# Suricata privacy rating

Network intrusion detection and prevention engine and network security monitoring tool that inspects traffic against rule sets and logs protocol events and alerts.

## Summary

Suricata scores 50 out of 100 (grade D) on the intrusion detection criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.

- Website: https://suricata.io
- Source code: https://github.com/OISF/suricata
- License: GPL-2.0
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Linux, Windows, macOS
- Home page trackers: none found
- Category: [Intrusion detection](https://privacyratings.com/intrusion-detection/)
- Grade: D (50/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | GPL-2.0. | https://github.com/OISF/suricata/blob/main/LICENSE |
| No trackers or telemetry | No | The engine has no telemetry, but the website privacy policy lists Google Analytics, Google AdWords and Facebook tracking. | https://suricata.io/privacy-policy/ |
| No ads or data sales | Yes | Developed by the non-profit Open Information Security Foundation, funded by consortium memberships and training, with no ads or data sales. | https://oisf.net/ |
| Independent audit | No | No independent audit is published. |  |

Source: https://privacyratings.com/intrusion-detection/suricata/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/intrusion-detection/suricata.md
