Where your software actually runs, who else touches it, and how long it will be supported.
Every field below carries the page it came from and the date we read it. Nothing is a rating, a score or a verdict — we record what vendors disclose, and what changed since.
- 3of 20 state no EU data location at all
- 7publish a compliance page no ordinary client can read
- 4of 5 shipping software miss the CRA five-year floor
What is in here
For each vendor: who legally operates it, where the data sits, who else touches it, what it is certified for, how long it is supported. Every field carries the page it came from and the date we read it. 345 distinct subprocessors are recorded across 20 vendors — see who relies on whom, or the change log.
- Legal entity
- who you actually contract with, and where it is owned
- Data location
- whether an EU region exists, and which plan reaches it
- Subprocessors
- every name the vendor lists, with country and purpose
- Assurance
- what is certified, and what is only claimed
- Support window
- how long the product is supported, against the CRA floor
- Security contact
- the route for reporting a flaw, and whether it is maintained
542 sourced facts, each with its page and date · observation began 2026-09-17
Who sits underneath
A vendor-by-vendor review never shows this. These names are each recorded by several of your suppliers at once, so the blast radius of one of them is wider than any single contract suggests — and because names are transcribed exactly as each vendor writes them, never merged, the real concentration is higher than the count below. See all 345.
What this is not
A verdict is something a sponsor could buy. A dated observation is not.
Why there is no score on this site