Skip to content

Security Scorecard

Security ratings from A to F for 160 developer services. We check SOC2, HIPAA, and GDPR certifications, encryption at rest and in transit, MFA enforcement, SSO availability, audit logging, bug bounty programs, and public breach history. Know before you trust them with your data.

160
Services rated
43
A-rated
111
SOC2 certified
17
Had breaches
SupabaseBaaS
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Row-level security built-in. Self-hosted option for full control.

FirebaseBaaS
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Google Cloud security. BAA available for HIPAA. Security rules DSL.

ClerkAuth
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

Auth provider — security is their core product. Built-in bot detection.

StripePayments
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

PCI DSS Level 1. Best-in-class payment security. Radar for fraud.

SentryMonitoring
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Data scrubbing for PII. Self-hosted option. BAA for HIPAA.

PlanetScaleDatabase
A
+ SOC2+ HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Vitess-based. Non-blocking schema changes reduce incident risk.

AnthropicAI API
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

30-day data retention for abuse monitoring (can opt out on Enterprise). Strong security posture from safety-focused culture.

Auth0Auth
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

Enterprise-grade auth. Okta parent company adds security depth. Adaptive MFA, bot detection built-in.

DatadogMonitoring
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

Enterprise-grade. HIPAA-eligible logs. FedRAMP authorized. Agent runs with host access — ensure proper scoping.

Grafana CloudMonitoring
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

HIPAA BAA available on Pro and Enterprise. SOC2 Type II. RBAC granular controls. Open-source core allows self-hosted if needed.

Redis CloudCache/Database
A
+ SOC2+ HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Redis Enterprise features: RBAC, TLS mutual auth, CRDT-based Active-Active. HIPAA BAA on Premium. PCI DSS compliant.

CockroachDBDatabase
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Distributed SQL with built-in encryption. SOC2 Type II. HIPAA BAA on Dedicated. Column-level encryption available. FedRAMP in progress.

FastlyCDN/Edge
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

PCI DSS Level 1. HIPAA BAA available. Real-time log streaming. WAF powered by Signal Sciences. Edge Compute runs in isolated sandbox.

AkamaiCDN/Edge
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

FedRAMP authorized. PCI DSS Level 1. Largest CDN network. Prolexic DDoS protection. Enterprise-grade WAF and bot management.

WorkOSAuth
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

Enterprise SSO/SCIM provider — security is core product. SOC2 Type II. Directory Sync with SCIM 2.0. Admin Portal for customer self-service. Bug bounty via HackerOne.

LaunchDarklyFeature Flags
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II, HIPAA BAA on Enterprise. Audit log with full flag change history. RBAC with custom roles. Relay Proxy for air-gapped environments. FedRAMP authorized.

TiDB CloudDatabase
A
+ SOC2+ HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II, HIPAA BAA on Dedicated Tier. MySQL-compatible distributed SQL. RBAC with fine-grained column-level permissions. Data encryption via AWS KMS or GCP CMEK.

YugabyteDB ManagedDatabase
A
+ SOC2+ HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. HIPAA BAA on Dedicated. Distributed PostgreSQL-compatible. Column-level encryption. VPC peering for network isolation. Audit logging on all tiers.

StytchAuth
A
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II. Passwordless-first approach reduces credential stuffing risk. Device fingerprinting built-in. SSO and SCIM on Enterprise. B2B auth focus.

AmplitudeAnalytics
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II, HIPAA BAA on Enterprise. EU data residency available. PII governance controls. RBAC with custom roles. ISO 27001 certified.

SplunkMonitoring
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

Enterprise SIEM leader. FedRAMP authorized. PCI DSS compliant. Role-based access with granular index-level permissions. Splunk Cloud is SOC2 Type II and ISO 27001.

Elastic CloudSearch/Monitoring
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II, HIPAA BAA on Enterprise. Elasticsearch encryption at rest via AES-256. RBAC with field-level security. Self-hosted option for full control.

DynatraceMonitoring
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II, ISO 27001, FedRAMP authorized. HIPAA BAA available. OneAgent runs with host access — scope permissions carefully. Data residency options for EU.

TimescaleDB CloudDatabase
A
+ SOC2+ HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II, HIPAA BAA on Enterprise. Built on PostgreSQL — inherits PG security model. VPC peering available. Column-level encryption via pgcrypto.

ClickHouse CloudDatabase
A
+ SOC2+ HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II, HIPAA BAA on Dedicated. OLAP database. RBAC with row-level security policies. IP whitelisting. Private endpoints via AWS PrivateLink or GCP Private Service Connect.

HashiCorp VaultSecurity
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

Industry-standard secrets manager. SOC2 Type II, FedRAMP authorized (HCP Vault). Dynamic secrets, encryption-as-a-service, PKI. Self-hosted or HCP managed. Audit log with detailed request tracing.

Terraform CloudIaC
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II. State files encrypted at rest. Sentinel policy-as-code for governance. SSO on Business. Audit log tracks all state and plan operations. Run tasks for pre-apply checks.

Temporal CloudWorkflow Engine
A
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II. mTLS for all worker-to-server communication. Data converter encryption for payload-level security. SSO via SAML. Namespace-level isolation. Audit log on all plans.

MiroCollaboration
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II, ISO 27001, HIPAA BAA on Enterprise. SAML SSO on Business+. Audit log on Enterprise. Board-level sharing controls. Data residency in EU available.

GitLabDevOps
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II, ISO 27001. Self-managed option for full control. SAML SSO on Premium+. Audit events on Premium+. Transparent security handbook published publicly.

Cloudflare R2Storage
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

Inherits Cloudflare security posture. S3-compatible. Server-side encryption at rest. Access via Workers bindings or API tokens. Zero egress fees. SOC2 Type II.

ShopifyE-commerce
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required
2020: Two rogue employees accessed ~200 merchant transaction records

PCI DSS Level 1. SOC2 Type II. Bug bounty via HackerOne. 2020 insider threat was contained and employees terminated. Staff permissions model is robust.

ContentstackCMS
A
+ SOC2+ HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II, HIPAA BAA on Enterprise. ISO 27001. SAML SSO. Granular RBAC with custom roles. Audit log on all plans. Content versioning with rollback capability.

HoneycombObservability
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II, ISO 27001. SAML SSO on Enterprise. Audit log via API. Field-level data redaction at ingest via processors. Strong opinionated security defaults. No HIPAA BAA.

Temporal CloudWorkflow Engine
A
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II. mTLS for all worker-to-server connections. Data converter for payload-level encryption. SAML SSO. Namespace-level isolation. Audit log on all plans. No HIPAA BAA.

WorkOSAuth
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II, ISO 27001. Enterprise SSO/SCIM is the core product. SCIM 2.0 provisioning. Admin Portal for customer self-service. Bug bounty via HackerOne. No HIPAA BAA.

StytchAuth
A
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II. Passwordless-first reduces credential stuffing risk. Device fingerprinting built-in. SCIM on Enterprise. B2B auth focus. No HIPAA BAA. No bug bounty.

SegmentAnalytics/CDP
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II, HIPAA BAA on Business+. Part of Twilio — inherits enterprise security posture. Audit log for all workspace changes. RBAC with workspace-level access control. Destination-level data filtering.

DopplerSecrets Mgmt
A
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II. Secrets encrypted at rest with AES-256-GCM. All API calls audited. SSO on Team+. Immutable audit log — cannot be deleted. No HIPAA BAA. CLI, GitHub Actions, and Kubernetes integrations.

dbt CloudAnalytics/Transform
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II. SAML SSO on Enterprise. Audit log for all developer actions. IP allowlisting on Enterprise. Credentials for data warehouse connections encrypted with per-customer keys. Bug bounty via HackerOne.

Segment (Twilio)Analytics/CDP
A
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

SOC2 Type II, HIPAA BAA on Business+. Twilio parent company provides deep enterprise security posture. Workspace RBAC. Audit log for all changes. Destination-level data controls. Bug bounty via HackerOne.

Supabase BranchingDatabase
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Branching creates isolated Postgres instances per PR. Each branch has separate credentials. Inherits Supabase's SOC2 and encryption. RLS applies per branch.

HasuraAPI
A
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Role-based access control for GraphQL. JWT and webhook auth modes. Allow-list for production queries. API rate limiting. Self-host for full control.

VercelHosting
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

No bug bounty program. SSO only on Enterprise. Deployment protection available.

MongoDB AtlasDatabase
B
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional
2023: Phishing attack on corporate systems, no customer data exposed

Client-side field-level encryption available. 2023 incident was contained.

PostHogAnalytics
B
+ SOC2+ HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Self-hosted option for full data control. EU cloud available.

CloudflareCDN/Edge
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required
2017: Cloudbleed — memory leak exposed data from other customers

Cloudbleed was severe but quickly patched. WAF and DDoS protection built-in.

OpenAIAI API
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional
2023: ChatGPT conversation history leak due to Redis bug

API data not used for training by default. Enterprise plan offers data processing agreement. 2023 leak was patched quickly.

NetlifyHosting
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Decent security posture. SSO on Business plan. No bug bounty. Deploy previews can leak sensitive data if misconfigured.

NeonDatabase
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO- Audit LogMFA: Optional

Serverless Postgres. SOC2 Type II attained 2024. No HIPAA BAA. Branching model means dev branches share infra — scope access carefully.

LinearProductivity
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. SSO on Business plan. Audit log available. No HIPAA. API tokens are long-lived — rotate regularly.

TwilioCommunications
B
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required
2022: Employee phishing attack via SMS, 125 customer accounts accessed

2022 breach was phishing-based, not infra failure. HIPAA BAA available. PCI DSS Level 1. Watch for account takeover via phone number porting.

InfisicalSecurity
B
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Open-source secrets manager. End-to-end encryption — Infisical can't read your secrets. Self-hosted option available. No SOC2 yet (in progress).

InngestBackground Jobs
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II achieved 2024. Event payloads encrypted at rest. SSO on Pro plan. No HIPAA BAA. Function execution logs retained 7 days.

Deno DeployEdge
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

V8 isolate sandboxing provides strong runtime security. SOC2 Type II. No SSO or audit log yet. Deno's secure-by-default permissions model is a plus.

UpstashCache/Database
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. REST-based access with per-key token scoping. SSO on Pro. Data encrypted with AES-256 at rest. No HIPAA BAA.

DigitalOceanCloud
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional
2020: Billing data exposed for ~1% of customers due to internal doc leak

SOC2 Type II. No HIPAA BAA. 2020 billing incident was minor and quickly contained. VPC and firewall controls available. Cloud HSM not available.

ConvexBaaS
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Serverless functions run in deterministic sandbox. Row-level access control via helper functions. No HIPAA BAA. Audit log on Pro.

XataDatabase
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Built on PostgreSQL. Branch-per-environment model. SSO on Business plan. No HIPAA BAA. API keys are scoped per-database.

PostmarkEmail
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. DKIM/SPF/DMARC enforcement. 45-day message retention. SSO available. No HIPAA BAA. Strict anti-spam policy — accounts reviewed manually.

FlagsmithFeature Flags
B
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Open-source with self-hosted option. No SOC2 on cloud (in progress). SSO available on Scale plan. Audit log tracks flag changes. RBAC per-project.

Cal.comScheduling
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II achieved 2024. Open-source with self-hosted option. SSO on Enterprise. Calendar data contains meeting details — scope access carefully. OAuth integrations require careful permission scoping.

n8nAutomation
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II on n8n Cloud. Self-hosted option for full control. Workflows store credentials for third-party services — credential encryption is critical. SSO on Enterprise.

Backblaze B2Storage
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO+ Audit LogMFA: Optional

SOC2 Type II. S3-compatible API. Server-side encryption with SSE-B2 or SSE-C. No SSO — account-level auth only. Application keys with bucket-scoped permissions.

New RelicMonitoring
B
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required
2023: Staging environment breach via compromised employee credentials

SOC2 Type II, HIPAA BAA on Enterprise. 2023 staging breach did not expose customer telemetry data. FedRAMP Moderate. SAML SSO on Pro+.

InfluxDB CloudDatabase
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Time-series database. API token scoping per bucket. SSO on Enterprise. No HIPAA BAA. Self-hosted OSS option for compliance-sensitive workloads.

ConsulNetworking
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty- Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Service mesh and service discovery. mTLS between services. ACL system with token-based auth. Self-hosted requires manual TLS setup for gossip protocol. HCP Consul is SOC2 Type II.

Kong GatewayAPI Gateway
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

API gateway with plugin-based security. Rate limiting, OAuth2, mTLS plugins. Kong Konnect (cloud) is SOC2 Type II. Self-hosted OSS requires manual security hardening.

Pulumi CloudIaC
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. State encrypted at rest. Secrets encrypted per-stack with configurable providers (AWS KMS, etc.). SSO on Enterprise. No HIPAA BAA. Self-managed backends available.

ZapierAutomation
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Stores OAuth tokens for 7000+ integrations — high-value target. SSO on Company plan. Audit log on Enterprise. No HIPAA BAA. Zap data retained 30 days.

NotionProductivity
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. SAML SSO on Enterprise. Audit log on Enterprise. No HIPAA BAA. Content is not end-to-end encrypted — Notion can access workspace content. API tokens are long-lived.

FigmaDesign
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. SAML SSO on Organization plan. Audit log on Enterprise. No HIPAA BAA. Design files may contain sensitive mockups — control sharing and link access settings.

Jira CloudProductivity
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required
2022: SolarWinds-style supply chain concern flagged but no breach confirmed

SOC2 Type II, ISO 27001. Atlassian Guard (formerly Access) for SSO and MFA enforcement. Audit log via Atlassian Admin. No HIPAA BAA. Cloud vs Data Center security models differ significantly.

BitbucketDevOps
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

Atlassian product — shares Atlassian Guard for SSO and MFA. SOC2 Type II. No HIPAA BAA. Audit log via Atlassian Admin. IP allowlisting on Premium.

WasabiStorage
B
+ SOC2+ HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II, HIPAA BAA available. S3-compatible storage. Server-side encryption AES-256. IAM with bucket policies. SSO on Enterprise. No egress fees reduces cost-driven security shortcuts.

BigCommerceE-commerce
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II, PCI DSS Level 1. ISO 27001. SSO on Enterprise. API tokens with OAuth scoping. No bug bounty program. WAF and DDoS protection included.

StoryblokCMS
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. SAML SSO on Business+. Audit log available. No HIPAA BAA. API tokens with per-space scoping. Content delivery via CDN with token-based preview access.

WebflowWebsite Builder
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. SAML SSO on Enterprise. Audit log on Enterprise. Bug bounty via HackerOne. No HIPAA BAA. Site-level publishing permissions. Custom code injection requires trust in editors.

GroqAI API
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II achieved 2024. LPU inference platform. API keys with org/project scoping. SSO on Enterprise. No HIPAA BAA. Inputs/outputs not retained for training per default policy.

ModalServerless GPU
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Serverless GPU compute. gVisor sandboxing for function isolation. Secrets encrypted via cloud KMS. SSO on Team plan. No HIPAA BAA. Volumes encrypted at rest.

SlackCommunications
B
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required
2022: GitHub source code repos accessed via stolen employee tokens
2015: Compromised internal database, password hashes accessed

SOC2 Type II, ISO 27001, HIPAA BAA on Enterprise Grid. SAML SSO. Enterprise Key Management for customer-managed encryption keys. Audit logs API. Two notable breaches in history.

InngestBackground Jobs
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Event-driven function platform. Event payloads encrypted at rest. SSO on Pro+. Audit log on Pro. No HIPAA BAA. Function logs retained 7 days on standard plans.

DenoRuntime
B
- SOC2- HIPAA- GDPR+ Bug Bounty- Encrypt at Rest- SSO- Audit LogMFA: None

Open-source runtime with secure-by-default permissions model (--allow-net, --allow-read, etc.). Bug bounty via huntr. Significantly safer default than Node for untrusted code. Deno Deploy is separately certified.

SanityCMS
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. SAML SSO on Enterprise. Document-level access control via custom roles. Bug bounty via HackerOne. Content Lake encrypted at rest. EU data residency available.

TinybirdAnalytics
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Built on ClickHouse. Token-based auth with row-level security policies. SSO on Enterprise. EU and US data residency. No HIPAA BAA. Strong audit logging via Service Data Sources.

GroqAI API
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II achieved 2024. LPU inference with no training on paid API data. API key scoped per project. SSO on Enterprise. No HIPAA BAA. No bug bounty program.

ModalServerless GPU
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. gVisor container sandboxing. Secrets managed via cloud KMS. SSO on Team plan. Function logs accessible per-invocation. No HIPAA BAA. No bug bounty.

PlausibleAnalytics
B
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

EU-hosted (Hetzner). GDPR-compliant by design — no personal data collected. No cookies, no IP storage. No SOC2 (small company). Self-hosted option for maximum control.

BetterStackMonitoring
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. EU and US data residency. SSO on Team plan. Audit log for status page and alert changes. No HIPAA BAA. No bug bounty.

Hugging FaceAI Platform
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional
2024: Security team discovered unauthorized access to Spaces secrets; subset of Spaces tokens may have been exposed

SOC2 Type II. 2024 incident prompted rotation of user tokens and security improvements. Bug bounty available. Private model repos and inference endpoints available. No HIPAA BAA. SSO on Enterprise Hub.

AirbyteETL
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II (Airbyte Cloud). Open-source self-hosted option for full control. RBAC for workspace members. Secret management via AWS Secrets Manager on Cloud. No HIPAA BAA.

HasuraAPI
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II (Hasura Cloud). Row-level security via Hasura permissions inherited from PostgreSQL RLS. JWT and webhook auth modes. Audit log on Enterprise tier. No HIPAA BAA. Self-hosted option.

RetoolInternal Tools
B
+ SOC2+ HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required
2022: SMS phishing attack compromised 27 employees and allowed access to 27 customer accounts in cloud plan

SOC2 Type II, HIPAA BAA on Enterprise. 2022 phishing breach was via Okta; affected 27 customers. ISO 27001 certified. Self-hosted option for regulated industries. Bug bounty via HackerOne.

ContentfulCMS
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II, ISO 27001. SAML SSO on Team+. Audit log via Activities API. No HIPAA BAA. API key and OAuth token auth. Content delivery via CDN. No bug bounty.

SanityCMS
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. SAML SSO on Enterprise. Document-level access control. Bug bounty via HackerOne. Content Lake encrypted at rest. EU data residency available. No HIPAA BAA.

XataDatabase
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. PostgreSQL-based. Branch-per-environment model reduces blast radius. SSO on Business. No HIPAA BAA. API keys scoped per-database.

UnkeyAPI Security
B
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO+ Audit LogMFA: Optional

Open source API key management. Keys hashed at rest. Rate limiting built-in. Per-key usage audit logs. No SOC2 yet. Self-host for full control.

ArcjetApp Security
B
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO+ Audit LogMFA: None

Security SDK — rate limiting, bot detection, email validation in your app. Open source core. No SOC2. No data leaves your infra on self-host.

Stack AuthAuth
B
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Open source auth. Passwords bcrypt-hashed. OAuth and magic links. Self-host for data control. No SOC2 yet. SSO on paid plan.

HankoAuth
B
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Required

Passkey-first — WebAuthn by default eliminates password vulnerabilities. Open source. FIDO2 certified. Passkeys inherently phishing-resistant.

LangfuseAI/ML
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II (cloud). LLM traces encrypted at rest. Self-host — no prompts leave your infra. SSO on Teams. API key scoped per project.

CerebrasAI/ML
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Data not used for training. SSO on Enterprise. Wafer-scale chip — isolated compute per request.

ConvexBaaS
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Row-level access via functions. All queries server-side. SSO on Pro+. AES-256 at rest.

Better AuthAuth
B
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO- Audit LogMFA: Optional

Self-hosted auth library. Security depends on your deployment. Passwords bcrypt-hashed. MFA and SSO built-in. No cloud = no vendor breach risk. You own your security posture.

HonoFramework
B
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest- SSO- Audit LogMFA: None

Code library — security is your responsibility. Built-in CSRF protection, secure headers middleware. No data handling. Runs in V8 isolates on edge = sandboxed by default.

GroqAI API
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Data not used for training. Custom LPU hardware — isolated compute. SSO on Enterprise. API key rotation supported.

EncoreFramework
B
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO+ Audit LogMFA: Optional

Built-in structured auth middleware. Automatic TLS. Cloud offering has infrastructure-level security. Open source framework — audit the code. DPA available.

BiomeTooling
B
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest- SSO- Audit LogMFA: None

CLI tool — no network, no data storage, no attack surface. Runs locally. Rust memory safety. Supply chain risk minimal — single binary, no npm dependencies at runtime.

OpenTofuIaC
B
- SOC2- HIPAA- GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: None

CLI tool — state file encryption supported. Linux Foundation governance. State files may contain secrets — always encrypt at rest. Remote state backends inherit their provider's security posture.

TinybirdAnalytics
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. ClickHouse-based. Per-token API access scoping. SSO on Enterprise. EU data residency. Row-level security on published endpoints.

ResendEmail
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

SOC2 Type II achieved 2025. DKIM/SPF/DMARC support for email auth. API key scoped per domain. No SSO yet. Webhook signature verification.

MintlifyDocumentation
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional
2024: GitHub token exposure — customer repo tokens briefly accessible via Mintlify worker

SOC2 Type II. 2024 token exposure was disclosed and patched quickly. SSO on Enterprise. Content served via CDN with DDoS protection.

SanityCMS
B
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. SAML SSO on Enterprise. Content API with token-scoped access. Document-level permissions. EU data residency available.

NeonDatabase
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Serverless Postgres with IP allow-listing. Branch credentials isolated. Connection pooling via PgBouncer. No HIPAA BAA. Per-branch access control.

CerebrasAI/ML
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Wafer-scale chip provides hardware-level compute isolation. Data not used for training. SSO on Enterprise. API key management with rotation.

GroqAI/ML
B
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional

SOC2 Type II. Custom LPU hardware. Data not retained after response. SSO on Enterprise. Per-key rate limiting. No fine-tuning = no stored model data.

RailwayHosting
C
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

No SSO. No audit log. Good basics but missing enterprise features.

ResendEmail
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

Young company, no SOC2 yet. No SSO or audit log. DKIM/SPF support.

Fly.ioHosting
C
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

Docker-based security model. No SSO or audit log. Private networking via WireGuard. Smaller team = slower security patches.

TursoDatabase
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

Young company, no SOC2 yet. Edge SQLite via libSQL. No SSO or audit log. Data can be replicated globally — know where your data lives.

RenderHosting
C
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

SOC2 Type II achieved 2023. No SSO, no audit log, no bug bounty. Deploy previews inherit production env vars if misconfigured.

CoolifyHosting
C
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest- SSO- Audit LogMFA: Optional

Self-hosted platform — you own the infra and all compliance. No cloud certifications apply. Security is entirely your responsibility. SSH key management critical.

Trigger.devBackground Jobs
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

Open-source with self-hosted option. No SOC2 yet (early-stage). No SSO or audit log on cloud plan. Self-host for full control.

HetznerCloud
C
- SOC2- HIPAA+ GDPR- Bug Bounty- Encrypt at Rest- SSO- Audit LogMFA: Optional

German company with strict GDPR compliance. No SOC2 or HIPAA. No managed encryption at rest — bring your own. No SSO or audit log. Great value but security is DIY.

EdgeDBDatabase
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

Cloud service launched 2024. No SOC2 yet. Built on PostgreSQL so inherits some data-at-rest guarantees. Self-hosted option for compliance-sensitive workloads.

LoopsEmail
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

Early-stage email marketing platform. No SOC2 yet. No SSO or audit log. DKIM/SPF support. Basic API key auth — no scoped tokens.

Payload CMSCMS
C
- SOC2- HIPAA+ GDPR- Bug Bounty- Encrypt at Rest- SSO+ Audit LogMFA: None

Self-hosted headless CMS — security depends on your infrastructure. Payload Cloud is young with no SOC2 yet. Built-in access control with field-level permissions. Auth uses local strategy by default.

DirectusCMS
C
- SOC2- HIPAA+ GDPR- Bug Bounty- Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Self-hosted with full control. Directus Cloud has no SOC2. SSO via OAuth/SAML available. Granular role-based access control. Activity log for all data changes.

TigrisStorage
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

Globally distributed S3-compatible object storage. Young service — no SOC2 yet. Integrated with Fly.io. Data replicated to edge locations — understand data residency implications.

MinIOStorage
C
- SOC2- HIPAA- GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: None

Self-hosted S3-compatible storage — you own all compliance. SSE-S3 and SSE-KMS encryption. LDAP/AD/OIDC integration. Audit log with webhook targets. Security is entirely your responsibility.

TraefikProxy/Ingress
C
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest- SSO- Audit LogMFA: None

Self-hosted reverse proxy and ingress controller. Auto TLS via Let's Encrypt. Dashboard has basic auth — use middleware for proper auth. No built-in audit log. Traefik Enterprise adds SSO and RBAC.

CircleCICI/CD
C
+ SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional
2023: Secret exfiltration incident — customer secrets and tokens exposed via compromised engineer laptop

2023 breach was severe — required all customers to rotate secrets. SOC2 Type II. OIDC token auth for cloud providers reduces secret exposure. SSO on Scale plan.

ArgoCDCI/CD
C
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest+ SSO+ Audit LogMFA: None
2022: CVE-2022-24348 — path traversal vulnerability allowing access to other app Helm values

Self-hosted GitOps tool. SSO via Dex/OIDC. RBAC with project-level isolation. Audit log built-in. 2022 CVE was patched quickly. Secrets management requires external integration (Vault, Sealed Secrets).

RancherContainer Management
C
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Self-hosted Kubernetes management. SAML/OIDC SSO. RBAC with cluster/project/namespace scoping. Audit log for API calls. CIS benchmark scanning built-in. Security depends on your infrastructure.

PortainerContainer Management
C
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest+ SSO+ Audit LogMFA: Optional

Self-hosted Docker/K8s management UI. LDAP/OAuth SSO on Business Edition. RBAC with team-based access. Audit log on Business Edition. Runs with Docker socket access — high privilege surface.

ScalewayCloud
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO+ Audit LogMFA: Optional

French cloud provider with strong GDPR stance. ISO 27001 certified. No SOC2. No SSO — account-level auth only. Managed encryption via Secret Manager. Data sovereignty in EU.

OVHcloudCloud
C
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest+ SSO+ Audit LogMFA: Optional
2021: Strasbourg data center fire destroyed SBG2, damaged SBG1 — data loss for customers without offsite backups

SOC2 Type II, ISO 27001. 2021 fire was catastrophic for affected customers. IAM with SSO available. GDPR-compliant EU hosting. Backups must be configured to different DC explicitly.

AppwriteBaaS
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO+ Audit LogMFA: Optional

Open-source BaaS. Self-hosted option for full control. Cloud service has no SOC2 yet. API key and JWT auth. Built-in abuse protection and rate limiting. Activity log on all plans.

NhostBaaS
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

Open-source Firebase alternative built on Hasura + PostgreSQL. No SOC2 yet. No SSO or audit log on cloud. Self-hosted option available. Row-level security via Hasura permissions.

GhostCMS
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

Ghost(Pro) managed hosting. No SOC2. Self-hosted option for full control. Staff roles with limited permission model. No SSO on managed plan. API keys with content/admin separation.

FramerWebsite Builder
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

No SOC2 yet. No SSO or audit log. GDPR-compliant. Sites served via Cloudflare CDN for DDoS protection. Team permissions with editor/viewer roles. Growing platform with maturing security posture.

ReplicateAI API
C
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

SOC2 Type II. ML model hosting and inference. API token auth. No SSO or audit log on standard plans. Public model predictions are not private — use private deployments for sensitive data.

DiscordCommunications
C
- SOC2- HIPAA+ GDPR+ Bug Bounty+ Encrypt at Rest- SSO+ Audit LogMFA: Optional
2023: Customer support agent breach exposed support ticket data and email addresses

No SOC2. Bug bounty via HackerOne. 2FA available but not required. No SSO. Voice chat E2E encrypted via DAVE protocol since 2024. Not designed for enterprise/regulated workloads.

BunRuntime
C
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest- SSO- Audit LogMFA: None
2024: bun install --trust supply chain risk highlighted by community for postinstall scripts

Open-source runtime. Security depends on your application code and dependencies. Lockfile (bun.lock) ensures reproducible installs. Audit subcommand checks for known vulns. No managed cloud product as of 2026.

Mistral AIAI API
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

ISO 27001 certified. GDPR-compliant, EU-hosted. No SOC2 Type II yet as of 2026. No bug bounty. Free tier data used for training — use paid tier for any sensitive workloads.

Together AIAI API
C
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

SOC2 Type II. Hosts open source models. API key auth — no scoped permissions. No SSO or audit log on standard plans. No HIPAA BAA. No bug bounty program.

ReplicateAI API
C
+ SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

SOC2 Type II. ML model inference. Public model predictions are not private — use private Deployments for sensitive data. No SSO or audit log. No HIPAA BAA.

PaddlePayments
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO+ Audit LogMFA: Optional

PCI DSS Level 1 compliant (required as Merchant of Record). GDPR-compliant EU operations. No SOC2 Type II published. No bug bounty. Team logins have 2FA available. Fraud and dispute handling built-in.

ElectricSQLDatabase
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: None

Open source sync engine. Data synced to client — consider what you replicate. Shape-based sync rules control exposure. Self-host only.

TwentyCRM
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO+ Audit LogMFA: Optional

Open source CRM. Self-host for sensitive data. Docker Compose. No SOC2. PostgreSQL encryption. GraphQL API auth via API keys.

PolarPayments
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO+ Audit LogMFA: Optional

EU-based Merchant of Record. Open source — audit the code yourself. No SOC2 yet. PCI compliance handled via Stripe underneath. Webhook signature verification.

PGliteDatabase
C
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest- SSO- Audit LogMFA: None

Client-side Postgres in WASM. No server = no server breaches. Data stored in browser/Node.js. Security is your app's responsibility. No network attack surface.

DocmostDocumentation
C
- SOC2- HIPAA- GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

Self-hosted only. PostgreSQL backend with standard encryption. No cloud = you control everything. Basic auth built-in. No SSO, no audit log. Add reverse proxy with TLS.

ValkeyCache/Database
C
- SOC2- HIPAA- GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: None

Linux Foundation fork of Redis. Self-hosted. TLS support. ACL-based auth. No managed service certification (use your cloud provider's certs). Default config has no auth — always enable requirepass.

CoolifyHosting
C
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest- SSO- Audit LogMFA: Optional

Self-hosted PaaS. Security is entirely your responsibility. SSH key management critical. Dashboard has basic auth. No SOC2. Add Cloudflare Tunnel or VPN for production use.

TursoDatabase
C
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: Optional

No SOC2. GDPR compliant. Per-database auth tokens. Embedded replicas use local SQLite files — consider local storage security. Edge replication means data in multiple regions.

SurrealDBDatabase
D
- SOC2- HIPAA+ GDPR- Bug Bounty+ Encrypt at Rest- SSO- Audit LogMFA: None

Very young project. No SOC2, no SSO, no audit log. Self-hosted only for production-grade security. Cloud beta has minimal compliance posture.

PrometheusMonitoring
D
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest- SSO- Audit LogMFA: None

Self-hosted open-source metrics. No built-in auth or encryption — use reverse proxy with TLS. No audit log. Security depends entirely on your infrastructure and network policies.

JenkinsCI/CD
D
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest+ SSO+ Audit LogMFA: None

Self-hosted — all security is your responsibility. Plugin ecosystem is a major attack surface. LDAP/SAML SSO via plugins. Credentials stored encrypted but master key management is critical.

PocketBaseBaaS
D
- SOC2- HIPAA- GDPR- Bug Bounty- Encrypt at Rest- SSO+ Audit LogMFA: None

Self-hosted single-binary BaaS. SQLite-based. No built-in TLS — use reverse proxy. No encryption at rest. Admin UI with basic auth. Activity log built-in. Security entirely your responsibility.

Explore other areas