New fields added:
Contradictory Logging Policies - This field indicates a company who advertises a zero logs or absolutely no logs policy in their marketing, but upon further inspection do keep logs to some extent. This does NOT mean that the company in question has provided details about their logging policy in their terms or privacy policies, only that they have not claimed “no logging”, then immediately disproved it.
Falsely Claims Service is 100% Effective - No security or privacy setup truly offers 100% protection or is a bulletproof solution. When a company uses hyperbole or otherwise claims 100% effectiveness for anonymity, privacy, security, or generally gives this impression - it misleads potential customers that don’t know better and can harm the user who expects it to be true.
Offers PPTP and / or IPSec - The PPTP protocol is widely known to be insecure. The IPSec protocol has also come under scrutiny for being potentially insecure against state-level actors. Companies that allow their users to connect to their service using these protocols are potentially acting irresponsibly - even if they warn them first that they might be insecure.
Weakest/Strongest Data/Handshake Encryption - Companies that allow their users to connect to their service using obsolete encryption standards are potentially acting irresponsibly - even if they warn them first that they might be insecure.
# of Persistent Cookies set by Website/# of External Trackers on Website - Using webcookies.org - persistent cookies
Server SSL Rating - Run using Qualys SSL Labs - SSL Server Test Tool
SSL Certificate held by - Some sites SSL certificates are held by Cloudflare or other services. Some… (and these are PRIVACY/SECURITY companies mind you) don’t have a cert at all.
TL;DR - I got sick of seeing privacy/security companies sell services that are riddled with problems and decided to shine the spotlight on them to warn others and put pressure on them to change the better.