{
  "generated_from": "https://saas-ranking.com/proposal-quoting/mercura",
  "disclaimer": "Every result describes what we found at the addresses we checked on the date given. It is not a statement about what the vendor does or does not have. The score is a public transparency score, not a product or security rating.",
  "snapshot": "r103.106280",
  "snapshot_run": 103,
  "score_version": "v1",
  "vendor": {
    "name": "Mercura",
    "domain": "mercura.io"
  },
  "category": {
    "slug": "proposal-quoting",
    "name": "Proposals and quoting"
  },
  "score": 43,
  "band": "D",
  "measured": 12,
  "of": 12,
  "criteria": [
    {
      "key": "dpa",
      "name": "Data processing agreement",
      "weight": 3,
      "result": "found",
      "source_url": "https://mercura.io/trust/dpa/",
      "addresses_checked": [
        {
          "url": "https://mercura.io/legal/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/data-processing-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/data-processing-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/data-processing-addendum",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/gdpr",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/trust/dpa",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "subprozessoren",
      "name": "Subprocessor list",
      "weight": 3,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://mercura.io/legal/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/sub-processors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/sub-processors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/trust/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/privacy/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/subprocessor-list",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "datenregion",
      "name": "Data location stated",
      "weight": 3,
      "result": "found",
      "source_url": "https://mercura.io/security/",
      "addresses_checked": [
        {
          "url": "https://mercura.io/security",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "statusseite",
      "name": "Status page with history",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://status.mercura.io/",
          "result": "The name \"status.mercura.io\" could not be resolved."
        },
        {
          "url": "https://mercura.io/status",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io.statuspage.io/",
          "result": "Could not be fetched: fetch failed."
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "preise",
      "name": "Public pricing",
      "weight": 2,
      "result": "found",
      "source_url": "https://mercura.io/pricing/",
      "addresses_checked": [
        {
          "url": "https://mercura.io/pricing",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "zertifizierungen",
      "name": "Certifications named",
      "weight": 1,
      "result": "found",
      "source_url": "https://mercura.io/security/",
      "addresses_checked": [
        {
          "url": "https://mercura.io/security",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "sla",
      "name": "Uptime SLA with a figure",
      "weight": 1,
      "result": "found",
      "source_url": "https://mercura.io/trust/sla/",
      "addresses_checked": [
        {
          "url": "https://mercura.io/legal/sla",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/sla",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/service-level-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/trust/sla",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "transport",
      "name": "HTTPS enforced with HSTS",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "http://mercura.io/",
          "result": "redirects to https://mercura.io/"
        },
        {
          "url": "https://mercura.io/",
          "result": "no HSTS header"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.988Z"
    },
    {
      "key": "tracker_vor_einwilligung",
      "name": "No third-party tracking before consent",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://mercura.io/",
          "result": "third-party requests before any interaction: pagead2.googlesyndication.com, region1.google-analytics.com, static.cloudflareinsights.com, www.googletagmanager.com"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.988Z"
    },
    {
      "key": "security_txt",
      "name": "security.txt (RFC 9116)",
      "weight": 1,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://mercura.io/.well-known/security.txt",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.988Z"
    },
    {
      "key": "subprozessor_meldung",
      "name": "Notice before subprocessors change",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://mercura.io/legal/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/sub-processors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/data-processing-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/trust/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/sub-processors",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.988Z"
    },
    {
      "key": "datenschutzkontakt",
      "name": "Named privacy contact",
      "weight": 1,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://mercura.io/legal/privacy",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/privacy",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/privacy-policy",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/privacy-policy",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/legal/privacy-notice",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/trust/privacy",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://mercura.io/datenschutz",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T10:53:08.988Z"
    }
  ],
  "details": [
    {
      "key": "datenregion",
      "name": "Hosting location named",
      "value": "european-union",
      "subject": null,
      "quote": "EU Hosted All data resides strictly within European Union borders.",
      "source_url": "https://mercura.io/security/",
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "datenregion",
      "name": "Hosting location named",
      "value": "frankfurt",
      "subject": null,
      "quote": "Object Storage : Static assets are stored in Amazon Web Services (AWS) data centers in Frankfurt (eu-central-1) and Ireland (eu-west-1).",
      "source_url": "https://mercura.io/security/",
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "datenregion",
      "name": "Hosting location named",
      "value": "germany",
      "subject": null,
      "quote": "Application & Database : Hosted with Hetzner Online GmbH in Germany (Nuremberg/Falkenstein) and Finland (Helsinki).",
      "source_url": "https://mercura.io/security/",
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "datenregion",
      "name": "Hosting location named",
      "value": "ireland",
      "subject": null,
      "quote": "Object Storage : Static assets are stored in Amazon Web Services (AWS) data centers in Frankfurt (eu-central-1) and Ireland (eu-west-1).",
      "source_url": "https://mercura.io/security/",
      "measured_on": "2026-09-14T10:53:08.987Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "cloudflareinsights.com",
      "subject": null,
      "quote": "static.cloudflareinsights.com",
      "source_url": "https://mercura.io/",
      "measured_on": "2026-09-14T10:53:08.988Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "google-analytics.com",
      "subject": null,
      "quote": "region1.google-analytics.com",
      "source_url": "https://mercura.io/",
      "measured_on": "2026-09-14T10:53:08.988Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "googlesyndication.com",
      "subject": null,
      "quote": "pagead2.googlesyndication.com",
      "source_url": "https://mercura.io/",
      "measured_on": "2026-09-14T10:53:08.988Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "googletagmanager.com",
      "subject": null,
      "quote": "www.googletagmanager.com",
      "source_url": "https://mercura.io/",
      "measured_on": "2026-09-14T10:53:08.988Z"
    },
    {
      "key": "sla_prozent",
      "name": "Uptime figure",
      "value": "99.5",
      "subject": null,
      "quote": "ce Availability Mercura guarantees that the CPQ solution will be available and operational at least 99.5% of the time during the following hours: Business Hours: Monday to Friday, 08:00 - 16:00 After-...",
      "source_url": "https://mercura.io/trust/sla/",
      "measured_on": "2026-09-14T10:53:08.988Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "iso-27001",
      "subject": "infrastruktur",
      "quote": "Certified Infrastructure Our data centers are ISO/IEC 27001:2022 certified.",
      "source_url": "https://mercura.io/security/",
      "measured_on": "2026-09-14T10:53:08.987Z"
    }
  ]
}