{
  "slug": "fortimail",
  "category": "spam-filters",
  "name": "FortiMail",
  "description": "Email security gateway from Fortinet that filters spam, phishing, malware and business email compromise. It runs as a hardware appliance, a virtual machine or a cloud service, and can also protect Microsoft 365 and Google Workspace through their APIs.",
  "website": "https://www.fortinet.com/products/email-security",
  "license": null,
  "platforms": [
    "web"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 18,
  "coverage": 100,
  "summary": "FortiMail scores 18 out of 100 (grade F) on the spam and virus filtering criteria. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: Mozilla HTTP Observatory grade B+.",
  "url": "https://privacyratings.com/spam-filters/fortimail/",
  "markdown": "https://privacyratings.com/spam-filters/fortimail/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://www.fortinet.com/corporate/about-us/privacy",
      "note": "The privacy policy describes Google Analytics and third-party ad services that track visitors across sites with cookies."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.fortinet.com/corporate/about-us/privacy",
      "note": "Paid product with no ads, but the privacy policy states that Fortinet \"sold\" and \"shared\" website visitor data, as the CCPA defines those terms, to marketing and analytics providers."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://trust.fortinet.com/",
      "note": "Fortinet lists ISO/IEC 27001 certification and SOC 2 reports, but audit reports are only shared on request."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": "https://www.fortinet.com/corporate/about-us/privacy",
      "note": "No transparency report or government request policy is published. The privacy policy only says data may be disclosed to comply with law or for law enforcement."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.fortimailcloud.com",
      "note": "Grade B+ (80/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": "B+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-03T09:56:54.935Z"
  },
  "last_modified": "2026-10-03T10:27:12Z"
}