VendorScore
Plain-language data-access scores from public trust docs — so you know before you sign the DPA. Strong SOC 2 ≠ “can’t read your content.”
Join the waitlistPublic documentation review only. Not a pen test. Not legal advice. PDF reports coming soon.
VendorScore scores SaaS on whether the vendor can read your data, from public trust docs.
Enterprise options on when they exist (CSE, E2EE, EKM, etc.). Higher = less inherent vendor read access.
| Vendor | Score | Verdict |
|---|---|---|
| Google Workspace | 82 | Yes by default; mostly no with CSE |
| Zoom | 75 | Yes by default; mostly no for E2EE meetings |
| Dropbox | 73 | Yes for normal files; mostly no for E2EE folders |
| Microsoft 365 | 69 | Yes (service can decrypt); DKE is the exception |
| Slack | 62 | Yes — EKM is custody/revoke, not ZK |
| Salesforce | 60 | Yes — Shield/BYOK ≠ can’t read |
| Notion | 51 | Yes — not E2EE; support access possible |
| HubSpot | 46 | Yes — CRM/AI processors see customer data |
Overall = equal-weight average of five dimensions (0–100).
PDF scorecards are not for sale yet. Join the waitlist — delivered by email when ready. No calls.
Coming soon
One scorecard: verdict, scores, evidence URLs, caveats. One revision in 7 days if a public source was missed.
Coming soon
Three PDFs plus a comparison table. For final vendor shortlists.
Coming soon · join waitlist
Full set of 8 PDFs plus a comparison summary table. Delivered by email — no calls.
Coming soon
Any named SaaS not in the catalog (5-day SLA when live). Quarterly refresh sold separately.
Click Join the waitlist to open a pre-filled email to vendorscore@proton.me (subject + body ready). Or write that address yourself. Checkout opens after autónomo go-live.
Yes, by design. Even with Slack EKM, Slack uses your keys to serve messages. EKM improves key custody and revoke, not zero-knowledge. VendorScore rates Slack 62/100 overall on Enterprise Grid/Enterprise+ with EKM, based on public trust docs.
VendorScore scores SaaS on whether the vendor can read your data, from public trust docs. Five equal-weight dimensions (0–100): key custody, plaintext access, encryption claims, subprocessors, and auditability.
No. VendorScore is a public documentation review only. It is not a pen test and not legal advice. Scores change when vendor trust pages change.
PDF scorecards are not for sale yet. Join the waitlist by emailing vendorscore@proton.me — reports will be delivered by email when ready. No calls.
No. Strong SOC 2 is about controls and auditability, not whether the vendor can decrypt or view your content. VendorScore separates those questions.