# Hyperproof privacy rating

Hosted compliance and risk management platform that maps controls across frameworks such as SOC 2, ISO 27001, NIST and FedRAMP, collects evidence from connected tools and manages audits.

## Summary

Hyperproof scores 31 out of 100 (grade F) on the compliance automation criteria. It meets 2 of 8 criteria: TLS configuration and security headers. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.

- Website: https://hyperproof.io
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Web
- Home page trackers: G2, Google Analytics, Google Tag Manager, HubSpot, LinkedIn Insight, Microsoft Ads, VWO
- Category: [Compliance automation](https://privacyratings.com/compliance-automation/)
- Grade: F (31/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. |  |
| No trackers or telemetry | No | The privacy policy says advertising and analytics partners use cookies, pixels and device identifiers, and the website loads HubSpot, 6sense, ZoomInfo, LinkedIn and Reddit tags. | https://hyperproof.io/privacy-policy/ |
| No ads or data sales | Partial | Paid service with no ads, and it says it is not in the business of selling information, but advertising partners use cookies to recognize visitors across services. | https://hyperproof.io/privacy-policy/ |
| Independent audit | Partial | States SOC 2 compliance and FedRAMP Moderate authorization for Hyperproof Gov, but the reports are not public. | https://hyperproof.io/security-trust/ |
| Transparency report | No | No transparency report is published. The privacy policy only says information may be shared to comply with legal process or government requests. | https://hyperproof.io/privacy-policy/ |
| Tells users about requests | No | No published policy on notifying users about data requests. |  |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=hyperproof.app&hideResults=on |
| Security headers | Yes | Grade A+ (115/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=hyperproof.app |
| Modern web standards | Not tested yet | Not tested yet. |  |

Source: https://privacyratings.com/compliance-automation/hyperproof/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/compliance-automation/hyperproof.md
