SaaS Ranking

Vast.ai

vast.ai · MLOps and model serving · checked 2026-09-05

52/100DBand D

Rank 4 of 33 in MLOps and model serving, where the median is 26.

We measured 12 of 12 criteria for Vast.ai on 2026-09-05. We found 6 with a source and did not find 6 at the addresses we checked. That is a transparency score of 52 out of 100, band D.

Overview

Transparency labelsaas-ranking.com

Vast.ai

vast.ai · MLOps and model serving

  1. A
  2. B
  3. C
  4. D
  5. E
  6. F
D 52of 100 Rank 4 of 33

Published commitments5 of 9 found

Measured behaviour1 of 3 found

Checked 2026-09-05. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.

The evidence pack carries every criterion with its source, the addresses we checked, the date and the data snapshot id – the four things a procurement file needs and a screenshot loses. We do not issue badges: a badge is the first step towards a paid placement, and there is none here.

The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.

Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that Vast.ai has no such document.

What they state

The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.

Gaps, heaviest first

Subprocessor list

weight 3 of 3

No subprocessor list found.

Checked 7 addresses on 2026-09-05.

Show the 7 addresses we checked
  1. https://vast.ai/legal/subprocessors – reached, no match (HTTP 404)
  2. https://vast.ai/subprocessors – reached, no match (HTTP 404)
  3. https://vast.ai/sub-processors – reached, no match (HTTP 404)
  4. https://vast.ai/legal/sub-processors – reached, no match (HTTP 404)
  5. https://vast.ai/trust/subprocessors – reached, no match (HTTP 404)
  6. https://vast.ai/privacy/subprocessors – reached, no match (HTTP 404)
  7. https://vast.ai/legal/subprocessor-list – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Status page with history

weight 2 of 3

No public status page found.

Checked 3 addresses on 2026-09-05.

Show the 3 addresses we checked
  1. https://status.vast.ai/ – reached, no match (HTTP 200)
  2. https://vast.ai/status – reached, no match (HTTP 200)
  3. https://vast.ai.statuspage.io/ – Could not be fetched: fetch failed.

Is this wrong? Send us the URL

No third-party tracking before consent

weight 2 of 3

No consent-free first load found.

Checked 1 address on 2026-09-05.

Show the 1 address we checked
  1. https://vast.ai/ – third-party requests before any interaction: cmp.osano.com, growthbook-cwfl3phrgq-uc.a.run.app, storage.googleapis.com, us-assets.i.posthog.com, us.posthog.com, www.googletagmanager.com

Is this wrong? Send us the URL

Notice before subprocessors change

weight 2 of 3

No commitment to give notice before subprocessors change found.

Checked 8 addresses on 2026-09-05.

Show the 8 addresses we checked
  1. https://vast.ai/legal/subprocessors – reached, no match (HTTP 404)
  2. https://vast.ai/subprocessors – reached, no match (HTTP 404)
  3. https://vast.ai/sub-processors – reached, no match (HTTP 404)
  4. https://vast.ai/legal/dpa – reached, no match (HTTP 404)
  5. https://vast.ai/dpa – reached, no match (HTTP 404)
  6. https://vast.ai/legal/data-processing-agreement – reached, no match (HTTP 404)
  7. https://vast.ai/trust/subprocessors – reached, no match (HTTP 404)
  8. https://vast.ai/legal/sub-processors – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Uptime SLA with a figure

weight 1 of 3

No uptime figure found.

Checked 6 addresses on 2026-09-05.

Show the 6 addresses we checked
  1. https://vast.ai/legal/sla – reached, no match (HTTP 404)
  2. https://vast.ai/sla – reached, no match (HTTP 404)
  3. https://vast.ai/legal/service-level-agreement – reached, no match (HTTP 404)
  4. https://vast.ai/trust/sla – reached, no match (HTTP 404)
  5. https://vast.ai/uptime – reached, no match (HTTP 404)
  6. https://vast.ai/legal/uptime-sla – reached, no match (HTTP 404)

Is this wrong? Send us the URL

security.txt (RFC 9116)

weight 1 of 3

No security.txt found.

Checked 1 address on 2026-09-05.

Show the 1 address we checked
  1. https://vast.ai/.well-known/security.txt – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Evidence

The full source lists sit behind these two groups, so that the answer above stays readable.

Published, with a source 6

Data processing agreement

weight 3 of 3

Published and readable without a login.

Source: https://vast.ai/data-processing-agreement · checked 2026-09-05

Data location stated

weight 3 of 3

The hosting location is stated on a public page.

  • Locations named next to the hosting wording United States.
    Show the exact wording

    The Website is hosted in the United States of America and is subject to U.S.

    Read at https://vast.ai/privacy

Source: https://vast.ai/privacy · checked 2026-09-05

Public pricing

weight 2 of 3

Actual numbers on a public page.

Source: https://vast.ai/pricing · checked 2026-09-05

HTTPS enforced with HSTS

weight 2 of 3

HTTP redirects to HTTPS and the HSTS header is set.

  • HSTS max-age 63072000 seconds (730 days).
    Show the exact wording

    max-age=63072000

    Read at https://vast.ai/

Source: https://vast.ai/ · checked 2026-09-05

Certifications named

weight 1 of 3

SOC 2 or ISO 27001 named on a public page.

  • Named on that page HIPAA, HITRUST CSF (named without a certification claim), ISO 22301 (named without a certification claim), ISO/IEC 27001 (named without a certification claim), PCI DSS (named without a certification claim), SOC 2 Type II.
    Show the 6 exact wordings

    HIPAA Vast.ai supports HIPAA-covered workloads on our Secure Cloud tier.

    Read at https://vast.ai/compliance

    may include: ISO 27001, ISO 20000-1, ISO 22301, ISO 14001 SOC 1 Type 2, SOC 2 Type 2, SOC 3 HIPAA, HITRUST, PCI DSS NIST frameworks Security certifications such as ISO 27001 or SOC 2 are encouraged an...

    Read at https://vast.ai/compliance

    d business identity Certifications held by datacenter partners may include: ISO 27001, ISO 20000-1, ISO 22301, ISO 14001 SOC 1 Type 2, SOC 2 Type 2, SOC 3 HIPAA, HITRUST, PCI DSS NIST frameworks Secur...

    Read at https://vast.ai/compliance

    security, ownership, and business identity Certifications held by datacenter partners may include: ISO 27001, ISO 20000-1, ISO 22301, ISO 14001 SOC 1 Type 2, SOC 2 Type 2, SOC 3 HIPAA, HITRUST, PCI DS...

    Read at https://vast.ai/compliance

    ude: ISO 27001, ISO 20000-1, ISO 22301, ISO 14001 SOC 1 Type 2, SOC 2 Type 2, SOC 3 HIPAA, HITRUST, PCI DSS NIST frameworks Security certifications such as ISO 27001 or SOC 2 are encouraged and streng...

    Read at https://vast.ai/compliance

    SOC 2 Type 2 Vast.ai has completed SOC 2 Type 2 certification.

    Read at https://vast.ai/compliance

Source: https://vast.ai/compliance · checked 2026-09-05

Named privacy contact

weight 1 of 3

A data protection officer or a dedicated privacy address is named.

  • What the privacy page carries Named data protection officer.
    Show the exact wording

    Data Protection Officer

    Read at https://vast.ai/privacy

Source: https://vast.ai/privacy · checked 2026-09-05

History

Not enough completed runs yet to draw a line. The next runs fill this in.

Compare

A shortlist holds up to six vendors across categories and lives entirely in the address of its page: share the link, bookmark it, put it in a ticket. Nothing is stored, so we do not know it exists.