Coro
coro.net · SIEM and security operations · checked 2026-09-04
Rank 11 of 24 in SIEM and security operations, where the median is 30.
- 4 found
- 8 not found
- 0 not measured
We measured 12 of 12 criteria for Coro on 2026-09-04. We found 4 with a source and did not find 8 at the addresses we checked. That is a transparency score of 30 out of 100, band E.
Overview
Transparency labelsaas-ranking.com
Coro
- A
- B
- C
- D
- E
- F
Published commitments4 of 9 found
- foundData processing agreement×3
- not foundSubprocessor list×3
- not foundData location stated×3
- not foundStatus page with history×2
- not foundPublic pricing×2
- foundNotice before subprocessors change×2
- foundCertifications named×1
- not foundUptime SLA with a figure×1
- foundNamed privacy contact×1
Measured behaviour0 of 3 found
- not foundHTTPS enforced with HSTS×2
- not foundNo third-party tracking before consent×2
- not foundsecurity.txt (RFC 9116)×1
Checked 2026-09-04. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.
The evidence pack carries every criterion with its source, the addresses we checked, the date and the data snapshot id – the four things a procurement file needs and a screenshot loses. We do not issue badges: a badge is the first step towards a paid placement, and there is none here.
The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.
Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that Coro has no such document.
What they state
The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.
- Named on that page HIPAA (named without a certification claim), ISO/IEC 27001 (named without a certification claim), PCI DSS (named without a certification claim), SOC 2 (named without a certification claim).
Show the 4 exact wordings
ignificantly engaged in providing financial products or services The Federal trade commission (FTC) HIPAA A series of regulatory standards that outline the lawful use and disclosure of protected healt...
Read at https://www.coro.net/compliancevices (CMS), the Federal Drug Administration (FDA), and the Federal Communications Commission (FCC) ISO 27001 (ISMS) Helps organizations protect their information in a systematic and cost-effective ma...
Read at https://www.coro.net/complianceformation on residents or those doing business in New York The office of the Attorney General (OAG) PCI DSS Protects credit, debit, and cash card transactions and prevent the misuse of cardholders' pe...
Read at https://www.coro.net/compliancepts card payments, including seasonal or small businesses Visa, Mastercard, AmEx, JCB, and Discover SOC2 Helps companies determine whether their business partners and vendors can securely manage data....
Read at https://www.coro.net/compliance - What the privacy page carries Named data protection officer.
Show the exact wording
Data Protection Officer
Read at https://www.coro.net/legal/privacy - Third-party hosts we saw on the first load 37 ads-twitter.com, amazonaws.com, amp.vg, bing.com, bing.net, brilliantchap.com, callrail.com, doubleclick.net, facebook.com, facebook.net, g2.com, g2crowd.com, google.com, google.de, googleapis.com, googletagmanager.com, gstatic.com, hs-analytics.net, hs-banner.com, hs-scripts.com, hsforms.com, hsforms.net, hubspot.com, intentsify.io, jsdelivr.net, licdn.com, metadata.io, reddit.com, redditstatic.com, salesloft.com, stackadapt.com, t.co, termly.io, twitter.com, unpkg.com, usbrowserspeed.com, usemessages.com.
Show the 37 exact wordings
static.ads-twitter.com
Read at https://coro.net/s3-us-west-2.amazonaws.com
Read at https://coro.net/coro.amp.vg
Read at https://coro.net/bat.bing.com
Read at https://coro.net/bat.bing.net
Read at https://coro.net/ob.brilliantchap.com, obs.brilliantchap.com
Read at https://coro.net/cdn.callrail.com
Read at https://coro.net/ad.doubleclick.net, stats.g.doubleclick.net
Read at https://coro.net/www.facebook.com
Read at https://coro.net/connect.facebook.net
Read at https://coro.net/tracking-api.g2.com
Read at https://coro.net/tracking.g2crowd.com
Read at https://coro.net/region1.analytics.google.com, www.google.com
Read at https://coro.net/www.google.de
Read at https://coro.net/fonts.googleapis.com
Read at https://coro.net/www.googletagmanager.com
Read at https://coro.net/fonts.gstatic.com
Read at https://coro.net/js-eu1.hs-analytics.net
Read at https://coro.net/js-eu1.hs-banner.com
Read at https://coro.net/js-eu1.hs-scripts.com, js.hs-scripts.com
Read at https://coro.net/forms-eu1.hsforms.com
Read at https://coro.net/js-eu1.hsforms.net
Read at https://coro.net/api-eu1.hubspot.com, app-eu1.hubspot.com
Read at https://coro.net/tracking.intentsify.io
Read at https://coro.net/cdn.jsdelivr.net
Read at https://coro.net/snap.licdn.com
Read at https://coro.net/cdn.metadata.io
Read at https://coro.net/alb.reddit.com, pixel-config.reddit.com
Read at https://coro.net/www.redditstatic.com
Read at https://coro.net/scout-cdn.salesloft.com, scout.salesloft.com
Read at https://coro.net/tags.srv.stackadapt.com
Read at https://coro.net/t.co
Read at https://coro.net/app.termly.io
Read at https://coro.net/analytics.twitter.com
Read at https://coro.net/unpkg.com
Read at https://coro.net/a.usbrowserspeed.com
Read at https://coro.net/js-eu1.usemessages.com
Read at https://coro.net/
Gaps, heaviest first
Subprocessor list
weight 3 of 3No subprocessor list found.
Checked 7 addresses on 2026-09-04.
Show the 7 addresses we checked
https://coro.net/legal/subprocessors– reached, no match (HTTP 404)https://coro.net/subprocessors– reached, no match (HTTP 404)https://coro.net/sub-processors– reached, no match (HTTP 404)https://coro.net/legal/sub-processors– reached, no match (HTTP 404)https://coro.net/trust/subprocessors– reached, no match (HTTP 404)https://coro.net/privacy/subprocessors– reached, no match (HTTP 404)https://coro.net/legal/subprocessor-list– reached, no match (HTTP 404)
Data location stated
weight 3 of 3We found this behind a sign-in, so it is not published openly.
Seen at https://www.coro.net/legal/privacy · checked 2026-09-04
Show the 7 addresses we checked
https://coro.net/security– reached, no match (HTTP 200)https://coro.net/trust– reached, no match (HTTP 404)https://coro.net/legal/privacy– found, but behind a sign-inhttps://coro.net/privacy– found, but behind a sign-inhttps://coro.net/privacy-policy– found, but behind a sign-inhttps://coro.net/compliance– reached, no match (HTTP 200)https://coro.net/legal/privacy-policy– reached, no match (HTTP 404)
Status page with history
weight 2 of 3No public status page found.
Checked 3 addresses on 2026-09-04.
Show the 3 addresses we checked
https://status.coro.net/– The name "status.coro.net" could not be resolved.https://coro.net/status– reached, no match (HTTP 404)https://coro.net.statuspage.io/– Could not be fetched: fetch failed.
Public pricing
weight 2 of 3No public pricing with figures found.
Checked 5 addresses on 2026-09-04.
Show the 5 addresses we checked
https://coro.net/pricing– reached and rendered, no matchhttps://coro.net/pricing/– reached, no match (HTTP 200)https://coro.net/plans– reached, no match (HTTP 404)https://coro.net/en/pricing– reached, no match (HTTP 200)https://coro.net/pricing-plans– reached, no match (HTTP 404)
HTTPS enforced with HSTS
weight 2 of 3No enforced HTTPS with HSTS found.
Checked 2 addresses on 2026-09-04.
Show the 2 addresses we checked
http://coro.net/– redirects to https://www.coro.net/https://coro.net/– no HSTS header
No third-party tracking before consent
weight 2 of 3No consent-free first load found.
- Third-party hosts we saw on the first load 37 ads-twitter.com, amazonaws.com, amp.vg, bing.com, bing.net, brilliantchap.com, callrail.com, doubleclick.net, facebook.com, facebook.net, g2.com, g2crowd.com, google.com, google.de, googleapis.com, googletagmanager.com, gstatic.com, hs-analytics.net, hs-banner.com, hs-scripts.com, hsforms.com, hsforms.net, hubspot.com, intentsify.io, jsdelivr.net, licdn.com, metadata.io, reddit.com, redditstatic.com, salesloft.com, stackadapt.com, t.co, termly.io, twitter.com, unpkg.com, usbrowserspeed.com, usemessages.com.
Show the 37 exact wordings
static.ads-twitter.com
Read at https://coro.net/s3-us-west-2.amazonaws.com
Read at https://coro.net/coro.amp.vg
Read at https://coro.net/bat.bing.com
Read at https://coro.net/bat.bing.net
Read at https://coro.net/ob.brilliantchap.com, obs.brilliantchap.com
Read at https://coro.net/cdn.callrail.com
Read at https://coro.net/ad.doubleclick.net, stats.g.doubleclick.net
Read at https://coro.net/www.facebook.com
Read at https://coro.net/connect.facebook.net
Read at https://coro.net/tracking-api.g2.com
Read at https://coro.net/tracking.g2crowd.com
Read at https://coro.net/region1.analytics.google.com, www.google.com
Read at https://coro.net/www.google.de
Read at https://coro.net/fonts.googleapis.com
Read at https://coro.net/www.googletagmanager.com
Read at https://coro.net/fonts.gstatic.com
Read at https://coro.net/js-eu1.hs-analytics.net
Read at https://coro.net/js-eu1.hs-banner.com
Read at https://coro.net/js-eu1.hs-scripts.com, js.hs-scripts.com
Read at https://coro.net/forms-eu1.hsforms.com
Read at https://coro.net/js-eu1.hsforms.net
Read at https://coro.net/api-eu1.hubspot.com, app-eu1.hubspot.com
Read at https://coro.net/tracking.intentsify.io
Read at https://coro.net/cdn.jsdelivr.net
Read at https://coro.net/snap.licdn.com
Read at https://coro.net/cdn.metadata.io
Read at https://coro.net/alb.reddit.com, pixel-config.reddit.com
Read at https://coro.net/www.redditstatic.com
Read at https://coro.net/scout-cdn.salesloft.com, scout.salesloft.com
Read at https://coro.net/tags.srv.stackadapt.com
Read at https://coro.net/t.co
Read at https://coro.net/app.termly.io
Read at https://coro.net/analytics.twitter.com
Read at https://coro.net/unpkg.com
Read at https://coro.net/a.usbrowserspeed.com
Read at https://coro.net/js-eu1.usemessages.com
Read at https://coro.net/
Checked 1 address on 2026-09-04.
Show the 1 address we checked
https://coro.net/– third-party requests before any interaction: a.usbrowserspeed.com, ad.doubleclick.net, alb.reddit.com, analytics.twitter.com, api-eu1.hubspot.com, app-eu1.hubspot.com, app.termly.io, bat.bing.com, bat.bing.net, cdn.callrail.com, cdn.jsdelivr.net, cdn.metadata.io, connect.facebook.net, coro.amp.vg, fonts.googleapis.com, fonts.gstatic.com, forms-eu1.hsforms.com, js-eu1.hs-analytics.net, js-eu1.hs-banner.com, js-eu1.hs-scripts.com, js-eu1.hsforms.net, js-eu1.usemessages.com, js.hs-scripts.com, ob.brilliantchap.com, obs.brilliantchap.com, pixel-config.reddit.com, region1.analytics.google.com, s3-us-west-2.amazonaws.com, scout-cdn.salesloft.com, scout.salesloft.com, snap.licdn.com, static.ads-twitter.com, stats.g.doubleclick.net, t.co, tags.srv.stackadapt.com, tracking-api.g2.com, tracking.g2crowd.com, tracking.intentsify.io, unpkg.com, www.facebook.com, www.google.com, www.google.de, www.googletagmanager.com, www.redditstatic.com
Uptime SLA with a figure
weight 1 of 3No uptime figure found.
Checked 6 addresses on 2026-09-04.
Show the 6 addresses we checked
https://coro.net/legal/sla– reached, no match (HTTP 404)https://coro.net/sla– reached, no match (HTTP 404)https://coro.net/legal/service-level-agreement– reached, no match (HTTP 404)https://coro.net/trust/sla– reached, no match (HTTP 404)https://coro.net/uptime– reached, no match (HTTP 404)https://coro.net/legal/uptime-sla– reached, no match (HTTP 404)
security.txt (RFC 9116)
weight 1 of 3No security.txt found.
Checked 1 address on 2026-09-04.
Show the 1 address we checked
https://coro.net/.well-known/security.txt– reached, no match (HTTP 404)
Evidence
The full source lists sit behind these two groups, so that the answer above stays readable.
Published, with a source 4
Data processing agreement
weight 3 of 3Published and readable without a login.
Source: https://www.coro.net/legal/dpa · checked 2026-09-04
Notice before subprocessors change
weight 2 of 3The vendor commits publicly to giving notice before the list changes.
Source: https://www.coro.net/legal/dpa · checked 2026-09-04
Certifications named
weight 1 of 3SOC 2 or ISO 27001 named on a public page.
- Named on that page HIPAA (named without a certification claim), ISO/IEC 27001 (named without a certification claim), PCI DSS (named without a certification claim), SOC 2 (named without a certification claim).
Show the 4 exact wordings
ignificantly engaged in providing financial products or services The Federal trade commission (FTC) HIPAA A series of regulatory standards that outline the lawful use and disclosure of protected healt...
Read at https://www.coro.net/compliancevices (CMS), the Federal Drug Administration (FDA), and the Federal Communications Commission (FCC) ISO 27001 (ISMS) Helps organizations protect their information in a systematic and cost-effective ma...
Read at https://www.coro.net/complianceformation on residents or those doing business in New York The office of the Attorney General (OAG) PCI DSS Protects credit, debit, and cash card transactions and prevent the misuse of cardholders' pe...
Read at https://www.coro.net/compliancepts card payments, including seasonal or small businesses Visa, Mastercard, AmEx, JCB, and Discover SOC2 Helps companies determine whether their business partners and vendors can securely manage data....
Read at https://www.coro.net/compliance
Source: https://www.coro.net/compliance · checked 2026-09-04
Named privacy contact
weight 1 of 3A data protection officer or a dedicated privacy address is named.
- What the privacy page carries Named data protection officer.
Show the exact wording
Data Protection Officer
Read at https://www.coro.net/legal/privacy
Source: https://www.coro.net/legal/privacy · checked 2026-09-04
History
Not enough completed runs yet to draw a line. The next runs fill this in.
Compare
A shortlist holds up to six vendors across categories and lives entirely in the address of its page: share the link, bookmark it, put it in a ticket. Nothing is stored, so we do not know it exists.