Pega
pega.com · Low-code and internal tools · checked 2026-09-04
Rank 3 of 27 in Low-code and internal tools, where the median is 26.
- 6 found
- 6 not found
- 0 not measured
We measured 12 of 12 criteria for Pega on 2026-09-04. We found 6 with a source and did not find 6 at the addresses we checked. That is a transparency score of 52 out of 100, band D.
Overview
Transparency labelsaas-ranking.com
Pega
- A
- B
- C
- D
- E
- F
Published commitments5 of 9 found
- not foundData processing agreement×3
- foundSubprocessor list×3
- foundData location stated×3
- not foundStatus page with history×2
- not foundPublic pricing×2
- foundNotice before subprocessors change×2
- foundCertifications named×1
- not foundUptime SLA with a figure×1
- foundNamed privacy contact×1
Measured behaviour1 of 3 found
- foundHTTPS enforced with HSTS×2
- not foundNo third-party tracking before consent×2
- not foundsecurity.txt (RFC 9116)×1
Checked 2026-09-04. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.
We do not issue badges: a badge is the first step towards a paid placement, and there is none here. The SVG is a document with the date in it, for your own files.
The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.
Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that Pega has no such document.
What they state
The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.
- Named on that page CSA STAR, Cyber Essentials, FedRAMP, HIPAA, HITRUST CSF, ISO 9001, ISO 22301, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, PCI DSS, SOC 2, SOC 2 Type II, TISAX.
Show the 14 exact wordings
Diagnostic Center Pega GenAI Pega Blueprint *Assessment status applicable if Co-Browse is not used CSA STAR CSA STAR The Security, Trust, Assurance, and Risk (STAR) Registry is a publicly accessible r...
Read at https://www.pega.com/truststic Center Digital Messaging Pega Blueprint *Assessment status applicable if Co-Browse is not used Cyber Essentials Cyber Essentials Cyber Essentials is a UK Government-backed, industry-supported cer...
Read at https://www.pega.com/trustssessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used FedRAMP FedRAMP The Federal Risk and Authorization Management Program (FedRAMP) provides a standardi...
Read at https://www.pega.com/trustPega’s HITRUST Assessment + Certification covers all the HIPAA Compliance Factors including the HIPAA Breach Notification, HIPAA Privacy Rule, and the HIPAA Secur
Read at https://www.pega.com/trustService Pega Diagnostic Center *Assessment status applicable if VoiceAI and Co-Browse are not used HITRUST HITRUST Developed in collaboration with data protection professionals, the HITRUST CSF ration...
Read at https://www.pega.com/trustpdated (YYYY-MM-DD) 2025-12-16 Assessment scope Pega Cloud AWS & GCP Products All Pega AI and GenAI ISO 9001 ISO 9001 ISO 9001 is an international standard for quality management systems that applies....
Read at https://www.pega.com/trustssessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used ISO 22301 ISO 22301 Published by the International Organization for Standardization, ISO 22301 is de...
Read at https://www.pega.com/trustssessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used ISO 27001 ISO 27001 ISO/IEC 27001 is widely known, providing requirements for an information securit...
Read at https://www.pega.com/truststic Center Digital Messaging Pega Blueprint *Assessment status applicable if Co-Browse is not used ISO 27017 ISO 27017 ISO 27017 is an international standard offering guidance on information security...
Read at https://www.pega.com/truststic Center Digital Messaging Pega Blueprint *Assessment status applicable if Co-Browse is not used ISO 27018 ISO 27018 ISO 27018 is a standard that provides guidelines for protecting personally ident...
Read at https://www.pega.com/trustpe Pega Cloud Products Pega Cloud PCI/DSS PCI/DSS The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that ALL companies that accept, process,....
Read at https://www.pega.com/trustThe SOC 2 reports cover controls around security, availability, and confidentiality of customer data.
Read at https://www.pega.com/trustssessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used SOC 2 SOC 2, Type 2 The American Institute of Certified Public Accountants (AICPA) Service Organizat...
Read at https://www.pega.com/trustssessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used TISAX TISAX TISAX is an assessment and exchange mechanism for the information security of enterprise...
Read at https://www.pega.com/trust - Locations named next to the hosting wording India, Japan, Singapore, United States.
Show the 4 exact wordings
ot limited to Australia, New Zealand, Brazil, Canada, United Kingdom, Germany, Netherlands, Poland, India, Japan, Singapore and the United States. Therefore, your personal information may be transferr...
Read at https://www.pega.com/privacyted to Australia, New Zealand, Brazil, Canada, United Kingdom, Germany, Netherlands, Poland, India, Japan, Singapore and the United States. Therefore, your personal information may be transferred, pro...
Read at https://www.pega.com/privacyAustralia, New Zealand, Brazil, Canada, United Kingdom, Germany, Netherlands, Poland, India, Japan, Singapore and the United States. Therefore, your personal information may be transferred, processed....
Read at https://www.pega.com/privacyland, Brazil, Canada, United Kingdom, Germany, Netherlands, Poland, India, Japan, Singapore and the United States. Therefore, your personal information may be transferred, processed and stored outside...
Read at https://www.pega.com/privacy - Infrastructure providers named on that list Amazon Web Services, Google Cloud.
Show the 2 exact wordings
Amazon Web Services
Read at https://www.pega.com/subprocessorsGoogle Cloud
Read at https://www.pega.com/subprocessors - What the privacy page carries Named data protection officer.
Show the exact wording
Data Protection Officer
Read at https://www.pega.com/privacy - Third-party hosts we saw on the first load 12 googleapis.com, googletagmanager.com, gstatic.com, imganalytics.com, ipify.org, ipinfo.io, newrelic.com, nr-data.net, pega.digital, script.ac, trustarc.com, truste.com.
Show the 12 exact wordings
fonts.googleapis.com
Read at https://pega.com/www.googletagmanager.com
Read at https://pega.com/fonts.gstatic.com
Read at https://pega.com/s.imganalytics.com
Read at https://pega.com/api.ipify.org
Read at https://pega.com/ipinfo.io
Read at https://pega.com/js-agent.newrelic.com
Read at https://pega.com/bam.nr-data.net
Read at https://pega.com/widget.use1.chat.pega.digital
Read at https://pega.com/sonar.script.ac
Read at https://pega.com/consent.trustarc.com
Read at https://pega.com/consent.truste.com
Read at https://pega.com/ - HSTS max-age 31536000 seconds (365 days).
Show the exact wording
max-age=31536000; includeSubDomains; preload
Read at https://pega.com/ - HSTS options includeSubDomains, preload.
Show the 2 exact wordings
max-age=31536000; includeSubDomains; preload
Read at https://pega.com/max-age=31536000; includeSubDomains; preload
Read at https://pega.com/
Gaps, heaviest first
Data processing agreement
weight 3 of 3No data processing agreement found.
Checked 8 addresses on 2026-09-04.
Show the 8 addresses we checked
https://pega.com/legal/dpa– reached, no match (HTTP 404)https://pega.com/dpa– blocked or unavailable (HTTP 503)https://pega.com/legal/data-processing-agreement– reached, no match (HTTP 404)https://pega.com/data-processing-agreement– reached, no match (HTTP 404)https://pega.com/legal/data-processing-addendum– reached, no match (HTTP 404)https://pega.com/legal/gdpr– reached, no match (HTTP 404)https://pega.com/trust/dpa– reached, no match (HTTP 404)https://pega.com/privacy/dpa– reached, no match (HTTP 404)
Status page with history
weight 2 of 3No public status page found.
Checked 3 addresses on 2026-09-04.
Show the 3 addresses we checked
https://status.pega.com/– The name "status.pega.com" could not be resolved.https://pega.com/status– reached, no match (HTTP 404)https://pega.com.statuspage.io/– Could not be fetched: fetch failed.
Public pricing
weight 2 of 3No public pricing with figures found.
Checked 5 addresses on 2026-09-04.
Show the 5 addresses we checked
https://pega.com/pricing– reached, no match (HTTP 404)https://pega.com/pricing/– reached, no match (HTTP 404)https://pega.com/plans– reached, no match (HTTP 404)https://pega.com/en/pricing– reached, no match (HTTP 404)https://pega.com/pricing-plans– reached, no match (HTTP 404)
No third-party tracking before consent
weight 2 of 3No consent-free first load found.
- Third-party hosts we saw on the first load 12 googleapis.com, googletagmanager.com, gstatic.com, imganalytics.com, ipify.org, ipinfo.io, newrelic.com, nr-data.net, pega.digital, script.ac, trustarc.com, truste.com.
Show the 12 exact wordings
fonts.googleapis.com
Read at https://pega.com/www.googletagmanager.com
Read at https://pega.com/fonts.gstatic.com
Read at https://pega.com/s.imganalytics.com
Read at https://pega.com/api.ipify.org
Read at https://pega.com/ipinfo.io
Read at https://pega.com/js-agent.newrelic.com
Read at https://pega.com/bam.nr-data.net
Read at https://pega.com/widget.use1.chat.pega.digital
Read at https://pega.com/sonar.script.ac
Read at https://pega.com/consent.trustarc.com
Read at https://pega.com/consent.truste.com
Read at https://pega.com/
Checked 1 address on 2026-09-04.
Show the 1 address we checked
https://pega.com/– third-party requests before any interaction: api.ipify.org, bam.nr-data.net, consent.trustarc.com, consent.truste.com, fonts.googleapis.com, fonts.gstatic.com, ipinfo.io, js-agent.newrelic.com, s.imganalytics.com, sonar.script.ac, widget.use1.chat.pega.digital, www.googletagmanager.com
Uptime SLA with a figure
weight 1 of 3No uptime figure found.
Checked 6 addresses on 2026-09-04.
Show the 6 addresses we checked
https://pega.com/legal/sla– reached, no match (HTTP 404)https://pega.com/sla– reached, no match (HTTP 404)https://pega.com/legal/service-level-agreement– reached, no match (HTTP 404)https://pega.com/trust/sla– reached, no match (HTTP 404)https://pega.com/uptime– reached, no match (HTTP 404)https://pega.com/legal/uptime-sla– reached, no match (HTTP 404)
security.txt (RFC 9116)
weight 1 of 3No security.txt found.
Checked 1 address on 2026-09-04.
Show the 1 address we checked
https://pega.com/.well-known/security.txt– reached, no match (HTTP 404)
Evidence
The full source lists sit behind these two groups, so that the answer above stays readable.
Published, with a source 6
Subprocessor list
weight 3 of 3The actual list is published, not just a promise to keep one.
- Infrastructure providers named on that list Amazon Web Services, Google Cloud.
Show the 2 exact wordings
Amazon Web Services
Read at https://www.pega.com/subprocessorsGoogle Cloud
Read at https://www.pega.com/subprocessors
Source: https://www.pega.com/subprocessors · checked 2026-09-04
Data location stated
weight 3 of 3The hosting location is stated on a public page.
- Locations named next to the hosting wording India, Japan, Singapore, United States.
Show the 4 exact wordings
ot limited to Australia, New Zealand, Brazil, Canada, United Kingdom, Germany, Netherlands, Poland, India, Japan, Singapore and the United States. Therefore, your personal information may be transferr...
Read at https://www.pega.com/privacyted to Australia, New Zealand, Brazil, Canada, United Kingdom, Germany, Netherlands, Poland, India, Japan, Singapore and the United States. Therefore, your personal information may be transferred, pro...
Read at https://www.pega.com/privacyAustralia, New Zealand, Brazil, Canada, United Kingdom, Germany, Netherlands, Poland, India, Japan, Singapore and the United States. Therefore, your personal information may be transferred, processed....
Read at https://www.pega.com/privacyland, Brazil, Canada, United Kingdom, Germany, Netherlands, Poland, India, Japan, Singapore and the United States. Therefore, your personal information may be transferred, processed and stored outside...
Read at https://www.pega.com/privacy
Source: https://www.pega.com/privacy · checked 2026-09-04
HTTPS enforced with HSTS
weight 2 of 3HTTP redirects to HTTPS and the HSTS header is set.
- HSTS max-age 31536000 seconds (365 days).
Show the exact wording
max-age=31536000; includeSubDomains; preload
Read at https://pega.com/ - HSTS options includeSubDomains, preload.
Show the 2 exact wordings
max-age=31536000; includeSubDomains; preload
Read at https://pega.com/max-age=31536000; includeSubDomains; preload
Read at https://pega.com/
Source: https://pega.com/ · checked 2026-09-04
Notice before subprocessors change
weight 2 of 3The vendor commits publicly to giving notice before the list changes.
Source: https://www.pega.com/subprocessors · checked 2026-09-04
Certifications named
weight 1 of 3SOC 2 or ISO 27001 named on a public page.
- Named on that page CSA STAR, Cyber Essentials, FedRAMP, HIPAA, HITRUST CSF, ISO 9001, ISO 22301, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, PCI DSS, SOC 2, SOC 2 Type II, TISAX.
Show the 14 exact wordings
Diagnostic Center Pega GenAI Pega Blueprint *Assessment status applicable if Co-Browse is not used CSA STAR CSA STAR The Security, Trust, Assurance, and Risk (STAR) Registry is a publicly accessible r...
Read at https://www.pega.com/truststic Center Digital Messaging Pega Blueprint *Assessment status applicable if Co-Browse is not used Cyber Essentials Cyber Essentials Cyber Essentials is a UK Government-backed, industry-supported cer...
Read at https://www.pega.com/trustssessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used FedRAMP FedRAMP The Federal Risk and Authorization Management Program (FedRAMP) provides a standardi...
Read at https://www.pega.com/trustPega’s HITRUST Assessment + Certification covers all the HIPAA Compliance Factors including the HIPAA Breach Notification, HIPAA Privacy Rule, and the HIPAA Secur
Read at https://www.pega.com/trustService Pega Diagnostic Center *Assessment status applicable if VoiceAI and Co-Browse are not used HITRUST HITRUST Developed in collaboration with data protection professionals, the HITRUST CSF ration...
Read at https://www.pega.com/trustpdated (YYYY-MM-DD) 2025-12-16 Assessment scope Pega Cloud AWS & GCP Products All Pega AI and GenAI ISO 9001 ISO 9001 ISO 9001 is an international standard for quality management systems that applies....
Read at https://www.pega.com/trustssessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used ISO 22301 ISO 22301 Published by the International Organization for Standardization, ISO 22301 is de...
Read at https://www.pega.com/trustssessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used ISO 27001 ISO 27001 ISO/IEC 27001 is widely known, providing requirements for an information securit...
Read at https://www.pega.com/truststic Center Digital Messaging Pega Blueprint *Assessment status applicable if Co-Browse is not used ISO 27017 ISO 27017 ISO 27017 is an international standard offering guidance on information security...
Read at https://www.pega.com/truststic Center Digital Messaging Pega Blueprint *Assessment status applicable if Co-Browse is not used ISO 27018 ISO 27018 ISO 27018 is a standard that provides guidelines for protecting personally ident...
Read at https://www.pega.com/trustpe Pega Cloud Products Pega Cloud PCI/DSS PCI/DSS The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that ALL companies that accept, process,....
Read at https://www.pega.com/trustThe SOC 2 reports cover controls around security, availability, and confidentiality of customer data.
Read at https://www.pega.com/trustssessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used SOC 2 SOC 2, Type 2 The American Institute of Certified Public Accountants (AICPA) Service Organizat...
Read at https://www.pega.com/trustssessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used TISAX TISAX TISAX is an assessment and exchange mechanism for the information security of enterprise...
Read at https://www.pega.com/trust
Source: https://www.pega.com/trust · checked 2026-09-04
Named privacy contact
weight 1 of 3A data protection officer or a dedicated privacy address is named.
- What the privacy page carries Named data protection officer.
Show the exact wording
Data Protection Officer
Read at https://www.pega.com/privacy
Source: https://www.pega.com/privacy · checked 2026-09-04
History
Not enough completed runs yet to draw a line. The next runs fill this in.