{
  "slug": "santa",
  "category": "macos-hardening",
  "name": "Santa",
  "description": "A binary and file access authorization system for macOS that allows or blocks apps by hash, signing certificate or team ID. Created at Google and now maintained by North Pole Security.",
  "website": "https://northpole.dev",
  "source": "https://github.com/northpolesec/santa",
  "license": "Apache-2.0",
  "platforms": [
    "macos"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 50,
  "coverage": 100,
  "summary": "Santa scores 50 out of 100 (grade D) on the macOS hardening criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
  "url": "https://privacyratings.com/macos-hardening/santa/",
  "markdown": "https://privacyratings.com/macos-hardening/santa/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/northpolesec/santa/blob/main/LICENSE",
      "note": "Apache-2.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://northpole.security/privacy",
      "note": "The agent reports only to a sync server chosen by the administrator, but the website loads Google Analytics."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://northpole.security",
      "note": "Funded by North Pole Security's commercial management service, with no ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Analytics",
        "host": "www.google-analytics.com",
        "effect": "no"
      },
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      },
      {
        "name": "Plausible",
        "host": "plausible.io",
        "effect": "partial"
      }
    ],
    "tested_at": "2026-10-01T06:38:36.305Z"
  },
  "last_modified": "2026-10-01T06:56:31Z"
}