreement
weight 3 of 3Published and readable without a login.
Source: https://incident.io/legal/data-processing-agreement · checked 2026-09-04
Subprocessor list
weight 3 of 3The actual list is published, not just a promise to keep one.
- Infrastructure providers named on that list Sentry, Slack, Twilio.
Show the 3 exact wordings
Sentry
Read at https://incident.io/legal/sub-processorsSlack
Read at https://incident.io/legal/sub-processorsTwilio
Read at https://incident.io/legal/sub-processors
Source: https://incident.io/legal/sub-processors · checked 2026-09-04
Public pricing
weight 2 of 3Actual numbers on a public page.
Source: https://incident.io/pricing · checked 2026-09-04
HTTPS enforced with HSTS
weight 2 of 3HTTP redirects to HTTPS and the HSTS header is set.
- HSTS max-age 63072000 seconds (730 days).
Show the exact wording
max-age=63072000; includeSubDomains; preload
Read at https://incident.io/ - HSTS options includeSubDomains, preload.
Show the 2 exact wordings
max-age=63072000; includeSubDomains; preload
Read at https://incident.io/max-age=63072000; includeSubDomains; preload
Read at https://incident.io/
Source: https://incident.io/ · checked 2026-09-04
Notice before subprocessors change
weight 2 of 3The vendor commits publicly to giving notice before the list changes.
Source: https://incident.io/legal/data-processing-agreement · checked 2026-09-04
Certifications named
weight 1 of 3SOC 2 or ISO 27001 named on a public page.
- Named on that page SOC 2.
Show the exact wording
We're SOC 2 Type I & II and GDPR compliant to ensure your data stays safe.
Read at https://incident.io/security
Source: https://incident.io/security · checked 2026-09-04
Uptime SLA with a figure
weight 1 of 3An availability commitment with a figure.
- Highest uptime figure on that page 99.99 %.
Show the exact wording
rm Availability 99.9% 99.9% (b) Triggering of Notification following Ingestion of an Incident 99.9% 99.99% 3.1.1.
Read at https://incident.io/legal/sla
Source: https://incident.io/legal/sla · checked 2026-09-04
security.txt (RFC 9116)
weight 1 of 3Served at /.well-known/security.txt.
- The file expires 2027-07-15. It was still valid when we checked on 2026-09-04.
Show the exact wording
Expires: 2027-07-15T12:00:00Z
Read at https://incident.io/.well-known/security.txt
Source: https://incident.io/.well-known/security.txt · checked 2026-09-04
History
Not enough completed runs yet to draw a line. The next runs fill this in.