SaaS Ranking

Security and compliance / Privileged access management

ConductorOne

What ConductorOne publishes on conductorone.com, measured on 2026-09-02. Every line links the page we found it on, or lists the addresses we checked.

Transparency 61/100 CBand C

Rank 2 of 11 in Privileged access managementcategory median 22checked 2026-09-02

4 gaps found: 4 criteria not found at the addresses we checked. 8 found4 not found0 not measured

Public transparency score, not a product or security rating.

Transparency labelsaas-ranking.com

ConductorOne

conductorone.com · Privileged access management

  1. A
  2. B
  3. C
  4. D
  5. E
  6. F
C 61of 100 Rank 2 of 11

Published commitments6 of 9 found

Measured behaviour2 of 3 found

Checked 2026-09-02. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.

We do not issue badges: a badge is the first step towards a paid placement, and there is none here. The SVG is a document with the date in it, for your own files.

Show the full transparency label

Transparency labelsaas-ranking.com

ConductorOne

conductorone.com · Privileged access management

  1. A
  2. B
  3. C
  4. D
  5. E
  6. F
C 61of 100 Rank 2 of 11

Published commitments6 of 9 found

Measured behaviour2 of 3 found

Checked 2026-09-02. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.

We do not issue badges: a badge is the first step towards a paid placement, and there is none here. The SVG is a document with the date in it, for your own files.

Not found, heaviest first

Data location stated

weight 3 of 3

No statement about data location found.

Checked 7 addresses on 2026-09-02.

Show the 7 addresses we checked
  1. https://conductorone.com/security – reached, no match (HTTP 200)
  2. https://conductorone.com/trust – reached, no match (HTTP 404)
  3. https://conductorone.com/legal/privacy – reached, no match (HTTP 404)
  4. https://conductorone.com/privacy – reached, no match (HTTP 404)
  5. https://conductorone.com/privacy-policy – reached, no match (HTTP 200)
  6. https://conductorone.com/compliance – reached, no match (HTTP 404)
  7. https://conductorone.com/legal/privacy-policy – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Status page with history

weight 2 of 3

No public status page found.

Checked 3 addresses on 2026-09-02.

Show the 3 addresses we checked
  1. https://status.conductorone.com/ – reached, no match (HTTP 200)
  2. https://conductorone.com/status – reached, no match (HTTP 404)
  3. https://conductorone.com.statuspage.io/ – Could not be fetched: fetch failed.

Is this wrong? Send us the URL

Public pricing

weight 2 of 3

No public pricing with figures found.

Checked 5 addresses on 2026-09-02.

Show the 5 addresses we checked
  1. https://conductorone.com/pricing – reached and rendered, no match
  2. https://conductorone.com/pricing/ – reached, no match (HTTP 200)
  3. https://conductorone.com/plans – reached, no match (HTTP 404)
  4. https://conductorone.com/en/pricing – reached, no match (HTTP 404)
  5. https://conductorone.com/pricing-plans – reached, no match (HTTP 404)

Is this wrong? Send us the URL

No third-party tracking before consent

weight 2 of 3

No consent-free first load found.

Checked 1 address on 2026-09-02.

Show the 1 address we checked
  1. https://conductorone.com/ – third-party requests before any interaction: alb.reddit.com, api.cr-relay.com, api.hubapi.com, api.vector.co, arclight.vimeo.com, b2bjsstore.s3.us-west-2.amazonaws.com, bat.bing.com, c1ai.chilipiper.com, cdn-cookieyes.com, cdn.cr-relay.com, cdn.seamintent.ai, cdn.vector.co, connect.facebook.net, d.adroll.com, directory.cookieyes.com, f.vimeocdn.com, fonts.googleapis.com, fonts.gstatic.com, forms.hscollectedforms.net, forms.hsforms.com, i.vimeocdn.com, js.hs-analytics.net, js.hs-banner.com, js.hs-scripts.com, js.hsadspixel.net, js.hscollectedforms.net, js.hubspot.com, log.cookieyes.com, pagead2.googlesyndication.com, player.vimeo.com, px.ads.linkedin.com, region1.google-analytics.com, s.adroll.com, s3-us-west-2.amazonaws.com, snap.licdn.com, vimeo.com, vod-adaptive-ak.vimeocdn.com, www.c1.ai, www.googletagmanager.com, www.redditstatic.com

Is this wrong? Send us the URL

Published evidence 8

Data processing agreement

weight 3 of 3

Published and readable without a login.

Source: https://www.c1.ai/legal/dpa · checked 2026-09-02

Subprocessor list

weight 3 of 3

The actual list is published, not just a promise to keep one.

Source: https://www.c1.ai/legal/subprocessors · checked 2026-09-02

HTTPS enforced with HSTS

weight 2 of 3

HTTP redirects to HTTPS and the HSTS header is set.

Source: https://conductorone.com/ · checked 2026-09-02

Notice before subprocessors change

weight 2 of 3

The vendor commits publicly to giving notice before the list changes.

Source: https://www.c1.ai/legal/subprocessors · checked 2026-09-02

Certifications named

weight 1 of 3

SOC 2 or ISO 27001 named on a public page.

Source: https://www.c1.ai/security · checked 2026-09-02

Uptime SLA with a figure

weight 1 of 3

An availability commitment with a figure.

Source: https://www.c1.ai/sla · checked 2026-09-02

security.txt (RFC 9116)

weight 1 of 3

Served at /.well-known/security.txt.

Source: https://www.c1.ai/.well-known/security.txt · checked 2026-09-02

Named privacy contact

weight 1 of 3

A data protection officer or a dedicated privacy address is named.

Source: https://www.c1.ai/privacy-policy · checked 2026-09-02

Keep going