{
  "slug": "vaadin",
  "category": "jvm-frameworks",
  "name": "Vaadin",
  "description": "Java framework for building web application user interfaces, with server-side Java UI components (Flow) and React-based views (Hilla). Some components and tools are commercial.",
  "website": "https://vaadin.com",
  "source": "https://github.com/vaadin/flow",
  "license": "Apache-2.0",
  "platforms": [
    "linux",
    "macos",
    "windows"
  ],
  "jurisdiction": {
    "code": "FI",
    "name": "Finland",
    "eyes": null,
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 35,
  "coverage": 100,
  "summary": "Vaadin scores 35 out of 100 (grade F) on the Java and Kotlin frameworks criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in Finland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
  "url": "https://privacyratings.com/jvm-frameworks/vaadin/",
  "markdown": "https://privacyratings.com/jvm-frameworks/vaadin/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://vaadin.com/licensing-faq-and-troubleshooting",
      "note": "The core framework is Apache 2.0-licensed, but some components and tools are under the proprietary Vaadin Commercial License."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://vaadin.com/docs/latest/flow/configuration/properties",
      "note": "Development mode collects usage statistics by default until disabled, and vaadin.com loads HubSpot analytics."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://vaadin.com/pricing",
      "note": "Funded by commercial subscriptions and support, with no ads in the framework."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:02:18.525Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}