# Lynis privacy rating

A command-line security auditing tool from CISOfy that scans Linux, macOS and other Unix-like systems and suggests hardening steps.

## Summary

Lynis scores 80 out of 100 (grade B) on the Linux hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the Netherlands: Nine Eyes member; EU member (GDPR).

- Website: https://cisofy.com/lynis/
- Source code: https://github.com/CISOfy/lynis
- License: GPL-3.0
- Jurisdiction: Netherlands. Nine Eyes member. EU member (GDPR).
- Platforms: Linux, macOS
- Home page trackers: none found
- Category: [Linux hardening](https://privacyratings.com/linux-hardening/)
- Grade: B (80/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | GPL-3.0. | https://github.com/CISOfy/lynis/blob/master/LICENSE |
| No trackers or telemetry | Yes | The website avoids analytics tools and third-party cookies, and the tool has no telemetry in its source code. | https://cisofy.com/privacy/ |
| No ads or data sales | Yes | Funded by the paid Lynis Enterprise product, with no ads. | https://cisofy.com/pricing/ |
| Independent audit | No | No independent audit is published. |  |

Source: https://privacyratings.com/linux-hardening/lynis/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/linux-hardening/lynis.md
