SaaSFort
Public signal leaderboard

SaaS Security Leaderboard

Which SaaS platforms pass NIS2 Article 21 external checks? Public grades for 68 well-known domains: HTTP security headers, DMARC, DNSSEC. Measured from outside, no authentication. Embed the badge on your own site.

Domain Grade
Airtable (airtable.com) A
Mixpanel (mixpanel.com) A
Auth0 (auth0.com) A
Vercel (vercel.com) A
Drata (drata.com) A
Resend (resend.com) A
Stripe (stripe.com) B
GitHub (github.com) B
SendGrid (sendgrid.com) B
Linear (linear.app) B
Webflow (webflow.com) B
Sentry (sentry.io) B
Asana (asana.com) B
Miro (miro.com) B
1Password (1password.com) B
ClickUp (clickup.com) B
Snyk (snyk.io) B
Stytch (stytch.com) B
Slack (slack.com) C
Wise (wise.com) C
Loom (loom.com) C
Vanta (vanta.com) C
Amplitude (amplitude.com) D
Pipedrive (pipedrive.com) D
Atlassian (atlassian.com) D
Figma (figma.com) D
Revolut (revolut.com) D
Calendly (calendly.com) D
Mailchimp (mailchimp.com) D
PostHog (posthog.com) D
Notion (notion.so) F
HubSpot (hubspot.com) F
Salesforce (salesforce.com) F
Monday.com (monday.com) F
Brevo (brevo.com) F
ActiveCampaign (activecampaign.com) F
PagerDuty (pagerduty.com) F
Cloudflare (cloudflare.com) F
Dropbox (dropbox.com) F
Netlify (netlify.com) F
Fastly (fastly.com) F
Paddle (paddle.com) F
BambooHR (bamboohr.com) F
Basecamp (basecamp.com) F
Supabase (supabase.com) F
DocuSign (docusign.com) F
Contentful (contentful.com) F
Shopify (shopify.com) F
Intercom (intercom.io) F
Zendesk (zendesk.com) F
Freshworks (freshworks.com) F
Okta (okta.com) F
Xero (xero.com) F
Datadog (datadog.com) F
Workday (workday.com) F
Box (box.com) F
Twilio (twilio.com) F
Zoom (zoom.us) F
Personio (personio.de) F
Typeform (typeform.com) F
Canva (canva.com) F
Hotjar (hotjar.com) F
Segment (segment.com) F
Klaviyo (klaviyo.com) F
Copper (copper.com) F
Chargebee (chargebee.com) F
Wistia (wistia.com) F
Plausible (plausible.io) F

About these snapshots

Each page shows 7 publicly-observable signals: HTTP security headers (HSTS, X-Content-Type-Options, X-Frame-Options, CSP, Referrer-Policy), DMARC DNS TXT policy, and DNSSEC. This is what an external observer can measure from outside without authentication. A full NIS2 Article 21 assessment covers far more. Scan your own domain at saasfort.com/scan for the complete 60-check picture.

Check your own domain with 60 checks, not 7

The free scan runs 60 OWASP and NIS2 checks in under 60 seconds. The €39 audit pack adds the dated PDF your auditor or enterprise buyer asks for. No account, no subscription.

Also see: security scan use cases, NIS2 evidence guides, 30-day NIS2 audit checklist, NIS2 checklist for German SMBs, BSI notice response guide.