Is Penpot Safe?
Penpot — Nerq Trust Score 48.2/100 (D grade). Based on analysis of 2 trust dimensions, it is has notable safety concerns. Last updated: 2026-05-13.
Exercise caution with Penpot. Penpot is a SaaS platform with a Nerq Trust Score of 48.2/100 (D), based on 3 independent data dimensions. Below the recommended threshold of 70. Security: 90/100. Popularity: 0/100. Data sourced from company registration, SOC 2/ISO 27001 certifications, privacy policy analysis, and app store metadata. Last updated: 2026-04-12. Machine-readable data (JSON).
Is Penpot safe?
NO — USE WITH CAUTION — Penpot has a Nerq Trust Score of 48.2/100 (D). It has below-average trust signals with significant gaps in security, maintenance, or documentation. Not recommended for production use without thorough manual review and additional security measures.
What is Penpot's trust score?
Penpot has a Nerq Trust Score of 48.2/100, earning a D grade. This score is based on 2 independently measured dimensions including security, maintenance, and community adoption.
What are the key security findings for Penpot?
Penpot's strongest signal is security at 90/100. No known vulnerabilities have been detected. It has not yet reached the Nerq Verified threshold of 70+.
What is Penpot and who maintains it?
| Author | Unknown |
| Category | SaaS |
| Source | N/A |
SaaS Assessment
Open Source
Penpot is open source with 45,018 GitHub stars.
Similar Saas by Trust Score
Safety Guide: Penpot
What is Penpot?
Penpot is a SaaS platform — Open-source design and prototyping platform. Backed by Kaleidos, fully web-based..
How to Verify Safety
Check SOC 2 compliance. Review data handling and incident history.
You can also check the trust score via API: GET /v1/preflight?target=Penpot
Key Safety Concerns for SaaS platform
When evaluating any SaaS platform, watch for: data security, compliance certifications, incident history.
Trust Assessment
Penpot has a Nerq Trust Score of 48/100 (D) and has not yet reached Nerq trust threshold (70+). This score is based on automated analysis of security, maintenance, community, and quality signals.
Key Takeaways
- Penpot has a Trust Score of 48/100 (D).
- Review carefully before use — below trust threshold.
- Always verify independently using the Nerq API.
Detailed Score Analysis
| Dimension | Score |
|---|---|
| Security | 90/100 |
| Maintenance | 50/100 |
| Popularity | 0/100 |
| Quality | 40/100 |
| Community | 35/100 |
Based on 5 dimensions. Data from company registration, SOC 2/ISO 27001 certifications, privacy policy analysis, and app store metadata.
What data does Penpot collect?
Penpot is a SaaS platform. Open-source design and prototyping platform. Backed by Kaleidos, fully web-based.
Privacy score: 46/100. As a SaaS platform, Penpot processes user data in the cloud. Review the privacy policy for details on data retention, third-party sharing, and data processing locations.
For business use, request a Data Processing Agreement (DPA) and verify GDPR compliance before uploading sensitive data.
Full analysis: Penpot Privacy Report · Privacy review
Is Penpot secure?
Security score: 90/100. Open-source design and prototyping platform. Backed by Kaleidos, fully web-based.
Check Penpot's security page for certifications such as SOC 2 Type II, ISO 27001, or GDPR compliance documentation. These certifications indicate that the vendor follows established security practices and undergoes regular audits.
For enterprise deployments, verify SSO/SAML support, role-based access control, and audit logging capabilities.
Full analysis: Penpot Security Report
How we calculated this score
Penpot's trust score of 48.2/100 (D) is computed from company registration, SOC 2/ISO 27001 certifications, privacy policy analysis, and app store metadata. The score reflects 5 independent dimensions: security (90/100), maintenance (50/100), popularity (0/100), quality (40/100), community (35/100). Each dimension is weighted equally to produce the composite trust score.
Nerq analyzes over 7.5 million entities across 26 registries using the same methodology, enabling direct cross-entity comparison. Scores are updated continuously as new data becomes available.
This page was last reviewed on May 13, 2026. Data version: 1.0.
Full methodology documentation · Machine-readable data (JSON API)
Frequently Asked Questions
Is Penpot Safe?
What is Penpot's trust score?
What are safer alternatives to Penpot?
Is Penpot GDPR compliant?
Does Penpot sell my data?
Popular in SaaS
Browse Categories
See Also
Disclaimer: Nerq trust scores are automated assessments based on publicly available signals. They are not endorsements or guarantees. Always conduct your own due diligence.