# SaaS Ranking > SaaS vendors ranked by what they publish about how they handle your data. > 5117 vendors across 200 categories, measured by us > on 12 criteria. Every result links the page we found it on > and carries the date we checked it. > Last completed measurement run: 2026-09-04. ## The one rule that shapes every sentence on this site A negative result always describes OUR measurement and is never a property of the vendor. We write "No data processing agreement found, checked 8 addresses on 2026-08-31". We never write "Vendor X has no DPA": the contract may sit behind a login, and the sentence would be an untrue statement of fact about a real company. There are three states, not two: - found we found it, and the source URL is on the page - not found we reached at least one address and none of them carried it - not measured we reached nothing, or robots.txt asks us not to "not measured" says something about US. HTTP 403, 429 and 5xx are recorded as not measured, never as "no". A vendor who blocks our crawler is left out of the percentages rather than scored badly. A vendor measured on fewer than 9 of the 12 criteria gets no score and no rank at all: a score out of three measurements looks like a score out of twelve and is not one. **If you quote a number from this site, quote its date with it.** We re-measure continuously; a figure without its date is not our figure. ## No paid placement, ever Nobody can pay to appear here, to appear higher, or to be left out. There is no advertising slot in any ranking. How the site is financed is on https://saas-ranking.com/about. ## The criteria and their weights - Data processing agreement (weight 3): Without a published DPA you cannot review the contract before you talk to sales. https://saas-ranking.com/criteria/data-processing-agreement - Subprocessor list (weight 3): Naming the actual subprocessors is what turns a privacy promise into something you can check. https://saas-ranking.com/criteria/subprocessor-list - Data location stated (weight 3): Where the data physically sits decides which law applies to it. https://saas-ranking.com/criteria/data-location - Status page with history (weight 2): A status page without past incidents tells you nothing about reliability. https://saas-ranking.com/criteria/status-page - Public pricing (weight 2): Hidden pricing moves the first comparison into a sales call. https://saas-ranking.com/criteria/public-pricing - Certifications named (weight 1): Naming SOC 2 or ISO 27001 publicly is the low bar; not naming them is a signal. https://saas-ranking.com/criteria/certifications - Uptime SLA with a figure (weight 1): "High availability" is marketing. "99.9 %" is a commitment. https://saas-ranking.com/criteria/uptime-sla - HTTPS enforced with HSTS (weight 2): We measure this ourselves on their own site. It is the cheapest security control there is. https://saas-ranking.com/criteria/https-enforced - No third-party tracking before consent (weight 2): We load their front page and count third-party requests before anything is clicked. https://saas-ranking.com/criteria/no-tracking-before-consent - security.txt (RFC 9116) (weight 1): It tells a researcher where to report a vulnerability instead of guessing. https://saas-ranking.com/criteria/security-txt - Notice before subprocessors change (weight 2): A list is a snapshot. Art. 28(2) GDPR gives you a right to object, and that needs advance notice. https://saas-ranking.com/criteria/subprocessor-notice - Named privacy contact (weight 1): "Contact us" is not a privacy contact. A named officer or a dedicated address is. https://saas-ranking.com/criteria/privacy-contact ## The band on the label Each vendor page shows the score as a band, A to F, with fixed thresholds: A 85 to 100, B 70 to 84, C 55 to 69, D 40 to 54, E 25 to 39, F 0 to 24. A vendor without a score has no band. ## Where the data is - Method, weights and how a score is computed: https://saas-ranking.com/methodology - Machine-readable, read only, no key needed: https://saas-ranking.com/developers documents every endpoint, every field and the three states; the entry point is https://saas-ranking.com/api/v1/criteria also /api/v1/categories, /api/v1/categories/, /api/v1/vendors/ No boolean values anywhere in it: a result is found, not_found or not_measured. - The measured detail behind the scores: https://saas-ranking.com/data/ 281 pages, one per value we read off vendor pages: which vendors name ISO 27001, which state EU hosting, whose front page loads which tracker. Every entry carries the sentence it was read from and the date. These are QUOTES, not verdicts, and they do not enter any score. - Nothing comparable has changed between our last two runs yet, so https://saas-ranking.com/changes carries the measurement progress instead of a list. - Check any domain against these criteria yourself: https://saas-ranking.com/check - How our crawler behaves and how to exclude it: https://saas-ranking.com/bot - Something wrong? https://saas-ranking.com/correction - the next run picks it up. - Who runs this: https://saas-ranking.com/imprint