Skip to main content

Is osano.com a Scam? Security Check Results - Osano Reviews

osano.com favicon

Is osano.com Safe? Security Analysis for Osano

Check if osano.com is a scam or legitimate. Free security scan and reviews.

TechnologyN/amedium
HubSpot CMSSwiper.jsOsano Consent ManagerGoogle Tag Manager (gtag)HubSpot Feedback+1 more
Analyzed 9/4/2025Completed 11:28:50 AM
79
Security Score
LOW RISK

AI Summary

Osano is a technology company specializing in data privacy compliance solutions, offering a comprehensive SaaS platform that simplifies global privacy law adherence such as GDPR, CCPA, and CPRA. The company positions itself as a market leader with a unique $500,000 guarantee against fines and penalties, targeting organizations seeking to manage consent, privacy requests, and vendor risk efficiently. Their platform includes modules for cookie consent, subject rights management, privacy assessments, data mapping, and unified consent management. Technically, the website is built on HubSpot CMS and integrates modern JavaScript libraries like Swiper.js and Osano's own consent manager. The site is well-optimized for mobile and accessibility, with strong SEO practices and a professional design. Security-wise, the site enforces HTTPS, implements a robust Content Security Policy, and includes a cookie consent mechanism, but lacks explicit published security policies or incident response details. WHOIS data is unavailable, which slightly impacts trustworthiness, but the overall digital presence and trust signals indicate a legitimate and mature business. Recommendations include publishing security policies, vulnerability disclosure, and improving WHOIS transparency.

Detected Technologies

HubSpot CMSSwiper.jsOsano Consent ManagerGoogle Tag Manager (gtag)HubSpot FeedbackHubSpot Conversations

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

Osano operates in the privacy compliance technology sector, serving a broad range of organizations from startups to enterprises. Their business model is SaaS-based, generating revenue through subscription plans for privacy management tools. The company leverages partnerships and integrations to enhance its platform capabilities. Market positioning is strong, supported by customer testimonials, industry reviews, and a guarantee that differentiates them from competitors. The company targets privacy professionals, legal teams, and non-experts needing compliance solutions. Growth indicators include a large volume of processed consents and a comprehensive resource library. The ecosystem includes developer documentation, customer support, and a swag store, indicating a well-rounded brand engagement strategy.

Security Posture Analysis

Comprehensive Security Assessment

The website demonstrates a solid security posture with HTTPS enforcement and modern security headers like Content-Security-Policy and Referrer-Policy. The presence of a cookie consent banner aligns with privacy compliance best practices. However, the absence of a public security policy, incident response plan, or vulnerability disclosure reduces transparency and preparedness perception. No direct security contact emails or security.txt file were found, which could hinder incident reporting. No vulnerabilities or exposed sensitive data were detected in the analysis. Overall, the security maturity is good but could be enhanced by publishing formal security documentation and improving DNSSEC deployment.

Strategic Recommendations

Priority Actions for Security Improvement

1

Publish a dedicated security policy and incident response plan on the website.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

Osano

Description:

Osano simplifies global privacy compliance (GDPR, CPRA, and more) by helping organizations build, manage, and scale their privacy program.

Key Services:
Cookie Consent ManagementSubject Rights ManagementPrivacy AssessmentsUnified Consent & Preference HubData MappingVendor Privacy Risk Management
Content Quality:

excellent

Branding:

consistent

Technical Stack

Technologies:
HubSpot CMSSwiper.jsOsano Consent ManagerGoogle Tag Manager (gtag)HubSpot FeedbackHubSpot Conversations
Platforms:
HubSpot
Performance:

moderate

Mobile:

good

Accessibility:

good

SEO:

good

Security Assessment

Security Score:
85/100
Best Practices:
  • HTTPS enforced
  • Content Security Policy implemented
  • Cookie consent mechanism present
  • No exposed sensitive data detected

Analytics & Tracking

Services:
Google Analytics (gtag)HubSpot Analytics
Tracking Level:moderate
Privacy Compliance:good

Advertising & Marketing

Tracking Pixels:
HubSpot AnalyticsOsano Consent Manager
Marketing Tools:
HubSpotOsano CMP
Transparency Level:good

Website Quality Assessment

Design Quality:excellent
User Experience:excellent
Content Relevance:excellent
Navigation Clarity:excellent
Professionalism:excellent
Trustworthiness:high

Key Observations

1

Website is fully accessible with rich content and navigation.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

55/100
Score

Missing X-Frame-Options header

HIGH

Prevents clickjacking attacks

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing X-XSS-Protection header

MEDIUM

Legacy XSS protection (deprecated but still recommended)

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

95/100
Score

No Data Protection Officer mentioned

LOW

Large organizations may need to designate a DPO under GDPR

GDPR Compliance Analysis

Privacy Policy85% confidence
Cookie Policy85% confidence
Contact Information Found90% confidence
phone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

47/100
Score

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

95/100
Score

Complex SPF record

LOW

Too many include statements can cause lookup limits

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
SPF Details
Record:
v=spf1 include:4785246.spf10.hubspotemail.net include:amazonses.com include:mail.zendesk.com include:ba89d1.workshop-spf.net include:spf.protection.outlook.com -all
DNS Lookups:5/10
Policy:-all
DKIM Selectors Found
Selector:selector1(1296-bit rsa)
DMARC Details
Policy:reject
Aggregate Reports:ipm1atz@ar.glockapps.com
Forensic Reports:ipm1atz@fr.glockapps.com
MTA-STS Details
Mode:enforce
Max Age:7 days

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

75/100
Score

SSL Certificate Expires Within 90 Days

MEDIUM

SSL certificate expires in 85 days

Weak SSL Key Length

HIGH

SSL certificate uses 256-bit key, which is considered weak

Partial SSL/TLS Assessment

LOW

Completed 2 of 4 security checks due to time constraints

Certificate Details

Subject:www.osano.com
Issuer:WE1
Valid Until:11/28/2025 (85 days)
SANs:www.osano.com

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

85/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

Domain Registration Details

Domain Age
25 years(mature)
Expiry Risk
medium(42 days)
Protection Level
strongDNSSEC OFF

DNS Records

A Records:199.60.103.47
Name Servers:
ns-1530.awsdns-63.org
ns-1770.awsdns-29.co.uk
ns-353.awsdns-44.com
ns-950.awsdns-54.net
MX Records:
0: osano-com.mail.protection.outlook.com
SOA:Serial: 1, TTL: 86400s

DNSSEC Status

DNSSEC Not Enabled

DNS Performance

Resolution Time:28ms

SPF Analysis

SPF Record:
v=spf1 include:4785246.spf10.hubspotemail.net include:amazonses.com include:mail.zendesk.com include:ba89d1.workshop-spf.net include:spf.protection.outlook.com -all

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website is built on the HubSpot CMS platform, utilizing modern JavaScript libraries such as Swiper.js for UI components and Osano's own consent management scripts. The site uses Google Analytics via gtag for analytics and HubSpot's feedback and conversation widgets for user engagement. The technical implementation includes a strict Content Security Policy and referrer policies enhancing security. Performance is moderate with good mobile optimization and accessibility features. SEO is well addressed with proper meta tags, Open Graph, and JSON-LD structured data. No major technical debt or deprecated technologies were detected. Hosting provider details are not explicitly found but likely HubSpot's infrastructure. Overall, the technical infrastructure is modern and well maintained.
Analyze Another Website