SaaS Ranking

Cerenade

cerenade.com · Legal practice management · checked 2026-09-15

48/100DBand D

Rank 1 of 50 in Legal practice management, where the median is 17.

We measured 12 of 12 criteria for Cerenade on 2026-09-15. We found 5 with a source and did not find 7 at the addresses we checked. That is a transparency score of 48 out of 100, band D.

Overview

0 days since the newest finding, 0 since the oldest. 12 of 12 criteria measured in the last 30 days.

Evidence freshness is a statement about our measurement and is kept apart from the transparency score, which is frozen at v1. How good our own measurement is.

Transparency labelsaas-ranking.com

Cerenade

cerenade.com · Legal practice management

  1. A
  2. B
  3. C
  4. D
  5. E
  6. F
D 48of 100 Rank 1 of 50

Published commitments4 of 9 found

Measured behaviour1 of 3 found

Checked 2026-09-15. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.

The evidence pack carries every criterion with its source, the addresses we checked, the date and the data snapshot id – the four things a procurement file needs and a screenshot loses. We do not issue badges: a badge is the first step towards a paid placement, and there is none here.

The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.

Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that Cerenade has no such document.

Where Cerenade sits in Legal practice management

  1. A0 0%
  2. B0 0%
  3. C0 0%
  4. D2 4%
  5. E14 28%
  6. F34 68%
50 vendors with a score; 3 more without a score because we could measure too little. Bands have fixed thresholds, see how the score works.

The band of Cerenade is marked. Vendors without a score are the ones where we could measure too few criteria to rank them – a gap on our side, counted separately.

What they state

The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.

Gaps, heaviest first

Data location stated

weight 3 of 3

No statement about data location found.

Checked 7 addresses on 2026-09-15.

Show the 7 addresses we checked
  1. https://cerenade.com/security – reached, no match (HTTP 200)
  2. https://cerenade.com/trust – reached, no match (HTTP 404)
  3. https://cerenade.com/legal/privacy – reached, no match (HTTP 404)
  4. https://cerenade.com/privacy – reached, no match (HTTP 404)
  5. https://cerenade.com/privacy-policy – reached, no match (HTTP 200)
  6. https://cerenade.com/compliance – reached, no match (HTTP 404)
  7. https://cerenade.com/legal/privacy-policy – reached, no match (HTTP 200)

Is this wrong? Send us the URL

Status page with history

weight 2 of 3

No public status page found.

Checked 3 addresses on 2026-09-15.

Show the 3 addresses we checked
  1. https://status.cerenade.com/ – Could not be fetched: fetch failed.
  2. https://cerenade.com/status – reached, no match (HTTP 404)
  3. https://cerenade.com.statuspage.io/ – Could not be fetched: fetch failed.

Is this wrong? Send us the URL

Public pricing

weight 2 of 3

No public pricing with figures found.

Checked 5 addresses on 2026-09-15.

Show the 5 addresses we checked
  1. https://cerenade.com/pricing – reached, no match (HTTP 404)
  2. https://cerenade.com/pricing/ – reached, no match (HTTP 404)
  3. https://cerenade.com/plans – reached, no match (HTTP 404)
  4. https://cerenade.com/en/pricing – reached, no match (HTTP 404)
  5. https://cerenade.com/pricing-plans – reached, no match (HTTP 404)

Is this wrong? Send us the URL

No third-party tracking before consent

weight 2 of 3

Third-party requests seen on the first load, before any interaction.

Checked 1 address on 2026-09-15.

Show the 1 address we checked
  1. https://cerenade.com/ – third-party requests before any interaction: 45248900.fs1.hubspotusercontent-na1.net, api.hubapi.com, app.hubspot.com, connect.facebook.net, cta-service-cms2.hubspot.com, fonts.gstatic.com, forms-na1.hsforms.com, forms.hscollectedforms.net, forms.hsforms.com, js.hs-analytics.net, js.hs-banner.com, js.hsadspixel.net, js.hscollectedforms.net, js.hsforms.net, js.hubspot.com, mpc2-prod-26-is5qnl632q-uc.a.run.app, pagead2.googlesyndication.com, perf-na1.hsforms.com, px.ads.linkedin.com, region1.google-analytics.com, snap.licdn.com, static.hotjar.com, track.hubspot.com, www.clickcease.com, www.facebook.com, www.google.com, www.googletagmanager.com, www.gstatic.com

Is this wrong? Send us the URL

Uptime SLA with a figure

weight 1 of 3

No uptime figure found.

Checked 6 addresses on 2026-09-15.

Show the 6 addresses we checked
  1. https://cerenade.com/legal/sla – reached, no match (HTTP 404)
  2. https://cerenade.com/sla – reached, no match (HTTP 404)
  3. https://cerenade.com/legal/service-level-agreement – reached, no match (HTTP 404)
  4. https://cerenade.com/trust/sla – reached, no match (HTTP 404)
  5. https://cerenade.com/uptime – reached, no match (HTTP 404)
  6. https://cerenade.com/legal/uptime-sla – reached, no match (HTTP 404)

Is this wrong? Send us the URL

security.txt (RFC 9116)

weight 1 of 3

No security.txt found.

Checked 1 address on 2026-09-15.

Show the 1 address we checked
  1. https://cerenade.com/.well-known/security.txt – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Named privacy contact

weight 1 of 3

No named privacy contact found.

Checked 7 addresses on 2026-09-15.

Show the 7 addresses we checked
  1. https://cerenade.com/legal/privacy – reached, no match (HTTP 404)
  2. https://cerenade.com/privacy – reached, no match (HTTP 404)
  3. https://cerenade.com/privacy-policy – reached, no match (HTTP 200)
  4. https://cerenade.com/legal/privacy-policy – reached, no match (HTTP 200)
  5. https://cerenade.com/legal/privacy-notice – reached, no match (HTTP 404)
  6. https://cerenade.com/trust/privacy – reached, no match (HTTP 404)
  7. https://cerenade.com/datenschutz – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Evidence

The full source lists sit behind these two groups, so that the answer above stays readable.

Published, with a source 5

Data processing agreement

weight 3 of 3

Published and readable without a login.

Source: https://cerenade.com/legal/data-processing-addendum · checked 2026-09-15

Subprocessor list

weight 3 of 3

The actual list is published, not just a promise to keep one.

Source: https://cerenade.com/legal/subprocessors · checked 2026-09-15

HTTPS enforced with HSTS

weight 2 of 3

HTTP redirects to HTTPS and the HSTS header is set.

  • HSTS max-age 31536000 seconds (365 days).
    Show the exact wording

    max-age=31536000

    Read at https://cerenade.com/

Source: https://cerenade.com/ · checked 2026-09-15

Notice before subprocessors change

weight 2 of 3

The vendor commits publicly to giving notice before the list changes.

Source: https://cerenade.com/legal/subprocessors · checked 2026-09-15

Certifications named

weight 1 of 3

SOC 2 or ISO 27001 named on a public page.

  • Named on that page FedRAMP (not counted: the sentence does not carry it), HIPAA, ISO/IEC 27001 (not counted: the sentence does not carry it), PCI DSS (not counted: the sentence does not carry it), SOC 2 (unclear from the sentence). The sentence we kept does not carry this finding on its own, so it counts in no list and no figure.
    Show the 5 exact wordings

    ISO27001, SOC 1/2, FedRAMP, and additional compliance via Azure Cerenade solutions are hosted on Microsoft Azure, who we partn

    Read at https://cerenade.com/security

    HIPAA Cerenade is fully compliant with HIPAA.

    Read at https://cerenade.com/security

    Our security posture is actively managed to comply with the best industry standards across PCI DSS, ISO 27001, SOC TSP, and more.

    Read at https://cerenade.com/security

    Our security posture is actively managed to comply with the best industry standards across PCI DSS, ISO 27001, SOC TSP, and more.

    Read at https://cerenade.com/security

    ernational and industry-specific compliance standards, such as ISO 27001, HIPAA, FedRAMP, SOC 1 and SOC 2, as well as country-specific standards like Australia IRAP, UK G-Cloud, and Singapore MTCS.

    Read at https://cerenade.com/security

Source: https://cerenade.com/security · checked 2026-09-15

History

100 0 2026-09-14: 48 of 1002026-09-15: 48 of 100 2026-09-14 2026-09-15
Score over the last 2 runs we measured Cerenade in: 48 (2026-09-14), 48 (2026-09-15).

Compare

A shortlist holds up to six vendors across categories and lives entirely in the address of its page: share the link, bookmark it, put it in a ticket. Nothing is stored, so we do not know it exists.