# CrowdSec privacy rating

An open source security engine that detects attacks in logs and blocks offending IP addresses, and shares signals with a crowdsourced blocklist run by the French company CrowdSec.

## Summary

CrowdSec scores 35 out of 100 (grade F) on the Linux hardening criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).

- Website: https://www.crowdsec.net
- Source code: https://github.com/crowdsecurity/crowdsec
- License: MIT
- Jurisdiction: France. Nine Eyes member. EU member (GDPR).
- Platforms: Linux, Windows
- Home page trackers: Google Analytics, Google Tag Manager, Hotjar, HubSpot, LinkedIn Insight, X (Twitter) Pixel
- Category: [Linux hardening](https://privacyratings.com/linux-hardening/)
- Grade: F (35/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Partial | The Security Engine is MIT-licensed, but the Central API and console that provide the community blocklist are closed source. | https://github.com/crowdsecurity/crowdsec/blob/master/LICENSE |
| No trackers or telemetry | No | The website loads Google Analytics, Hotjar, HubSpot and LinkedIn tracking. The engine sends signal metadata and usage metrics to CrowdSec unless the Central API is disabled. | https://docs.crowdsec.net/docs/central_api/intro/ |
| No ads or data sales | Yes | Funded by paid plans and threat intelligence built from community signals about attacking IP addresses, with no ads. | https://www.crowdsec.net/pricing |
| Independent audit | No | No independent audit is published. |  |

Source: https://privacyratings.com/linux-hardening/crowdsec/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/linux-hardening/crowdsec.md
