# .NET web frameworks privacy ratings

Web and API frameworks for C# and .NET. The .NET SDK itself sends telemetry by default.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [Carter](https://privacyratings.com/dotnet-frameworks/carter/) | B (80/100) | Unknown | Library for ASP.NET Core that organizes minimal API routes into modules, with support for validation and content negotiation. |
| [Orchard Core](https://privacyratings.com/dotnet-frameworks/orchard-core/) | C (70/100) | United States (Five Eyes) | Modular application framework and content management system built on ASP.NET Core, with multi-tenancy and a headless CMS mode. |
| [ASP.NET Core](https://privacyratings.com/dotnet-frameworks/asp-net-core/) | D (50/100) | United States (Five Eyes) | Microsoft framework for building web apps, APIs and real-time services in C# on .NET, with MVC, Razor Pages, minimal APIs and SignalR. |
| [Blazor](https://privacyratings.com/dotnet-frameworks/blazor/) | D (50/100) | United States (Five Eyes) | Microsoft framework for building interactive web user interfaces in C# with Razor components, running on the server or in the browser through WebAssembly. |
| [FastEndpoints](https://privacyratings.com/dotnet-frameworks/fastendpoints/) | D (50/100) | Unknown | Library for building REST APIs on ASP.NET Core in which each endpoint is a class with its own request and response types (the REPR pattern). |
| [ServiceStack](https://privacyratings.com/dotnet-frameworks/servicestack/) | D (50/100) | United States (Five Eyes) | Framework for building message-based web services and APIs on .NET, with typed clients, an ORM and generated admin interfaces. Dual-licensed under the AGPL and a commercial license. |
| [ABP Framework](https://privacyratings.com/dotnet-frameworks/abp-framework/) | D (40/100) | Türkiye | Application framework for ASP.NET Core from Volosoft, with a modular architecture, domain-driven design building blocks, multi-tenancy and startup templates. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?

Source: https://privacyratings.com/dotnet-frameworks/
