Criteria by category
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
End-to-end encryption weight 3
Can mail be end-to-end encrypted so that the provider cannot read message contents?
- ✔Yes Yes
- Built in by default between users, and supported for outside recipients (for example OpenPGP or password-protected mail).
- ◐Partial Partial
- Supported but not by default, or only with a browser extension or separate app.
- ✖No No
- Not supported.
Why: Without end-to-end encryption, the provider and anyone with access to its servers can read mail.
How to verify: Link the documentation that describes the encryption.
Encrypted mailbox storage weight 3
Is stored mail encrypted with a key the provider does not hold?
- ✔Yes Yes
- Mailboxes are encrypted at rest with a key derived from the user's password or private key.
- ◐Partial Partial
- Encrypted at rest, but with keys the provider holds.
- ✖No No
- Stored unencrypted or undocumented.
Why: Encrypted storage protects mail from breaches, rogue staff and bulk data requests.
How to verify: Link the security or encryption documentation.
Open protocols weight 2
Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?
- ✔Yes Yes
- IMAP and SMTP work with any client on every paid plan.
- ◐Partial Partial
- Standard protocols need a bridge app or a higher plan.
- ✖No No
- Only the provider's own apps work.
Why: Open protocols prevent lock-in and let people choose their own apps.
How to verify: Link the IMAP and SMTP setup documentation.
Custom domains weight 1
Can mail be sent and received with your own domain?
- ✔Yes Yes
- Supported on affordable plans.
- ◐Partial Partial
- Only on business plans.
- ✖No No
- Not supported.
Why: Your own domain makes it possible to switch providers without changing addresses.
How to verify: Link the custom domain documentation.
Sign up without personal data weight 2
Can an account be created without a phone number or another email address?
- ✔Yes Yes
- No phone number or existing email required.
- ◐Partial Partial
- Required only in some cases, such as flagged sign-ups.
- ✖No No
- A phone number or other personal data is required.
Why: Requiring a phone number ties the account to a real identity.
How to verify: Link the sign-up page or documentation.
Email security standards weight 2 automated hosted services
Does the mail domain score 90% or higher on the Internet.nl email test?
- ✔Yes Yes
- Score of 90% or higher.
- ◐Partial Partial
- Score between 70% and 89%.
- ✖No No
- Score below 70%.
Why: The test checks DMARC, DKIM, SPF, DNSSEC, DANE and STARTTLS, which protect mail from spoofing and interception.
How to verify: Run https://internet.nl/test-mail/ on the mail domain.
IMAP support weight 2 automated hosted services
Does the IMAP server accept connections over implicit TLS on port 993 and advertise IMAP4rev1 or IMAP4rev2 with IDLE push?
- ✔Yes Yes
- Implicit TLS on 993 (RFC 8314), IMAP4rev1 (RFC 3501) or IMAP4rev2 (RFC 9051), and IDLE (RFC 2177) advertised in CAPABILITY.
- ◐Partial Partial
- IMAP works, but only with STARTTLS on 143, or without IDLE in the advertised capabilities.
- ✖No No
- No IMAP server. Mail can only be read in the provider's own apps or through a local bridge.
Why: Standard IMAP lets people use any email app and keeps them free to leave. Implicit TLS is the current recommendation for mail access.
How to verify: Connect with `openssl s_client -connect imap.example.com:993` and send `a1 CAPABILITY`.
POP3 support weight 1 automated hosted services
Does the POP3 server accept connections over implicit TLS on port 995 and answer CAPA with UIDL?
- ✔Yes Yes
- Implicit TLS on 995 (RFC 8314), CAPA (RFC 2449) and UIDL (RFC 1939).
- ◐Partial Partial
- POP3 works, but only with STLS on 110, or without CAPA or UIDL.
- ✖No No
- No POP3 server.
Why: POP3 is the simplest way to download and keep a full local copy of every message.
How to verify: Connect with `openssl s_client -connect pop3.example.com:995` and send `CAPA`.
SMTP submission weight 2 automated hosted services
Does mail submission work over implicit TLS on port 465 with SMTPUTF8, 8BITMIME, PIPELINING and AUTH?
- ✔Yes Yes
- Implicit TLS on 465 (RFC 8314) with SMTPUTF8 (RFC 6531), 8BITMIME (RFC 6152), PIPELINING (RFC 2920) and AUTH (RFC 4954) in EHLO.
- ◐Partial Partial
- Submission works, but only with STARTTLS on 587, or without one of these extensions.
- ✖No No
- No SMTP submission. Mail can only be sent from the provider's own apps or through a local bridge.
Why: Standard SMTP submission lets any app send mail, and SMTPUTF8 allows international addresses.
How to verify: Connect with `openssl s_client -connect smtp.example.com:465` and send `EHLO example.com`.
Mail transport security weight 3 automated hosted services
Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?
- ✔Yes Yes
- SPF, DMARC set to quarantine or reject, MTA-STS in enforce mode (RFC 8461), TLS-RPT (RFC 8460), DNSSEC, and DANE TLSA records on every MX host (RFC 7672).
- ◐Partial Partial
- DMARC is enforced and either MTA-STS is enforced or DANE is published, but not everything above.
- ✖No No
- DMARC is not enforced, or neither MTA-STS nor DANE is used.
Why: These records stop attackers from downgrading or intercepting mail in transit, and from spoofing the provider's own domain.
How to verify: Check the TXT records for _mta-sts, _smtp._tls and _dmarc, the TLSA records for _25._tcp on each MX host, and DNSSEC validation.
Sender Rewriting Scheme weight 1
Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?
- ✔Yes Yes
- SRS is applied to all forwarded mail.
- ◐Partial Partial
- SRS is applied only in some cases or on some plans.
- ✖No No
- Forwarded mail is not rewritten.
Why: Without SRS, forwarded mail often fails SPF and lands in spam or is rejected.
How to verify: Link documentation or source code, or check the Return-Path of a forwarded message.
ARC sealing weight 1
Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?
- ✔Yes Yes
- ARC chains are validated on inbound mail and ARC seals are added to forwarded mail.
- ◐Partial Partial
- Only one of the two.
- ✖No No
- ARC is not supported.
Why: ARC lets receivers trust authentication results after a message is forwarded or modified by a mailing list.
How to verify: Link documentation or source code, or check for ARC-Seal headers on a forwarded message.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
End-to-end encryption weight 2
Can mail be end-to-end encrypted so that the provider cannot read message contents?
- ✔Yes Yes
- Built in by default between users, and supported for outside recipients (for example OpenPGP or password-protected mail).
- ◐Partial Partial
- Supported but not by default, or only with a browser extension or separate app.
- ✖No No
- Not supported.
Why: Without end-to-end encryption, the provider and anyone with access to its servers can read mail.
How to verify: Link the documentation that describes the encryption.
No stored mail weight 3
Is forwarded mail passed through without being written to disk?
- ✔Yes Yes
- Mail is forwarded in memory and never stored, except in a documented retry queue.
- ◐Partial Partial
- Mail is stored briefly for a documented reason.
- ✖No No
- Mail is stored or logged in full.
Why: Mail that is never stored cannot be breached or handed over later.
How to verify: Link the documentation or source code that shows how mail is handled.
Open protocols weight 2
Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?
- ✔Yes Yes
- IMAP and SMTP work with any client on every paid plan.
- ◐Partial Partial
- Standard protocols need a bridge app or a higher plan.
- ✖No No
- Only the provider's own apps work.
Why: Open protocols prevent lock-in and let people choose their own apps.
How to verify: Link the IMAP and SMTP setup documentation.
Custom domains weight 1
Can mail be sent and received with your own domain?
- ✔Yes Yes
- Supported on affordable plans.
- ◐Partial Partial
- Only on business plans.
- ✖No No
- Not supported.
Why: Your own domain makes it possible to switch providers without changing addresses.
How to verify: Link the custom domain documentation.
Sign up without personal data weight 2
Can an account be created without a phone number or another email address?
- ✔Yes Yes
- No phone number or existing email required.
- ◐Partial Partial
- Required only in some cases, such as flagged sign-ups.
- ✖No No
- A phone number or other personal data is required.
Why: Requiring a phone number ties the account to a real identity.
How to verify: Link the sign-up page or documentation.
Email security standards weight 2 automated hosted services
Does the mail domain score 90% or higher on the Internet.nl email test?
- ✔Yes Yes
- Score of 90% or higher.
- ◐Partial Partial
- Score between 70% and 89%.
- ✖No No
- Score below 70%.
Why: The test checks DMARC, DKIM, SPF, DNSSEC, DANE and STARTTLS, which protect mail from spoofing and interception.
How to verify: Run https://internet.nl/test-mail/ on the mail domain.
Mail transport security weight 3 automated hosted services
Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?
- ✔Yes Yes
- SPF, DMARC set to quarantine or reject, MTA-STS in enforce mode (RFC 8461), TLS-RPT (RFC 8460), DNSSEC, and DANE TLSA records on every MX host (RFC 7672).
- ◐Partial Partial
- DMARC is enforced and either MTA-STS is enforced or DANE is published, but not everything above.
- ✖No No
- DMARC is not enforced, or neither MTA-STS nor DANE is used.
Why: These records stop attackers from downgrading or intercepting mail in transit, and from spoofing the provider's own domain.
How to verify: Check the TXT records for _mta-sts, _smtp._tls and _dmarc, the TLSA records for _25._tcp on each MX host, and DNSSEC validation.
Sender Rewriting Scheme weight 2
Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?
- ✔Yes Yes
- SRS is applied to all forwarded mail.
- ◐Partial Partial
- SRS is applied only in some cases or on some plans.
- ✖No No
- Forwarded mail is not rewritten.
Why: Without SRS, forwarded mail often fails SPF and lands in spam or is rejected.
How to verify: Link documentation or source code, or check the Return-Path of a forwarded message.
ARC sealing weight 1
Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?
- ✔Yes Yes
- ARC chains are validated on inbound mail and ARC seals are added to forwarded mail.
- ◐Partial Partial
- Only one of the two.
- ✖No No
- ARC is not supported.
Why: ARC lets receivers trust authentication results after a message is forwarded or modified by a mailing list.
How to verify: Link documentation or source code, or check for ARC-Seal headers on a forwarded message.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
OpenPGP support weight 2
Can the app encrypt and sign mail with OpenPGP, built in or through an official add-on?
- ✔Yes Yes
- Built in.
- ◐Partial Partial
- Through a separate app or add-on.
- ✖No No
- Not supported.
Why: OpenPGP gives end-to-end encryption with any provider.
How to verify: Link the documentation.
Connects directly weight 3
Does the app connect directly to your mail server, without passing mail or passwords through the vendor's servers?
- ✔Yes Yes
- Connects directly. Passwords and mail stay on the device.
- ◐Partial Partial
- Connects directly, but optional features (such as push or sync) use vendor servers.
- ✖No No
- Mail or credentials pass through vendor servers.
Why: A client that syncs through the vendor's cloud gives the vendor a copy of every mailbox.
How to verify: Link the documentation or privacy policy that describes how the app connects.
Blocks remote content weight 2
Are remote images and tracking pixels blocked by default?
- ✔Yes Yes
- Blocked by default.
- ◐Partial Partial
- Can be blocked in settings.
- ✖No No
- Cannot be blocked.
Why: Remote images tell senders when and where a message was opened.
How to verify: Link the documentation or settings screen.
Works with any provider weight 1
Does the app work with any standard IMAP and SMTP provider?
- ✔Yes Yes
- Any IMAP and SMTP provider.
- ◐Partial Partial
- A limited list of providers.
- ✖No No
- Only the vendor's own service.
Why: Apps tied to one provider make switching harder.
How to verify: Link the account setup documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
OpenPGP support weight 2
Can the app encrypt and sign mail with OpenPGP, built in or through an official add-on?
- ✔Yes Yes
- Built in.
- ◐Partial Partial
- Through a separate app or add-on.
- ✖No No
- Not supported.
Why: OpenPGP gives end-to-end encryption with any provider.
How to verify: Link the documentation.
Connects directly weight 3
Does the app connect directly to your mail server, without passing mail or passwords through the vendor's servers?
- ✔Yes Yes
- Connects directly. Passwords and mail stay on the device.
- ◐Partial Partial
- Connects directly, but optional features (such as push or sync) use vendor servers.
- ✖No No
- Mail or credentials pass through vendor servers.
Why: A client that syncs through the vendor's cloud gives the vendor a copy of every mailbox.
How to verify: Link the documentation or privacy policy that describes how the app connects.
Blocks remote content weight 2
Are remote images and tracking pixels blocked by default?
- ✔Yes Yes
- Blocked by default.
- ◐Partial Partial
- Can be blocked in settings.
- ✖No No
- Cannot be blocked.
Why: Remote images tell senders when and where a message was opened.
How to verify: Link the documentation or settings screen.
Works with any provider weight 1
Does the app work with any standard IMAP and SMTP provider?
- ✔Yes Yes
- Any IMAP and SMTP provider.
- ◐Partial Partial
- A limited list of providers.
- ✖No No
- Only the vendor's own service.
Why: Apps tied to one provider make switching harder.
How to verify: Link the account setup documentation.
Self-hostable weight 1
Can the webmail be installed on your own server?
- ✔Yes Yes
- Officially supported self-hosting.
- ◐Partial Partial
- Possible but unsupported or limited.
- ✖No No
- Hosted only.
Why: Self-hosting keeps mail and sessions on servers you control.
How to verify: Link the installation guide.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
Message content deleted after delivery weight 3
Is the content of sent mail deleted once it has been delivered?
- ✔Yes Yes
- Message bodies are not kept after delivery, or are kept only when the sender turns this on.
- ◐Partial Partial
- Message bodies are kept by default for a documented period of 30 days or less, or a longer period can be shortened to 30 days or less or turned off.
- ✖No No
- Message bodies are kept for more than 30 days or for an undocumented period, with no way to shorten it.
Why: Every stored copy of a password reset, receipt or newsletter can be breached or handed over later.
How to verify: Link the documentation on message logs, content storage or data retention.
Open and click tracking off by default weight 2
Are open tracking pixels and click tracking links off unless the sender turns them on?
- ✔Yes Yes
- Open and click tracking are not offered, or are off until the sender turns them on.
- ◐Partial Partial
- Open or click tracking is on by default, but can be turned off or made anonymous for the account or for each message.
- ✖No No
- Open or click tracking is always on.
Why: Tracking pixels and rewritten links record when, where and on which device each recipient reads mail.
How to verify: Link the tracking settings documentation or API reference.
Encrypted delivery can be enforced weight 2
Can outbound mail be kept from being delivered without TLS?
- ✔Yes Yes
- Outbound delivery honors the recipient domain's MTA-STS or DANE policy, or the sender can require TLS so mail is not sent in plain text.
- ◐Partial Partial
- TLS is used when the receiving server offers it, with no way to require it.
- ✖No No
- Outbound mail is sent without TLS.
Why: With opportunistic TLS alone, an attacker on the network can strip encryption and read mail in transit.
How to verify: Link the TLS or delivery security documentation.
EU data location weight 1
Can message content and delivery logs be processed and stored only in the European Union?
- ✔Yes Yes
- An EU region, an EU-only service or self-hosting keeps message data in the EU, on every plan.
- ◐Partial Partial
- An EU region is offered only on some plans, on request or in beta.
- ✖No No
- Message data is processed or stored outside the EU.
Why: Data kept in the EU stays under the GDPR and out of reach of some foreign surveillance laws.
How to verify: Link the data location, region or data residency documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
Blocks trackers by default weight 3
Are third-party trackers blocked by default, without installing extensions?
- ✔Yes Yes
- Blocked by default.
- ◐Partial Partial
- Limits cross-site tracking (for example cookie isolation) but does not block tracker requests.
- ✖No No
- Not blocked by default.
Why: Most people never change default settings.
How to verify: Link the documentation, or a test such as https://coveryourtracks.eff.org/.
Fingerprinting protection weight 2
Does the browser defend against fingerprinting by default?
- ✔Yes Yes
- Randomizes or standardizes fingerprinting data by default.
- ◐Partial Partial
- Only in a stricter mode that is off by default.
- ✖No No
- No protection.
Why: Fingerprinting tracks people even after cookies are cleared.
How to verify: Link the documentation, or a test such as https://coveryourtracks.eff.org/.
No calls to big-tech services weight 2
Does the browser work without background connections to Google, Microsoft or Apple services?
- ✔Yes Yes
- No background connections to big-tech services by default.
- ◐Partial Partial
- Some connections remain and can be turned off.
- ✖No No
- Background connections are built in and cannot be turned off.
Why: Background connections share browsing activity and device data.
How to verify: Link documentation or source code that lists removed or disabled services.
Timely security updates weight 3
Are security fixes from the upstream engine shipped quickly and automatically?
- ✔Yes Yes
- Fixes ship within days and install automatically.
- ◐Partial Partial
- Fixes ship quickly but must be installed by hand or through a package manager.
- ✖No No
- Fixes often lag weeks behind upstream.
Why: Browsers are the most attacked software on most devices.
How to verify: Link the release notes or update documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
Effective by default weight 3
Does it block ads and trackers with its default settings, without paid tiers?
- ✔Yes Yes
- Blocks ads and trackers by default, for free.
- ◐Partial Partial
- Needs extra lists or configuration.
- ✖No No
- Allows "acceptable ads" by default, or blocking is paid.
Why: Allowlists paid for by advertisers let their ads and trackers through.
How to verify: Link the documentation or filter list settings.
No browsing data collected weight 3
Does it work without sending browsing data to the developer?
- ✔Yes Yes
- All filtering happens on the device, with no data sent.
- ◐Partial Partial
- Anonymous usage statistics that can be turned off.
- ✖No No
- Browsing data is collected.
Why: An ad blocker sees every page visited.
How to verify: Link the privacy policy or source code.
Custom filters weight 1
Can users add their own filter lists and rules?
- ✔Yes Yes
- Yes.
- ◐Partial Partial
- Limited.
- ✖No No
- No.
Why: Custom rules handle sites that default lists miss.
How to verify: Link the documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
No search history logs weight 3
Are searches stored without IP addresses or other identifiers?
- ✔Yes Yes
- Searches are not stored with identifiers.
- ◐Partial Partial
- Identifiers are removed after a short, documented period.
- ✖No No
- Searches are tied to identifiers or accounts.
Why: Search history reveals health, money, politics and more.
How to verify: Link the privacy policy.
No profile-based ads weight 2
Are ads (if any) based only on the current search, not a profile?
- ✔Yes Yes
- No ads, or ads based only on the search terms.
- ◐Partial Partial
- Profile-based ads can be turned off.
- ✖No No
- Ads are based on a profile.
Why: Profile-based ads need a stored profile of your searches.
How to verify: Link the privacy policy or ad documentation.
No account needed weight 1
Can every feature be used without an account?
- ✔Yes Yes
- No account needed.
- ◐Partial Partial
- Some features need an account.
- ✖No No
- An account is needed.
Why: Accounts link searches to an identity.
How to verify: Link the help or settings page.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
No account needed weight 2
Can apps be installed without an account?
- ✔Yes Yes
- No account needed.
- ◐Partial Partial
- Only for some apps.
- ✖No No
- An account is required.
Why: An account links every installed app to an identity.
How to verify: Link the documentation.
Shows trackers and anti-features weight 1
Does the store show which apps contain trackers, ads or other anti-features?
- ✔Yes Yes
- Shown for every app.
- ◐Partial Partial
- Partly, for example self-reported privacy labels.
- ✖No No
- Not shown.
Why: It helps people avoid apps that track them.
How to verify: Link an example listing or documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
End-to-end encrypted vault weight 3
Is the vault encrypted on the device before it is synced, with a key the provider does not hold?
- ✔Yes Yes
- End-to-end encrypted, or local-only with no sync service.
- ◐Partial Partial
- Encrypted, but key handling is not documented.
- ✖No No
- The provider can decrypt vaults.
Why: A breached password manager exposes every account.
How to verify: Link the security whitepaper or encryption documentation.
Local or self-hosted option weight 2
Can the vault be kept locally or on your own server?
- ✔Yes Yes
- Local files or a supported self-hosted server.
- ◐Partial Partial
- Export only.
- ✖No No
- Only the vendor's cloud.
Why: Keeping data under your control removes a third party.
How to verify: Link the documentation.
Full export weight 1
Can every item be exported in an open format?
- ✔Yes Yes
- Full export in an open format.
- ◐Partial Partial
- Partial export.
- ✖No No
- No export.
Why: Export prevents lock-in.
How to verify: Link the export documentation.
Publishes full reports weight 3
Are full audit reports routinely published, with client consent, rather than only summaries or badges?
- ✔Yes Yes
- Many full reports are public, listed by the firm or linked from clients.
- ◐Partial Partial
- Some reports or summaries are public.
- ✖No No
- Reports stay private.
Why: A public report lets anyone check what was tested, what was found and what was fixed.
How to verify: Link the firm's publications page or public reports.
Audits open-source projects weight 2
Does the firm regularly audit open-source software and non-profit projects?
- ✔Yes Yes
- Regular public audits of open-source projects, for example through OSTIF or the Open Technology Fund.
- ◐Partial Partial
- Occasional open-source audits.
- ✖No No
- Commercial clients only.
Why: Audits of open-source software protect everyone who uses it.
How to verify: Link public audits of open-source projects.
Public research weight 1
Does the firm publish security research, advisories or tools?
- ✔Yes Yes
- Regular public research, advisories or open-source tools.
- ◐Partial Partial
- Occasional publications.
- ✖No No
- None.
Why: Published research shows expertise and helps defenders.
How to verify: Link the research or advisories page.
No trackers on website weight 1
Is the firm's website free of third-party trackers?
- ✔Yes Yes
- No third-party trackers. Any analytics are cookieless and aggregate-only.
- ◐Partial Partial
- Analytics that use cookies or persistent identifiers, without other trackers.
- ✖No No
- Third-party trackers are present.
Why: A privacy and security firm's own site shows its standards.
How to verify: Run the tracker test or check the privacy policy.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
End-to-end encrypted by default weight 3
Are all chats, including groups, end-to-end encrypted by default?
- ✔Yes Yes
- All chats and calls by default.
- ◐Partial Partial
- Only some chats, or only when turned on.
- ✖No No
- Not end-to-end encrypted.
Why: Without it, the service can read messages.
How to verify: Link the encryption documentation.
No phone number needed weight 2
Can an account be created without a phone number?
- ✔Yes Yes
- No phone number needed.
- ◐Partial Partial
- A phone number is needed but can be hidden from contacts.
- ✖No No
- A phone number is needed and visible.
Why: Phone numbers are tied to real identities.
How to verify: Link the sign-up documentation.
Metadata protection weight 2
Does the service minimize who-talks-to-whom metadata (for example sealed sender or no user identifiers)?
- ✔Yes Yes
- Documented design that hides sender or contact lists from the server.
- ◐Partial Partial
- Some metadata protection.
- ✖No No
- The server sees who talks to whom.
Why: Metadata alone can reveal relationships and habits.
How to verify: Link the documentation or design paper.
Decentralized weight 1
Can people run their own server or talk peer to peer?
- ✔Yes Yes
- Federated or peer to peer.
- ◐Partial Partial
- Self-hosting is possible but not federated.
- ✖No No
- One central service.
Why: Decentralized networks cannot be shut down or censored at one point.
How to verify: Link the self-hosting documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
End-to-end encrypted weight 3
Are calls end-to-end encrypted by default?
- ✔Yes Yes
- All calls, including group calls, by default.
- ◐Partial Partial
- Optional, or only for some calls.
- ✖No No
- Not end-to-end encrypted.
Why: Without end-to-end encryption, the provider can access calls.
How to verify: Link the security documentation.
Join without an account weight 1
Can people join calls without an account?
- ✔Yes Yes
- Guests join from a link with no account.
- ◐Partial Partial
- Only the host needs an account.
- ✖No No
- Everyone needs an account.
Why: Accounts tie calls to identities.
How to verify: Link the documentation.
Self-hostable weight 1
Can the server be self-hosted?
- ✔Yes Yes
- Officially supported.
- ◐Partial Partial
- Possible but limited.
- ✖No No
- Hosted only.
Why: Self-hosting keeps call metadata on your own servers.
How to verify: Link the self-hosting guide.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
Message content deleted or redacted weight 3
Can the text of messages be kept from being stored after delivery?
- ✔Yes Yes
- Message bodies are not stored after delivery, or the customer can turn on redaction or deletion for every message without asking.
- ◐Partial Partial
- Message bodies are kept for a documented period of 30 days or less, or can be deleted through the API, or redaction is available on request or on some plans.
- ✖No No
- Message bodies are kept for more than 30 days or an undocumented period, with no way to delete them.
Why: Stored texts hold one-time codes, appointments and personal conversations tied to phone numbers.
How to verify: Link the data retention, message redaction or deletion documentation.
EU data location weight 1
Can messages, call records and logs be processed and stored in the European Union?
- ✔Yes Yes
- An EU region, an EU-only service or self-hosting keeps message data in the EU, on every plan.
- ◐Partial Partial
- An EU region is offered only on some plans, on request or in beta.
- ✖No No
- Message data is processed or stored outside the EU.
Why: Data kept in the EU stays under the GDPR and out of reach of some foreign surveillance laws.
How to verify: Link the data location, region or data residency documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
Audited no-logs policy weight 3
Has an independent audit confirmed that activity and connection logs are not kept?
- ✔Yes Yes
- A public audit report confirms it.
- ◐Partial Partial
- A no-logs policy exists but has not been audited.
- ✖No No
- Logs are kept, or there is no policy.
Why: A VPN sees all traffic. Only an audit shows the policy is followed.
How to verify: Link the audit report and the privacy policy.
Anonymous payment weight 2
Can an account be created and paid for without an email address, name or card?
- ✔Yes Yes
- Accounts need no email, and cash or Monero is accepted.
- ◐Partial Partial
- Cryptocurrency is accepted but an email is needed.
- ✖No No
- Personal data is required.
Why: Payment details tie the account to a real identity.
How to verify: Link the payment and sign-up documentation.
Open-source apps weight 2
Are the apps for every platform open source?
- ✔Yes Yes
- All platforms.
- ◐Partial Partial
- Some platforms.
- ✖No No
- None.
Why: The VPN app handles all traffic and keys.
How to verify: Link the source repositories.
Modern protocols weight 1
Is WireGuard (or another modern audited protocol) supported?
- ✔Yes Yes
- WireGuard supported.
- ◐Partial Partial
- Only OpenVPN or IKEv2.
- ✖No No
- Only outdated or proprietary protocols.
Why: Modern protocols are faster and have smaller, audited codebases.
How to verify: Link the documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
Encrypted DNS weight 3
Are DNS over HTTPS and DNS over TLS supported?
- ✔Yes Yes
- Both.
- ◐Partial Partial
- One of them.
- ✖No No
- Neither.
Why: Unencrypted DNS shows every site visited to anyone on the network.
How to verify: Link the setup documentation.
No query logs weight 3
Are queries stored without IP addresses, and is this independently audited?
- ✔Yes Yes
- No identifying logs, confirmed by an audit.
- ◐Partial Partial
- No identifying logs claimed, but not audited, or logs kept briefly.
- ✖No No
- Identifying logs are kept.
Why: DNS logs are a full browsing history.
How to verify: Link the privacy policy and audit.
DNSSEC validation weight 1
Does the resolver validate DNSSEC?
- ✔Yes Yes
- Yes.
- ◐Partial Partial
- Optional.
- ✖No No
- No.
Why: Validation stops forged DNS answers.
How to verify: Link the documentation or a test.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
DNSSEC weight 3
Can DNSSEC be turned on for hosted zones?
- ✔Yes Yes
- One click or automatic.
- ◐Partial Partial
- Supported with manual steps.
- ✖No No
- Not supported.
Why: DNSSEC stops attackers from forging a domain's records.
How to verify: Link the documentation.
API access weight 1
Can records be managed through an API on every plan?
- ✔Yes Yes
- Yes, on every plan.
- ◐Partial Partial
- Only on paid plans.
- ✖No No
- No API.
Why: An API makes automation and migrations possible.
How to verify: Link the API documentation.
Two-factor login weight 2
Do accounts support two-factor authentication with an authenticator app or security key?
- ✔Yes Yes
- TOTP or security keys.
- ◐Partial Partial
- SMS only.
- ✖No No
- No two-factor login.
Why: A hijacked DNS account can redirect all mail and web traffic.
How to verify: Link the documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
Free WHOIS privacy weight 2
Is registrant data hidden from public WHOIS and RDAP at no extra cost?
- ✔Yes Yes
- Free for every supported domain extension.
- ◐Partial Partial
- Free for some extensions only, or paid.
- ✖No No
- Not offered.
Why: Public registrant data exposes names, addresses and phone numbers.
How to verify: Link the pricing or privacy documentation.
Honest renewal pricing weight 1
Are renewal prices the same as, or close to, the first-year price?
- ✔Yes Yes
- At-cost or flat renewal pricing.
- ◐Partial Partial
- Renewals cost somewhat more.
- ✖No No
- Large renewal increases.
Why: Cheap first years with expensive renewals make it costly to keep a domain.
How to verify: Link the pricing page.
Two-factor login weight 2
Do accounts support two-factor authentication with an authenticator app or security key?
- ✔Yes Yes
- TOTP or security keys.
- ◐Partial Partial
- SMS only.
- ✖No No
- No two-factor login.
Why: A hijacked registrar account means a hijacked domain.
How to verify: Link the documentation.
Transfer and registry lock weight 1
Is transfer lock on by default, with registry lock available?
- ✔Yes Yes
- Both.
- ◐Partial Partial
- Transfer lock only.
- ✖No No
- Neither.
Why: Locks prevent domain theft.
How to verify: Link the documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
Mail-friendly (port 25) weight 1
Is outbound port 25 open by default, or opened on request?
- ✔Yes Yes
- Open by default.
- ◐Partial Partial
- Blocked by default but opened on request.
- ✖No No
- Always blocked.
Why: Running a mail server needs outbound port 25.
How to verify: Link the documentation or support policy.
Reverse DNS weight 1
Can reverse DNS (PTR) records be set for IPv4 and IPv6?
- ✔Yes Yes
- Both, self-service.
- ◐Partial Partial
- On request, or IPv4 only.
- ✖No No
- Not supported.
Why: Mail servers without matching reverse DNS are rejected as spam.
How to verify: Link the documentation.
IPv6 weight 1
Is native IPv6 included?
- ✔Yes Yes
- Yes, at no extra cost.
- ◐Partial Partial
- For an extra fee.
- ✖No No
- No.
Why: IPv6 is required for modern networking and many mail tests.
How to verify: Link the documentation.
Anonymous payment weight 1
Can servers be paid for with cryptocurrency or without identity checks?
- ✔Yes Yes
- Yes.
- ◐Partial Partial
- Only after verification.
- ✖No No
- No.
Why: Payment details tie servers to an identity.
How to verify: Link the payment documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
Runs on your own infrastructure weight 3
Can it run entirely on your own infrastructure or repository, without a vendor account?
- ✔Yes Yes
- Fully self-hosted or runs in your own repository.
- ◐Partial Partial
- Self-hosted with optional vendor services.
- ✖No No
- Hosted by the vendor only.
Why: Status data and visitor logs stay under your control.
How to verify: Link the installation documentation.
No visitor tracking weight 2
Is the public status page free of third-party trackers and analytics?
- ✔Yes Yes
- No third-party trackers.
- ◐Partial Partial
- Analytics can be turned off.
- ✖No No
- Trackers are always included.
Why: Status pages are visited by customers during outages.
How to verify: Link the source code or privacy policy.
Public uptime history weight 1
Does it publish response times and incident history?
- ✔Yes Yes
- Yes.
- ◐Partial Partial
- Current status only.
- ✖No No
- No.
Why: History shows how reliable a service has been over time.
How to verify: Link a live example.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
Keys stay on devices weight 3
Is traffic encrypted between devices with private keys created on each device, so the coordination server and relays cannot read it?
- ✔Yes Yes
- Private keys are created on each device and never leave it. Relays only forward encrypted packets.
- ◐Partial Partial
- Traffic is encrypted between devices, but key handling is not documented, or some setups use keys created on the server.
- ✖No No
- Traffic is decrypted on the vendor's servers.
Why: The coordination server knows every device on the network. Keys that stay on the devices keep it from reading the traffic too.
How to verify: Link the security or architecture documentation that describes key generation and relays.
Self-hosted coordination server weight 2
Can the coordination or control server be self-hosted with open-source software?
- ✔Yes Yes
- The vendor's control server is open source and can be self-hosted, or the network needs no central server.
- ◐Partial Partial
- Self-hosting needs a proprietary or source-available server, is not officially supported, or works only through a third-party open-source replacement.
- ✖No No
- Only the vendor's hosted service can be used.
Why: A self-hosted server keeps the list of devices, users and access rules off a third party's servers.
How to verify: Link the self-hosting documentation and the server's license.
No connection logs by default weight 2
Are connection logs and client diagnostic logs kept off the vendor's servers unless a user or admin turns them on?
- ✔Yes Yes
- Nothing is sent to the vendor by default, or there is no vendor service.
- ◐Partial Partial
- Logs or crash reports are sent to the vendor by default, but can be turned off.
- ✖No No
- Connection logs are kept by the vendor, with no documented way to turn them off.
Why: Connection logs show which devices talked to each other and when, even when the traffic itself is encrypted.
How to verify: Link the logging, telemetry or data collection documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
Works offline weight 3
Does the keyboard work without internet access?
- ✔Yes Yes
- Has no internet permission, or makes no network requests.
- ◐Partial Partial
- Network features such as suggestions or sync are optional and off by default.
- ✖No No
- Sends typing data or requires network access.
Why: A keyboard sees every password, message and search you type.
How to verify: Link the app permissions, source code or privacy policy.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
Works offline weight 2
Does the app scan and show disk usage without contacting the internet?
- ✔Yes Yes
- Makes no network requests, or only checks for updates when you ask or after you opt in.
- ◐Partial Partial
- Works offline, but checks for updates, loads content or sends usage data by default.
- ✖No No
- Needs an internet connection to work, or sends file names or scan results to a server.
Why: A disk scan lists every file and folder name on the computer, which can reveal projects, people and habits.
How to verify: Link the source code, network documentation or privacy policy.
No account needed weight 1
Can the app be used without an account or registering an email address?
- ✔Yes Yes
- No account or registration needed.
- ◐Partial Partial
- Only some features, such as cloud storage scanning, need an account.
- ✖No No
- An account or email registration is required.
Why: An account or registration ties the app and its use to an identity.
How to verify: Link the download page, documentation or privacy policy.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
Saved locally by default weight 2
Are screenshots and recordings saved on the device unless you choose to upload them?
- ✔Yes Yes
- Saved locally; uploading is optional.
- ◐Partial Partial
- Saved locally, but some features upload automatically.
- ✖No No
- Recordings are uploaded to the vendor's cloud by default.
Why: Screen recordings often capture passwords, messages and private documents.
How to verify: Link the documentation.
No account needed weight 1
Can the app be used without an account?
- ✔Yes Yes
- No account needed.
- ◐Partial Partial
- Only some features need an account.
- ✖No No
- An account is required.
Why: An account ties recordings to an identity.
How to verify: Link the documentation or sign-up page.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
Works offline weight 3
Can text be translated on the device, without sending it to a server?
- ✔Yes Yes
- Translation runs on the device or on your own server.
- ◐Partial Partial
- Offline translation is optional, with online translation by default.
- ✖No No
- Online only.
Why: Translated text is often private, such as messages, contracts and medical letters.
How to verify: Link the documentation.
Text not kept weight 2
Is translated text deleted after translation and kept out of model training?
- ✔Yes Yes
- Not stored or used for training.
- ◐Partial Partial
- Stored or used for training unless you opt out or pay.
- ✖No No
- Stored and used for training.
Why: Stored texts can be read, breached or used to train models.
How to verify: Link the privacy policy.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
Runs on the device weight 3
Is speech converted to text on the device, without sending audio to a server?
- ✔Yes Yes
- Transcription runs fully on the device or on your own server.
- ◐Partial Partial
- Local transcription is available, but cloud processing is the default or needed for some features.
- ✖No No
- Audio is sent to the vendor's servers.
Why: Voice recordings and transcripts hold private conversations, names and health or business details.
How to verify: Link the documentation or privacy policy.
No training on recordings weight 2
Are recordings and transcripts kept out of model training by default?
- ✔Yes Yes
- Never used for training, or processing is entirely local.
- ◐Partial Partial
- Used for training by default with an opt-out.
- ✖No No
- Used for training with no opt-out.
Why: Training on recordings can expose what was said.
How to verify: Link the privacy policy.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
No training on your data weight 3
Are prompts, chats and files kept out of model training by default?
- ✔Yes Yes
- Never used for training, or the model runs entirely on your device.
- ◐Partial Partial
- Used for training by default, but you can opt out.
- ✖No No
- Used for training with no opt-out.
Why: Text sent to an AI often contains private, work or health information. Training on it can expose it later.
How to verify: Link the privacy policy or data use documentation.
Runs locally weight 2
Can the assistant run on your own device or server, so prompts never leave it?
- ✔Yes Yes
- Runs fully on your own hardware.
- ◐Partial Partial
- Can use local models, but defaults to a hosted service.
- ✖No No
- Hosted only.
Why: A local model cannot leak prompts to anyone.
How to verify: Link the documentation.
Limited chat retention weight 2
Are chats deleted by default or on request, with no long-term server copy?
- ✔Yes Yes
- Chats are not stored on servers, or are deleted within 30 days of deletion or by default.
- ◐Partial Partial
- Chats are kept until you delete them, then removed.
- ✖No No
- Chats are kept indefinitely or for review even after deletion.
Why: Stored chats can be breached, subpoenaed or read by staff.
How to verify: Link the data retention policy.
No account needed weight 1
Can it be used without an account or personal details?
- ✔Yes Yes
- No account or email needed.
- ◐Partial Partial
- Limited use without an account.
- ✖No No
- An account is required.
Why: An account ties every prompt to an identity.
How to verify: Link the sign-up page or documentation.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit, Transparency report, Tells users about requests, TLS configuration, Security headers, Modern web standards
No cookies weight 2
Does it count visitors without cookies or other identifiers stored on the device?
- ✔Yes Yes
- No cookies, local storage or fingerprinting.
- ◐Partial Partial
- Cookieless mode is available but not the default.
- ✖No No
- Uses cookies or persistent identifiers.
Why: Cookies and identifiers let visitors be followed across visits and sites, and need consent under EU law.
How to verify: Link the documentation or privacy policy.
No personal data weight 3
Does it avoid storing IP addresses and personal data, and never share data with advertisers?
- ✔Yes Yes
- No IP addresses or personal data stored, and no data shared for ads.
- ◐Partial Partial
- Personal data is anonymized by default, or stored only in self-hosted setups.
- ✖No No
- Stores personal data or shares it for advertising.
Why: Counting visits needs no profile of each visitor.
How to verify: Link the data policy.
Self-hostable weight 1
Can the analytics be self-hosted?
- ✔Yes Yes
- Officially supported self-hosting.
- ◐Partial Partial
- Possible but unsupported or limited.
- ✖No No
- Hosted only.
Why: Self-hosting keeps visitor data on your own servers.
How to verify: Link the self-hosting guide.
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit
Data stays on device weight 3
Is cycle data stored only on the device by default?
- ✔Yes Yes
- Stored only on the device unless you choose to back it up.
- ◐Partial Partial
- Synced to a server but end-to-end encrypted.
- ✖No No
- Stored on the vendor's servers in readable form.
Why: Cycle and pregnancy data can be requested by courts and police in some jurisdictions.
How to verify: Link the privacy policy or documentation.
No account needed weight 2
Can the app be used without an account?
- ✔Yes Yes
- No account needed.
- ◐Partial Partial
- Account optional.
- ✖No No
- An account is required.
Why: An account links health data to an identity.
How to verify: Link the app listing or documentation.
Propose criteria.
Social networks
Criteria for every category: Open source, No trackers or telemetry, No ads or data sales, Independent audit