A-
Trust rating
Excellent · 92/100
Procurement snapshot
0 critical findings identified — these point to architectural gaps, not just configuration tweaks.
Strengths
DNS CAA Records
TLS Configuration
DMARC / Email Security
MX Records & Mail Provider
Estimated remediation effort: 1–2 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change
1 scan · Last scanned March 09, 2026
Your rating
Industry average
Score
100
75
50
25
0
A-
92/100
Compliance & Certifications
SOC 2 Type II
3rd party · AICPA
Pro subscribers only
ISO 27001
3rd party · accredited body
Pro subscribers only
GDPR
Self-reported
Pro subscribers only
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Pro subscribers only
Security Posture
4 items need attention
11 passed
Add missing cookie security settings
Cookie Security
This makes it meaningfully easier for an attacker to hijack authenticated customer sessions, increasing account-takeover risk. On bitbucket.org, most cookies are missing key protections: 2 cookie(s) can be sent over an unencrypted connection (missing the "Secure" flag); 3 cookie(s) can be read by page scripts, including malicious ones (missing "HttpOnly"); 3 cookie(s) don't restrict cross-site requests (missing "SameSite").
OWASP ASVS3.4
Session cookies use Secure, HttpOnly, and SameSite attributes
How to fix this
1Add Secure to every cookie your site sets — this is usually one line in your app's session/cookie config, not a DNS or hosting setting.
2Add HttpOnly to login/session cookies — same place as above, in your app's cookie settings.
3Add SameSite=Lax (or Strict for sensitive cookies) to every cookie.
4This needs a developer — it's a one-line change per cookie in your website's code, not something changeable from a hosting dashboard.
5Re-scan afterward to confirm all three flags are now set.
Report unlocked.
View all 11 passed checks
DNS CAA Records
TLS Configuration
DMARC / Email Security
MX Records & Mail Provider
HSTS Header
Known Breaches
security.txt (RFC 9116)
TLS Protocol Support
CVE Exposure
Certificate Hygiene
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Trust Center
trust.bitbucket.org ↗
Security page
bitbucket.org/security ↗
Privacy Policy
bitbucket.org/privacy ↗
DPA (Data Processing Agreement)
bitbucket.org/dpa ↗
Updated recently
Subprocessors List
bitbucket.org/policies/subprocessors ↗
Similar companies in B2B SaaS / Software
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Top AI vendors by trust score
94 companies · LynxRadar ranking
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking