Methodology
We check 10 things and link the source for every one of them. The weights below are ours and they are a judgement call, which is exactly why they are published. We never sell placement in a ranking.
The 10 criteria and their weights
| Criterion | Family | Weight | Why it counts |
|---|---|---|---|
| Data processing agreement | Published commitments | 3 | Without a published DPA you cannot review the contract before you talk to sales. |
| Subprocessor list | Published commitments | 3 | Naming the actual subprocessors is what turns a privacy promise into something you can check. |
| Data location stated | Published commitments | 3 | Where the data physically sits decides which law applies to it. |
| Status page with history | Published commitments | 2 | A status page without past incidents tells you nothing about reliability. |
| Public pricing | Published commitments | 2 | Hidden pricing moves the first comparison into a sales call. |
| Certifications named | Published commitments | 1 | Naming SOC 2 or ISO 27001 publicly is the low bar; not naming them is a signal. |
| Uptime SLA with a figure | Published commitments | 1 | "High availability" is marketing. "99.9 %" is a commitment. |
| HTTPS enforced with HSTS | Measured behaviour | 2 | We measure this ourselves on their own site. It is the cheapest security control there is. |
| No third-party tracking before consent | Measured behaviour | 2 | We load their front page and count third-party requests before anything is clicked. |
| security.txt (RFC 9116) | Measured behaviour | 1 | It tells a researcher where to report a vulnerability instead of guessing. |
The score is the weighted share of criteria we found, out of 20 possible points. A criterion we could not measure falls out of both sides of that calculation, so it never counts against a vendor.
Not found is not the same as not measured
Not found means we reached the vendor’s site and did not find the document at any of the addresses we checked. Those addresses are listed on the vendor page, with what each one returned. It does not mean the vendor has no such document: it may sit behind a login, or at an address we did not check. That is why every result carries a correction link.
Found, but behind a sign-in is its own result. It counts as not published openly, because that is what the criterion asks, but we say which it is. A vendor who has the document and shows it only to customers is in a different position from one where we found nothing.
Not measured means we could not look: the site did not answer, the vendor’s firewall blocked or rate-limited our crawler, or their robots.txt excludes us. That is a statement about us, not about them. It never counts against a vendor.
A vendor with fewer than 7 measured criteria gets no score and no rank at all, rather than a bad one.
If a vendor excludes our crawler
We honour robots.txt. A vendor who excludes us is not ranked and is not penalised for it: their entry says that we were excluded, and that is the end of it. Penalising someone for using a rule we ourselves respect would be absurd. See our crawler page.
How often we check
A full run visits every vendor in every category. The site only ever shows a run that finished. If a run breaks off halfway, you keep seeing the last complete one, because a half-finished run would put hundreds of vendors on “not found” for a fault on our side.
What we do not do
We do not collect user reviews, we do not aggregate anyone else’s ratings, and we have no opinion about whether a product is any good. We measure what a vendor publishes, and we link it.