# Privacy rating criteria

Scoring: yes = full weight, partial = half, no and unknown = zero; not applicable and automated tests that have not run yet are left out. Score = earned / possible × 100. Grades: A ≥ 90, B ≥ 75, C ≥ 60, D ≥ 40, F < 40. A grade needs evidence for 60% of criteria by weight. Jurisdiction is shown but not scored. Picks do not change scores.

## Every category

### Open source (weight 3)

Is all the source code needed to run the product public?

- Yes: All code needed to run the product is public, the apps (front end) and, for hosted services, the server (back end), under an open-source (OSI-approved) or source-available license. Source-available entries are labeled and left out of open-source lists.
- Partial: Only part of the code is public, for example the apps but not the server, or the product's own paid edition adds unpublished code. Separate paid products and services do not count.
- No: The product is closed source.
- Why: Public code lets anyone check what the software does with your data instead of trusting a privacy policy.
- Verify: Link the source repository and its license file.

### No trackers or telemetry (weight 3)

Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?

- Yes: No third-party trackers. Any analytics, first-party or from a privacy-focused service such as Plausible, Simple Analytics or GoatCounter, are cookieless and aggregate-only, with no stored IP addresses or persistent identifiers. App telemetry is absent or opt-in.
- Partial: No third-party trackers, but analytics use cookies or persistent identifiers, or app telemetry or crash reporting is on by default.
- No: Third-party trackers or analytics are present, or telemetry cannot be turned off.
- Why: Trackers and telemetry leak usage data to the vendor and to third parties.
- Verify: Link the privacy policy or telemetry documentation, or a network capture or tracker report (for example Exodus Privacy for Android apps).

### No ads or data sales (weight 2)

Is the product funded without advertising, ad targeting or selling user data?

- Yes: Funded by payments, donations or grants. No ads, no data sales, and no sharing of user data with ad networks.
- Partial: No ads based on user data and no data sales, but ads are opt-in or contextual, or the vendor shares website or app data with ad networks to advertise its own product (retargeting).
- No: Funded by advertising, shows ads based on user data, or sells or shares user data for other companies' advertising.
- Why: An ad-funded product earns more when it collects more data about you.
- Verify: Link the pricing page, funding page or privacy policy.

### Independent audit (weight 2)

Has an independent security or privacy audit been published within the last three years?

- Yes: A full report from an independent auditor is public.
- Partial: An audit was done but only a summary is public, or the audit is older than three years.
- No: No independent audit is public.
- Why: Audits catch problems that the vendor missed or did not disclose.
- Verify: Link the published audit report.

### Transparency report (weight 2)

Does the provider regularly publish how many government and legal requests it receives and how it responds?

- Yes: Publishes a transparency report with request counts and outcomes, updated at least once a year.
- Partial: Publishes a policy on requests or a warrant canary, but no counts.
- No: Publishes nothing about government requests.
- Why: Jurisdiction alone says little. Request counts and outcomes show how much a provider hands over, and how often, under its local law.
- Verify: Link the transparency report or government request policy.

### Tells users about requests (weight 1)

Does the provider promise to tell users about requests for their data, unless a court forbids it?

- Yes: A published policy promises notice when legally allowed.
- Partial: Notice is given case by case, with no published policy.
- No: No notice, or a policy of not notifying.
- Why: Notice gives people the chance to challenge a request.
- Verify: Link the law enforcement or privacy policy.

### TLS configuration (weight 2)

Does the website pass the Qualys SSL Labs test with a grade of A or better?

- Yes: Grade A+ or A on every endpoint.
- Partial: Grade A- or B on the weakest endpoint.
- No: Grade C or lower, or the test failed.
- Why: Weak TLS settings can expose traffic and logins to interception.
- Verify: Run https://www.ssllabs.com/ssltest/ on the domain.

### Security headers (weight 1)

Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?

- Yes: Grade A+ or A.
- Partial: Grade A-, B+ or B.
- No: Grade B- or lower, or the test failed.
- Why: Headers such as CSP and HSTS block common attacks against logged-in users.
- Verify: Run https://developer.mozilla.org/en-US/observatory on the domain.

### Modern web standards (weight 1)

Does the website score 90% or higher on the Internet.nl website test?

- Yes: Score of 90% or higher.
- Partial: Score between 70% and 89%.
- No: Score below 70%.
- Why: The test checks IPv6, DNSSEC, HTTPS and security options that protect visitors.
- Verify: Run https://internet.nl/test-site/ on the domain.

## Email providers

### End-to-end encryption (weight 3)

Can mail be end-to-end encrypted so that the provider cannot read message contents?

- Yes: Built in by default between users, and supported for outside recipients (for example OpenPGP or password-protected mail).
- Partial: Supported but not by default, or only with a browser extension or separate app.
- No: Not supported.
- Why: Without end-to-end encryption, the provider and anyone with access to its servers can read mail.
- Verify: Link the documentation that describes the encryption.

### Encrypted mailbox storage (weight 3)

Is stored mail encrypted with a key the provider does not hold?

- Yes: Mailboxes are encrypted at rest with a key derived from the user's password or private key.
- Partial: Encrypted at rest, but with keys the provider holds.
- No: Stored unencrypted or undocumented.
- Why: Encrypted storage protects mail from breaches, rogue staff and bulk data requests.
- Verify: Link the security or encryption documentation.

### Open protocols (weight 2)

Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?

- Yes: IMAP and SMTP work with any client on every paid plan.
- Partial: Standard protocols need a bridge app or a higher plan.
- No: Only the provider's own apps work.
- Why: Open protocols prevent lock-in and let people choose their own apps.
- Verify: Link the IMAP and SMTP setup documentation.

### Custom domains (weight 1)

Can mail be sent and received with your own domain?

- Yes: Supported on affordable plans.
- Partial: Only on business plans.
- No: Not supported.
- Why: Your own domain makes it possible to switch providers without changing addresses.
- Verify: Link the custom domain documentation.

### Sign up without personal data (weight 2)

Can an account be created without a phone number or another email address?

- Yes: No phone number or existing email required.
- Partial: Required only in some cases, such as flagged sign-ups.
- No: A phone number or other personal data is required.
- Why: Requiring a phone number ties the account to a real identity.
- Verify: Link the sign-up page or documentation.

### Email security standards (weight 2)

Does the mail domain score 90% or higher on the Internet.nl email test?

- Yes: Score of 90% or higher.
- Partial: Score between 70% and 89%.
- No: Score below 70%.
- Why: The test checks DMARC, DKIM, SPF, DNSSEC, DANE and STARTTLS, which protect mail from spoofing and interception.
- Verify: Run https://internet.nl/test-mail/ on the mail domain.

### IMAP support (weight 2)

Does the IMAP server accept connections over implicit TLS on port 993 and advertise IMAP4rev1 or IMAP4rev2 with IDLE push?

- Yes: Implicit TLS on 993 (RFC 8314), IMAP4rev1 (RFC 3501) or IMAP4rev2 (RFC 9051), and IDLE (RFC 2177) advertised in CAPABILITY.
- Partial: IMAP works, but only with STARTTLS on 143, or without IDLE in the advertised capabilities.
- No: No IMAP server. Mail can only be read in the provider's own apps or through a local bridge.
- Why: Standard IMAP lets people use any email app and keeps them free to leave. Implicit TLS is the current recommendation for mail access.
- Verify: Connect with `openssl s_client -connect imap.example.com:993` and send `a1 CAPABILITY`.

### POP3 support (weight 1)

Does the POP3 server accept connections over implicit TLS on port 995 and answer CAPA with UIDL?

- Yes: Implicit TLS on 995 (RFC 8314), CAPA (RFC 2449) and UIDL (RFC 1939).
- Partial: POP3 works, but only with STLS on 110, or without CAPA or UIDL.
- No: No POP3 server.
- Why: POP3 is the simplest way to download and keep a full local copy of every message.
- Verify: Connect with `openssl s_client -connect pop3.example.com:995` and send `CAPA`.

### SMTP submission (weight 2)

Does mail submission work over implicit TLS on port 465 with SMTPUTF8, 8BITMIME, PIPELINING and AUTH?

- Yes: Implicit TLS on 465 (RFC 8314) with SMTPUTF8 (RFC 6531), 8BITMIME (RFC 6152), PIPELINING (RFC 2920) and AUTH (RFC 4954) in EHLO.
- Partial: Submission works, but only with STARTTLS on 587, or without one of these extensions.
- No: No SMTP submission. Mail can only be sent from the provider's own apps or through a local bridge.
- Why: Standard SMTP submission lets any app send mail, and SMTPUTF8 allows international addresses.
- Verify: Connect with `openssl s_client -connect smtp.example.com:465` and send `EHLO example.com`.

### Mail transport security (weight 3)

Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?

- Yes: SPF, DMARC set to quarantine or reject, MTA-STS in enforce mode (RFC 8461), TLS-RPT (RFC 8460), DNSSEC, and DANE TLSA records on every MX host (RFC 7672).
- Partial: DMARC is enforced and either MTA-STS is enforced or DANE is published, but not everything above.
- No: DMARC is not enforced, or neither MTA-STS nor DANE is used.
- Why: These records stop attackers from downgrading or intercepting mail in transit, and from spoofing the provider's own domain.
- Verify: Check the TXT records for _mta-sts, _smtp._tls and _dmarc, the TLSA records for _25._tcp on each MX host, and DNSSEC validation.

### Sender Rewriting Scheme (weight 1)

Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?

- Yes: SRS is applied to all forwarded mail.
- Partial: SRS is applied only in some cases or on some plans.
- No: Forwarded mail is not rewritten.
- Why: Without SRS, forwarded mail often fails SPF and lands in spam or is rejected.
- Verify: Link documentation or source code, or check the Return-Path of a forwarded message.

### ARC sealing (weight 1)

Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?

- Yes: ARC chains are validated on inbound mail and ARC seals are added to forwarded mail.
- Partial: Only one of the two.
- No: ARC is not supported.
- Why: ARC lets receivers trust authentication results after a message is forwarded or modified by a mailing list.
- Verify: Link documentation or source code, or check for ARC-Seal headers on a forwarded message.

## Email forwarding and aliases

### End-to-end encryption (weight 2)

Can mail be end-to-end encrypted so that the provider cannot read message contents?

- Yes: Built in by default between users, and supported for outside recipients (for example OpenPGP or password-protected mail).
- Partial: Supported but not by default, or only with a browser extension or separate app.
- No: Not supported.
- Why: Without end-to-end encryption, the provider and anyone with access to its servers can read mail.
- Verify: Link the documentation that describes the encryption.

### No stored mail (weight 3)

Is forwarded mail passed through without being written to disk?

- Yes: Mail is forwarded in memory and never stored, except in a documented retry queue.
- Partial: Mail is stored briefly for a documented reason.
- No: Mail is stored or logged in full.
- Why: Mail that is never stored cannot be breached or handed over later.
- Verify: Link the documentation or source code that shows how mail is handled.

### Open protocols (weight 2)

Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?

- Yes: IMAP and SMTP work with any client on every paid plan.
- Partial: Standard protocols need a bridge app or a higher plan.
- No: Only the provider's own apps work.
- Why: Open protocols prevent lock-in and let people choose their own apps.
- Verify: Link the IMAP and SMTP setup documentation.

### Custom domains (weight 1)

Can mail be sent and received with your own domain?

- Yes: Supported on affordable plans.
- Partial: Only on business plans.
- No: Not supported.
- Why: Your own domain makes it possible to switch providers without changing addresses.
- Verify: Link the custom domain documentation.

### Sign up without personal data (weight 2)

Can an account be created without a phone number or another email address?

- Yes: No phone number or existing email required.
- Partial: Required only in some cases, such as flagged sign-ups.
- No: A phone number or other personal data is required.
- Why: Requiring a phone number ties the account to a real identity.
- Verify: Link the sign-up page or documentation.

### Email security standards (weight 2)

Does the mail domain score 90% or higher on the Internet.nl email test?

- Yes: Score of 90% or higher.
- Partial: Score between 70% and 89%.
- No: Score below 70%.
- Why: The test checks DMARC, DKIM, SPF, DNSSEC, DANE and STARTTLS, which protect mail from spoofing and interception.
- Verify: Run https://internet.nl/test-mail/ on the mail domain.

### Mail transport security (weight 3)

Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?

- Yes: SPF, DMARC set to quarantine or reject, MTA-STS in enforce mode (RFC 8461), TLS-RPT (RFC 8460), DNSSEC, and DANE TLSA records on every MX host (RFC 7672).
- Partial: DMARC is enforced and either MTA-STS is enforced or DANE is published, but not everything above.
- No: DMARC is not enforced, or neither MTA-STS nor DANE is used.
- Why: These records stop attackers from downgrading or intercepting mail in transit, and from spoofing the provider's own domain.
- Verify: Check the TXT records for _mta-sts, _smtp._tls and _dmarc, the TLSA records for _25._tcp on each MX host, and DNSSEC validation.

### Sender Rewriting Scheme (weight 2)

Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?

- Yes: SRS is applied to all forwarded mail.
- Partial: SRS is applied only in some cases or on some plans.
- No: Forwarded mail is not rewritten.
- Why: Without SRS, forwarded mail often fails SPF and lands in spam or is rejected.
- Verify: Link documentation or source code, or check the Return-Path of a forwarded message.

### ARC sealing (weight 1)

Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?

- Yes: ARC chains are validated on inbound mail and ARC seals are added to forwarded mail.
- Partial: Only one of the two.
- No: ARC is not supported.
- Why: ARC lets receivers trust authentication results after a message is forwarded or modified by a mailing list.
- Verify: Link documentation or source code, or check for ARC-Seal headers on a forwarded message.

## Email clients

### OpenPGP support (weight 2)

Can the app encrypt and sign mail with OpenPGP, built in or through an official add-on?

- Yes: Built in.
- Partial: Through a separate app or add-on.
- No: Not supported.
- Why: OpenPGP gives end-to-end encryption with any provider.
- Verify: Link the documentation.

### Connects directly (weight 3)

Does the app connect directly to your mail server, without passing mail or passwords through the vendor's servers?

- Yes: Connects directly. Passwords and mail stay on the device.
- Partial: Connects directly, but optional features (such as push or sync) use vendor servers.
- No: Mail or credentials pass through vendor servers.
- Why: A client that syncs through the vendor's cloud gives the vendor a copy of every mailbox.
- Verify: Link the documentation or privacy policy that describes how the app connects.

### Blocks remote content (weight 2)

Are remote images and tracking pixels blocked by default?

- Yes: Blocked by default.
- Partial: Can be blocked in settings.
- No: Cannot be blocked.
- Why: Remote images tell senders when and where a message was opened.
- Verify: Link the documentation or settings screen.

### Works with any provider (weight 1)

Does the app work with any standard IMAP and SMTP provider?

- Yes: Any IMAP and SMTP provider.
- Partial: A limited list of providers.
- No: Only the vendor's own service.
- Why: Apps tied to one provider make switching harder.
- Verify: Link the account setup documentation.

## Webmail

### OpenPGP support (weight 2)

Can the app encrypt and sign mail with OpenPGP, built in or through an official add-on?

- Yes: Built in.
- Partial: Through a separate app or add-on.
- No: Not supported.
- Why: OpenPGP gives end-to-end encryption with any provider.
- Verify: Link the documentation.

### Connects directly (weight 3)

Does the app connect directly to your mail server, without passing mail or passwords through the vendor's servers?

- Yes: Connects directly. Passwords and mail stay on the device.
- Partial: Connects directly, but optional features (such as push or sync) use vendor servers.
- No: Mail or credentials pass through vendor servers.
- Why: A client that syncs through the vendor's cloud gives the vendor a copy of every mailbox.
- Verify: Link the documentation or privacy policy that describes how the app connects.

### Blocks remote content (weight 2)

Are remote images and tracking pixels blocked by default?

- Yes: Blocked by default.
- Partial: Can be blocked in settings.
- No: Cannot be blocked.
- Why: Remote images tell senders when and where a message was opened.
- Verify: Link the documentation or settings screen.

### Works with any provider (weight 1)

Does the app work with any standard IMAP and SMTP provider?

- Yes: Any IMAP and SMTP provider.
- Partial: A limited list of providers.
- No: Only the vendor's own service.
- Why: Apps tied to one provider make switching harder.
- Verify: Link the account setup documentation.

### Self-hostable (weight 1)

Can the webmail be installed on your own server?

- Yes: Officially supported self-hosting.
- Partial: Possible but unsupported or limited.
- No: Hosted only.
- Why: Self-hosting keeps mail and sessions on servers you control.
- Verify: Link the installation guide.

## Email sending services

### Message content deleted after delivery (weight 3)

Is the content of sent mail deleted once it has been delivered?

- Yes: Message bodies are not kept after delivery, or are kept only when the sender turns this on.
- Partial: Message bodies are kept by default for a documented period of 30 days or less, or a longer period can be shortened to 30 days or less or turned off.
- No: Message bodies are kept for more than 30 days or for an undocumented period, with no way to shorten it.
- Why: Every stored copy of a password reset, receipt or newsletter can be breached or handed over later.
- Verify: Link the documentation on message logs, content storage or data retention.

### Open and click tracking off by default (weight 2)

Are open tracking pixels and click tracking links off unless the sender turns them on?

- Yes: Open and click tracking are not offered, or are off until the sender turns them on.
- Partial: Open or click tracking is on by default, but can be turned off or made anonymous for the account or for each message.
- No: Open or click tracking is always on.
- Why: Tracking pixels and rewritten links record when, where and on which device each recipient reads mail.
- Verify: Link the tracking settings documentation or API reference.

### Encrypted delivery can be enforced (weight 2)

Can outbound mail be kept from being delivered without TLS?

- Yes: Outbound delivery honors the recipient domain's MTA-STS or DANE policy, or the sender can require TLS so mail is not sent in plain text.
- Partial: TLS is used when the receiving server offers it, with no way to require it.
- No: Outbound mail is sent without TLS.
- Why: With opportunistic TLS alone, an attacker on the network can strip encryption and read mail in transit.
- Verify: Link the TLS or delivery security documentation.

### EU data location (weight 1)

Can message content and delivery logs be processed and stored only in the European Union?

- Yes: An EU region, an EU-only service or self-hosting keeps message data in the EU, on every plan.
- Partial: An EU region is offered only on some plans, on request or in beta.
- No: Message data is processed or stored outside the EU.
- Why: Data kept in the EU stays under the GDPR and out of reach of some foreign surveillance laws.
- Verify: Link the data location, region or data residency documentation.

## Browsers

### Blocks trackers by default (weight 3)

Are third-party trackers blocked by default, without installing extensions?

- Yes: Blocked by default.
- Partial: Limits cross-site tracking (for example cookie isolation) but does not block tracker requests.
- No: Not blocked by default.
- Why: Most people never change default settings.
- Verify: Link the documentation, or a test such as https://coveryourtracks.eff.org/.

### Fingerprinting protection (weight 2)

Does the browser defend against fingerprinting by default?

- Yes: Randomizes or standardizes fingerprinting data by default.
- Partial: Only in a stricter mode that is off by default.
- No: No protection.
- Why: Fingerprinting tracks people even after cookies are cleared.
- Verify: Link the documentation, or a test such as https://coveryourtracks.eff.org/.

### No calls to big-tech services (weight 2)

Does the browser work without background connections to Google, Microsoft or Apple services?

- Yes: No background connections to big-tech services by default.
- Partial: Some connections remain and can be turned off.
- No: Background connections are built in and cannot be turned off.
- Why: Background connections share browsing activity and device data.
- Verify: Link documentation or source code that lists removed or disabled services.

### Timely security updates (weight 3)

Are security fixes from the upstream engine shipped quickly and automatically?

- Yes: Fixes ship within days and install automatically.
- Partial: Fixes ship quickly but must be installed by hand or through a package manager.
- No: Fixes often lag weeks behind upstream.
- Why: Browsers are the most attacked software on most devices.
- Verify: Link the release notes or update documentation.

## Ad and tracker blockers

### Effective by default (weight 3)

Does it block ads and trackers with its default settings, without paid tiers?

- Yes: Blocks ads and trackers by default, for free.
- Partial: Needs extra lists or configuration.
- No: Allows "acceptable ads" by default, or blocking is paid.
- Why: Allowlists paid for by advertisers let their ads and trackers through.
- Verify: Link the documentation or filter list settings.

### No browsing data collected (weight 3)

Does it work without sending browsing data to the developer?

- Yes: All filtering happens on the device, with no data sent.
- Partial: Anonymous usage statistics that can be turned off.
- No: Browsing data is collected.
- Why: An ad blocker sees every page visited.
- Verify: Link the privacy policy or source code.

### Custom filters (weight 1)

Can users add their own filter lists and rules?

- Yes: Yes.
- Partial: Limited.
- No: No.
- Why: Custom rules handle sites that default lists miss.
- Verify: Link the documentation.

## Search engines

### No search history logs (weight 3)

Are searches stored without IP addresses or other identifiers?

- Yes: Searches are not stored with identifiers.
- Partial: Identifiers are removed after a short, documented period.
- No: Searches are tied to identifiers or accounts.
- Why: Search history reveals health, money, politics and more.
- Verify: Link the privacy policy.

### No profile-based ads (weight 2)

Are ads (if any) based only on the current search, not a profile?

- Yes: No ads, or ads based only on the search terms.
- Partial: Profile-based ads can be turned off.
- No: Ads are based on a profile.
- Why: Profile-based ads need a stored profile of your searches.
- Verify: Link the privacy policy or ad documentation.

### No account needed (weight 1)

Can every feature be used without an account?

- Yes: No account needed.
- Partial: Some features need an account.
- No: An account is needed.
- Why: Accounts link searches to an identity.
- Verify: Link the help or settings page.

## App stores

### No account needed (weight 2)

Can apps be installed without an account?

- Yes: No account needed.
- Partial: Only for some apps.
- No: An account is required.
- Why: An account links every installed app to an identity.
- Verify: Link the documentation.

### Shows trackers and anti-features (weight 1)

Does the store show which apps contain trackers, ads or other anti-features?

- Yes: Shown for every app.
- Partial: Partly, for example self-reported privacy labels.
- No: Not shown.
- Why: It helps people avoid apps that track them.
- Verify: Link an example listing or documentation.

## Password managers

### End-to-end encrypted vault (weight 3)

Is the vault encrypted on the device before it is synced, with a key the provider does not hold?

- Yes: End-to-end encrypted, or local-only with no sync service.
- Partial: Encrypted, but key handling is not documented.
- No: The provider can decrypt vaults.
- Why: A breached password manager exposes every account.
- Verify: Link the security whitepaper or encryption documentation.

### Local or self-hosted option (weight 2)

Can the vault be kept locally or on your own server?

- Yes: Local files or a supported self-hosted server.
- Partial: Export only.
- No: Only the vendor's cloud.
- Why: Keeping data under your control removes a third party.
- Verify: Link the documentation.

### Full export (weight 1)

Can every item be exported in an open format?

- Yes: Full export in an open format.
- Partial: Partial export.
- No: No export.
- Why: Export prevents lock-in.
- Verify: Link the export documentation.

## Security audit firms

### Publishes full reports (weight 3)

Are full audit reports routinely published, with client consent, rather than only summaries or badges?

- Yes: Many full reports are public, listed by the firm or linked from clients.
- Partial: Some reports or summaries are public.
- No: Reports stay private.
- Why: A public report lets anyone check what was tested, what was found and what was fixed.
- Verify: Link the firm's publications page or public reports.

### Audits open-source projects (weight 2)

Does the firm regularly audit open-source software and non-profit projects?

- Yes: Regular public audits of open-source projects, for example through OSTIF or the Open Technology Fund.
- Partial: Occasional open-source audits.
- No: Commercial clients only.
- Why: Audits of open-source software protect everyone who uses it.
- Verify: Link public audits of open-source projects.

### Public research (weight 1)

Does the firm publish security research, advisories or tools?

- Yes: Regular public research, advisories or open-source tools.
- Partial: Occasional publications.
- No: None.
- Why: Published research shows expertise and helps defenders.
- Verify: Link the research or advisories page.

### No trackers on website (weight 1)

Is the firm's website free of third-party trackers?

- Yes: No third-party trackers. Any analytics are cookieless and aggregate-only.
- Partial: Analytics that use cookies or persistent identifiers, without other trackers.
- No: Third-party trackers are present.
- Why: A privacy and security firm's own site shows its standards.
- Verify: Run the tracker test or check the privacy policy.

## Messengers

### End-to-end encrypted by default (weight 3)

Are all chats, including groups, end-to-end encrypted by default?

- Yes: All chats and calls by default.
- Partial: Only some chats, or only when turned on.
- No: Not end-to-end encrypted.
- Why: Without it, the service can read messages.
- Verify: Link the encryption documentation.

### No phone number needed (weight 2)

Can an account be created without a phone number?

- Yes: No phone number needed.
- Partial: A phone number is needed but can be hidden from contacts.
- No: A phone number is needed and visible.
- Why: Phone numbers are tied to real identities.
- Verify: Link the sign-up documentation.

### Metadata protection (weight 2)

Does the service minimize who-talks-to-whom metadata (for example sealed sender or no user identifiers)?

- Yes: Documented design that hides sender or contact lists from the server.
- Partial: Some metadata protection.
- No: The server sees who talks to whom.
- Why: Metadata alone can reveal relationships and habits.
- Verify: Link the documentation or design paper.

### Decentralized (weight 1)

Can people run their own server or talk peer to peer?

- Yes: Federated or peer to peer.
- Partial: Self-hosting is possible but not federated.
- No: One central service.
- Why: Decentralized networks cannot be shut down or censored at one point.
- Verify: Link the self-hosting documentation.

## Video calls

### End-to-end encrypted (weight 3)

Are calls end-to-end encrypted by default?

- Yes: All calls, including group calls, by default.
- Partial: Optional, or only for some calls.
- No: Not end-to-end encrypted.
- Why: Without end-to-end encryption, the provider can access calls.
- Verify: Link the security documentation.

### Join without an account (weight 1)

Can people join calls without an account?

- Yes: Guests join from a link with no account.
- Partial: Only the host needs an account.
- No: Everyone needs an account.
- Why: Accounts tie calls to identities.
- Verify: Link the documentation.

### Self-hostable (weight 1)

Can the server be self-hosted?

- Yes: Officially supported.
- Partial: Possible but limited.
- No: Hosted only.
- Why: Self-hosting keeps call metadata on your own servers.
- Verify: Link the self-hosting guide.

## SMS and voice APIs

### Message content deleted or redacted (weight 3)

Can the text of messages be kept from being stored after delivery?

- Yes: Message bodies are not stored after delivery, or the customer can turn on redaction or deletion for every message without asking.
- Partial: Message bodies are kept for a documented period of 30 days or less, or can be deleted through the API, or redaction is available on request or on some plans.
- No: Message bodies are kept for more than 30 days or an undocumented period, with no way to delete them.
- Why: Stored texts hold one-time codes, appointments and personal conversations tied to phone numbers.
- Verify: Link the data retention, message redaction or deletion documentation.

### EU data location (weight 1)

Can messages, call records and logs be processed and stored in the European Union?

- Yes: An EU region, an EU-only service or self-hosting keeps message data in the EU, on every plan.
- Partial: An EU region is offered only on some plans, on request or in beta.
- No: Message data is processed or stored outside the EU.
- Why: Data kept in the EU stays under the GDPR and out of reach of some foreign surveillance laws.
- Verify: Link the data location, region or data residency documentation.

## VPN providers

### Audited no-logs policy (weight 3)

Has an independent audit confirmed that activity and connection logs are not kept?

- Yes: A public audit report confirms it.
- Partial: A no-logs policy exists but has not been audited.
- No: Logs are kept, or there is no policy.
- Why: A VPN sees all traffic. Only an audit shows the policy is followed.
- Verify: Link the audit report and the privacy policy.

### Anonymous payment (weight 2)

Can an account be created and paid for without an email address, name or card?

- Yes: Accounts need no email, and cash or Monero is accepted.
- Partial: Cryptocurrency is accepted but an email is needed.
- No: Personal data is required.
- Why: Payment details tie the account to a real identity.
- Verify: Link the payment and sign-up documentation.

### Open-source apps (weight 2)

Are the apps for every platform open source?

- Yes: All platforms.
- Partial: Some platforms.
- No: None.
- Why: The VPN app handles all traffic and keys.
- Verify: Link the source repositories.

### Modern protocols (weight 1)

Is WireGuard (or another modern audited protocol) supported?

- Yes: WireGuard supported.
- Partial: Only OpenVPN or IKEv2.
- No: Only outdated or proprietary protocols.
- Why: Modern protocols are faster and have smaller, audited codebases.
- Verify: Link the documentation.

## DNS resolvers

### Encrypted DNS (weight 3)

Are DNS over HTTPS and DNS over TLS supported?

- Yes: Both.
- Partial: One of them.
- No: Neither.
- Why: Unencrypted DNS shows every site visited to anyone on the network.
- Verify: Link the setup documentation.

### No query logs (weight 3)

Are queries stored without IP addresses, and is this independently audited?

- Yes: No identifying logs, confirmed by an audit.
- Partial: No identifying logs claimed, but not audited, or logs kept briefly.
- No: Identifying logs are kept.
- Why: DNS logs are a full browsing history.
- Verify: Link the privacy policy and audit.

### DNSSEC validation (weight 1)

Does the resolver validate DNSSEC?

- Yes: Yes.
- Partial: Optional.
- No: No.
- Why: Validation stops forged DNS answers.
- Verify: Link the documentation or a test.

## DNS hosting

### DNSSEC (weight 3)

Can DNSSEC be turned on for hosted zones?

- Yes: One click or automatic.
- Partial: Supported with manual steps.
- No: Not supported.
- Why: DNSSEC stops attackers from forging a domain's records.
- Verify: Link the documentation.

### API access (weight 1)

Can records be managed through an API on every plan?

- Yes: Yes, on every plan.
- Partial: Only on paid plans.
- No: No API.
- Why: An API makes automation and migrations possible.
- Verify: Link the API documentation.

### Two-factor login (weight 2)

Do accounts support two-factor authentication with an authenticator app or security key?

- Yes: TOTP or security keys.
- Partial: SMS only.
- No: No two-factor login.
- Why: A hijacked DNS account can redirect all mail and web traffic.
- Verify: Link the documentation.

## Domain registrars

### Free WHOIS privacy (weight 2)

Is registrant data hidden from public WHOIS and RDAP at no extra cost?

- Yes: Free for every supported domain extension.
- Partial: Free for some extensions only, or paid.
- No: Not offered.
- Why: Public registrant data exposes names, addresses and phone numbers.
- Verify: Link the pricing or privacy documentation.

### Honest renewal pricing (weight 1)

Are renewal prices the same as, or close to, the first-year price?

- Yes: At-cost or flat renewal pricing.
- Partial: Renewals cost somewhat more.
- No: Large renewal increases.
- Why: Cheap first years with expensive renewals make it costly to keep a domain.
- Verify: Link the pricing page.

### Two-factor login (weight 2)

Do accounts support two-factor authentication with an authenticator app or security key?

- Yes: TOTP or security keys.
- Partial: SMS only.
- No: No two-factor login.
- Why: A hijacked registrar account means a hijacked domain.
- Verify: Link the documentation.

### Transfer and registry lock (weight 1)

Is transfer lock on by default, with registry lock available?

- Yes: Both.
- Partial: Transfer lock only.
- No: Neither.
- Why: Locks prevent domain theft.
- Verify: Link the documentation.

## Server hosting

### Mail-friendly (port 25) (weight 1)

Is outbound port 25 open by default, or opened on request?

- Yes: Open by default.
- Partial: Blocked by default but opened on request.
- No: Always blocked.
- Why: Running a mail server needs outbound port 25.
- Verify: Link the documentation or support policy.

### Reverse DNS (weight 1)

Can reverse DNS (PTR) records be set for IPv4 and IPv6?

- Yes: Both, self-service.
- Partial: On request, or IPv4 only.
- No: Not supported.
- Why: Mail servers without matching reverse DNS are rejected as spam.
- Verify: Link the documentation.

### IPv6 (weight 1)

Is native IPv6 included?

- Yes: Yes, at no extra cost.
- Partial: For an extra fee.
- No: No.
- Why: IPv6 is required for modern networking and many mail tests.
- Verify: Link the documentation.

### Anonymous payment (weight 1)

Can servers be paid for with cryptocurrency or without identity checks?

- Yes: Yes.
- Partial: Only after verification.
- No: No.
- Why: Payment details tie servers to an identity.
- Verify: Link the payment documentation.

## Status pages and uptime monitoring

### Runs on your own infrastructure (weight 3)

Can it run entirely on your own infrastructure or repository, without a vendor account?

- Yes: Fully self-hosted or runs in your own repository.
- Partial: Self-hosted with optional vendor services.
- No: Hosted by the vendor only.
- Why: Status data and visitor logs stay under your control.
- Verify: Link the installation documentation.

### No visitor tracking (weight 2)

Is the public status page free of third-party trackers and analytics?

- Yes: No third-party trackers.
- Partial: Analytics can be turned off.
- No: Trackers are always included.
- Why: Status pages are visited by customers during outages.
- Verify: Link the source code or privacy policy.

### Public uptime history (weight 1)

Does it publish response times and incident history?

- Yes: Yes.
- Partial: Current status only.
- No: No.
- Why: History shows how reliable a service has been over time.
- Verify: Link a live example.

## Mesh VPNs and private networks

### Keys stay on devices (weight 3)

Is traffic encrypted between devices with private keys created on each device, so the coordination server and relays cannot read it?

- Yes: Private keys are created on each device and never leave it. Relays only forward encrypted packets.
- Partial: Traffic is encrypted between devices, but key handling is not documented, or some setups use keys created on the server.
- No: Traffic is decrypted on the vendor's servers.
- Why: The coordination server knows every device on the network. Keys that stay on the devices keep it from reading the traffic too.
- Verify: Link the security or architecture documentation that describes key generation and relays.

### Self-hosted coordination server (weight 2)

Can the coordination or control server be self-hosted with open-source software?

- Yes: The vendor's control server is open source and can be self-hosted, or the network needs no central server.
- Partial: Self-hosting needs a proprietary or source-available server, is not officially supported, or works only through a third-party open-source replacement.
- No: Only the vendor's hosted service can be used.
- Why: A self-hosted server keeps the list of devices, users and access rules off a third party's servers.
- Verify: Link the self-hosting documentation and the server's license.

### No connection logs by default (weight 2)

Are connection logs and client diagnostic logs kept off the vendor's servers unless a user or admin turns them on?

- Yes: Nothing is sent to the vendor by default, or there is no vendor service.
- Partial: Logs or crash reports are sent to the vendor by default, but can be turned off.
- No: Connection logs are kept by the vendor, with no documented way to turn them off.
- Why: Connection logs show which devices talked to each other and when, even when the traffic itself is encrypted.
- Verify: Link the logging, telemetry or data collection documentation.

## Mobile keyboards

### Works offline (weight 3)

Does the keyboard work without internet access?

- Yes: Has no internet permission, or makes no network requests.
- Partial: Network features such as suggestions or sync are optional and off by default.
- No: Sends typing data or requires network access.
- Why: A keyboard sees every password, message and search you type.
- Verify: Link the app permissions, source code or privacy policy.

## Disk usage analyzers

### Works offline (weight 2)

Does the app scan and show disk usage without contacting the internet?

- Yes: Makes no network requests, or only checks for updates when you ask or after you opt in.
- Partial: Works offline, but checks for updates, loads content or sends usage data by default.
- No: Needs an internet connection to work, or sends file names or scan results to a server.
- Why: A disk scan lists every file and folder name on the computer, which can reveal projects, people and habits.
- Verify: Link the source code, network documentation or privacy policy.

### No account needed (weight 1)

Can the app be used without an account or registering an email address?

- Yes: No account or registration needed.
- Partial: Only some features, such as cloud storage scanning, need an account.
- No: An account or email registration is required.
- Why: An account or registration ties the app and its use to an identity.
- Verify: Link the download page, documentation or privacy policy.

## Screenshots and screen recording

### Saved locally by default (weight 2)

Are screenshots and recordings saved on the device unless you choose to upload them?

- Yes: Saved locally; uploading is optional.
- Partial: Saved locally, but some features upload automatically.
- No: Recordings are uploaded to the vendor's cloud by default.
- Why: Screen recordings often capture passwords, messages and private documents.
- Verify: Link the documentation.

### No account needed (weight 1)

Can the app be used without an account?

- Yes: No account needed.
- Partial: Only some features need an account.
- No: An account is required.
- Why: An account ties recordings to an identity.
- Verify: Link the documentation or sign-up page.

## Translation

### Works offline (weight 3)

Can text be translated on the device, without sending it to a server?

- Yes: Translation runs on the device or on your own server.
- Partial: Offline translation is optional, with online translation by default.
- No: Online only.
- Why: Translated text is often private, such as messages, contracts and medical letters.
- Verify: Link the documentation.

### Text not kept (weight 2)

Is translated text deleted after translation and kept out of model training?

- Yes: Not stored or used for training.
- Partial: Stored or used for training unless you opt out or pay.
- No: Stored and used for training.
- Why: Stored texts can be read, breached or used to train models.
- Verify: Link the privacy policy.

## Dictation and transcription

### Runs on the device (weight 3)

Is speech converted to text on the device, without sending audio to a server?

- Yes: Transcription runs fully on the device or on your own server.
- Partial: Local transcription is available, but cloud processing is the default or needed for some features.
- No: Audio is sent to the vendor's servers.
- Why: Voice recordings and transcripts hold private conversations, names and health or business details.
- Verify: Link the documentation or privacy policy.

### No training on recordings (weight 2)

Are recordings and transcripts kept out of model training by default?

- Yes: Never used for training, or processing is entirely local.
- Partial: Used for training by default with an opt-out.
- No: Used for training with no opt-out.
- Why: Training on recordings can expose what was said.
- Verify: Link the privacy policy.

## AI assistants

### No training on your data (weight 3)

Are prompts, chats and files kept out of model training by default?

- Yes: Never used for training, or the model runs entirely on your device.
- Partial: Used for training by default, but you can opt out.
- No: Used for training with no opt-out.
- Why: Text sent to an AI often contains private, work or health information. Training on it can expose it later.
- Verify: Link the privacy policy or data use documentation.

### Runs locally (weight 2)

Can the assistant run on your own device or server, so prompts never leave it?

- Yes: Runs fully on your own hardware.
- Partial: Can use local models, but defaults to a hosted service.
- No: Hosted only.
- Why: A local model cannot leak prompts to anyone.
- Verify: Link the documentation.

### Limited chat retention (weight 2)

Are chats deleted by default or on request, with no long-term server copy?

- Yes: Chats are not stored on servers, or are deleted within 30 days of deletion or by default.
- Partial: Chats are kept until you delete them, then removed.
- No: Chats are kept indefinitely or for review even after deletion.
- Why: Stored chats can be breached, subpoenaed or read by staff.
- Verify: Link the data retention policy.

### No account needed (weight 1)

Can it be used without an account or personal details?

- Yes: No account or email needed.
- Partial: Limited use without an account.
- No: An account is required.
- Why: An account ties every prompt to an identity.
- Verify: Link the sign-up page or documentation.

## Website analytics

### No cookies (weight 2)

Does it count visitors without cookies or other identifiers stored on the device?

- Yes: No cookies, local storage or fingerprinting.
- Partial: Cookieless mode is available but not the default.
- No: Uses cookies or persistent identifiers.
- Why: Cookies and identifiers let visitors be followed across visits and sites, and need consent under EU law.
- Verify: Link the documentation or privacy policy.

### No personal data (weight 3)

Does it avoid storing IP addresses and personal data, and never share data with advertisers?

- Yes: No IP addresses or personal data stored, and no data shared for ads.
- Partial: Personal data is anonymized by default, or stored only in self-hosted setups.
- No: Stores personal data or shares it for advertising.
- Why: Counting visits needs no profile of each visitor.
- Verify: Link the data policy.

### Self-hostable (weight 1)

Can the analytics be self-hosted?

- Yes: Officially supported self-hosting.
- Partial: Possible but unsupported or limited.
- No: Hosted only.
- Why: Self-hosting keeps visitor data on your own servers.
- Verify: Link the self-hosting guide.

## Period trackers

### Data stays on device (weight 3)

Is cycle data stored only on the device by default?

- Yes: Stored only on the device unless you choose to back it up.
- Partial: Synced to a server but end-to-end encrypted.
- No: Stored on the vendor's servers in readable form.
- Why: Cycle and pregnancy data can be requested by courts and police in some jurisdictions.
- Verify: Link the privacy policy or documentation.

### No account needed (weight 2)

Can the app be used without an account?

- Yes: No account needed.
- Partial: Account optional.
- No: An account is required.
- Why: An account links health data to an identity.
- Verify: Link the app listing or documentation.
