# Comp AI vs Eramba: privacy compared

| Criterion | Comp AI | Eramba |
| --- | --- | --- |
| Grade | F (38/100) | F (25/100) |
| Jurisdiction | United States (Five Eyes) | United Kingdom (Five Eyes) |
| Open source | Partial | Partial |
| No trackers or telemetry | No | No |
| No ads or data sales | Partial | Partial |
| Independent audit | Partial | No |
| Transparency report | No | Not applicable |
| Tells users about requests | No | Not applicable |
| TLS configuration | Yes | Not applicable |
| Security headers | Partial | Not applicable |
| Modern web standards | Not tested yet | Not applicable |

**Comp AI.** Comp AI scores 38 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets open source, no ads or data sales, independent audit and security headers. It does not meet no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.

**Eramba.** Eramba scores 25 out of 100 (grade F) on the compliance automation criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.

Source: https://privacyratings.com/compare/compliance-automation/comp-ai-vs-eramba/
