How FES scores work
FESIT scores are a shared checklist for European NGOs and public-interest organisations. They help structure a conversation about tools — they are not a product ranking or a seal of approval.
What Fair, Easy and Secure mean
-
Fair
No vendor lock-in, open standards, and European sovereignty over where data and decisions live.
-
Easy
Tools people can use and operate without a dedicated IT department, and that connect to the rest of the stack.
-
Secure
Sound IT security, safer defaults for users, and a clear story for personal data — including GDPR and exposure under laws such as the US Cloud Act.
Scores are indicative
Every score is guidance for discussion, not legal advice, not a security audit, not a DPIA, and not certification that a tool is “GDPR compliant” or “approved for government use”. Labels such as Illustrative vs Reviewed show how far a dossier has been curated — not that the tool has been formally verified in your organisation’s context.
Always check contracts, DPAs, subprocessors, residency options and security claims with people who know your risk profile.
We rely on public information
Evidence on dossiers is drawn from information that is publicly available: vendor websites, documentation, licence texts, privacy pages and similar sources. Where we can, we keep a source URL next to the score so you can follow the same trail.
Some Fair criteria can also be proposed from catalog facts we already store (for example hosting mode, whether the vendor is marked as an EU legal entity, or whether the licence looks open-source). Those rule-based proposals still need human judgement when the facts are incomplete or contradictory.
We do not test the software ourselves
FESIT does not install, penetration-test, or operationally evaluate products in a lab. We do not claim to have used every tool end-to-end. Scores reflect how public claims and dossier facts map onto the FES rubric — not a hands-on quality or security assessment.
How a score is built
- Scores sit on an offering (a specific hosting mode), not only on the brand name.
- Each criterion uses a 1–5 scale against a published rubric (stronger evidence for higher scores).
- Weak or missing evidence should stay empty or marked draft rather than inflated.
- Curators may accept proposals, adjust evidence, or leave gaps visible on purpose.