# Eramba privacy rating

Governance, risk and compliance software for managing risks, controls, policies, audits and frameworks such as ISO 27001, SOC 2, NIS2 and GDPR. A free Community edition and a paid Enterprise edition run on premises, and Enterprise is also offered as SaaS.

## Summary

Eramba scores 25 out of 100 (grade F) on the compliance automation criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.

- Website: https://www.eramba.org
- Jurisdiction: United Kingdom. Five Eyes member. GDPR-style data protection law. CLOUD Act data access agreement with the US.
- Platforms: Linux, Web
- Home page trackers: Google Analytics, Google Fonts (not scored), Google Tag Manager
- Category: [Compliance automation](https://privacyratings.com/compliance-automation/)
- Grade: F (25/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Partial | Source available but not open source. The license allows internal use only and forbids modification and redistribution. | https://www.eramba.org/faqs |
| No trackers or telemetry | No | The website loads Google Tag Manager and a Google Ads tag. |  |
| No ads or data sales | Partial | Funded by Enterprise licenses and services with no ads in the software, but the website runs a Google Ads conversion tag. | https://www.eramba.org/ |
| Independent audit | No | No independent audit is published. |  |

Source: https://privacyratings.com/compliance-automation/eramba/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/compliance-automation/eramba.md
