Comparison Overview

Elastic

VS

PageUp

Elastic

88 Kearny St, San Francisco, California, US, 94108
Last Update: 2026-03-29
Between 650 and 699

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale. Elastic’s solutions for search, observability, and security are built on the Elastic Search AI Platform — the development platform used by thousands of companies, including more than 50% of the Fortune 500.

NAICS: 5112
NAICS Definition: Software Publishers
Employees: 4,829
Subsidiaries: 0
12-month incidents
0
Known data breaches
1
Attack type number
2

PageUp

447 Collins St, Melbourne, 3000, AU
Last Update: 2026-03-31
Between 700 and 749

PageUp is a powerful talent management platform with unique capabilities to transform hiring and engagement experiences for all. It’s the experience-driven technology you’ve been dreaming of. Unlike other SaaS talent acquisition or management providers, PageUp offers a full suite of modern tools to help businesses attract, engage, and retain high performing teams and deliver measurable results. PageUp provides exceptional hiring and engagement experiences with Recruitment Marketing (sophisticated content management, marketing automation and candidate relationship management), Recruitment Management, Onboarding, Learning, Performance, and Succession tools. Customers love PageUp for its deep functionality, world-class support and ability to be configured for a range of workflows and industries. Used in over 190 countries, PageUp is a truly global solution. Our teams are located across multiple locations in Melbourne & Sydney, the Philippines, the United States, London, Paris & Dublin.

NAICS: 5112
NAICS Definition: Software Publishers
Employees: 331
Subsidiaries: 4
12-month incidents
0
Known data breaches
1
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/elastic-co.jpeg
Elastic
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/pageup.jpeg
PageUp
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Elastic
100%
Compliance Rate
0/4 Standards Verified
PageUp
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Software Development Industry Average (This Year)

No incidents recorded for Elastic in 2026.

Incidents vs Software Development Industry Average (This Year)

No incidents recorded for PageUp in 2026.

Incident History — Elastic (X = Date, Y = Severity)

Elastic cyber incidents detection timeline including parent company and subsidiaries

Incident History — PageUp (X = Date, Y = Severity)

PageUp cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/elastic-co.jpeg
Elastic
Incidents

Date Detected: 6/2025
Type:Vulnerability
Attack Vector: Local/Remote Code Execution via Custom Loader, Kernel Driver Manipulation, NULL Pointer Dereference Exploit (CWE-476)
Blog: Blog

Date Detected: 3/2025
Type:Vulnerability
Attack Vector: Arbitrary Code Execution
Blog: Blog

Date Detected: 1/2025
Type:Breach
Attack Vector: Unsecured Database (Elasticsearch cluster)
Motivation: Likely deliberate (data aggregation for malicious use)
Blog: Blog
https://images.rankiteo.com/companyimages/pageup.jpeg
PageUp
Incidents

Date Detected: 06/2018
Type:Breach
Attack Vector: Malware
Blog: Blog

FAQ

PageUp company demonstrates a stronger AI Cybersecurity Score compared to Elastic company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Elastic company has faced a higher number of disclosed cyber incidents historically compared to PageUp company.

In the current year, PageUp company and Elastic company have not reported any cyber incidents.

Neither PageUp company nor Elastic company has reported experiencing a ransomware attack publicly.

Both PageUp company and Elastic company have disclosed experiencing at least one data breach.

Neither PageUp company nor Elastic company has reported experiencing targeted cyberattacks publicly.

Elastic company has disclosed at least one vulnerability, while PageUp company has not reported such incidents publicly.

Neither Elastic nor PageUp holds any compliance certifications.

Neither company holds any compliance certifications.

PageUp company has more subsidiaries worldwide compared to Elastic company.

Elastic company employs more people globally than PageUp company, reflecting its scale as a Software Development.

Neither Elastic nor PageUp holds SOC 2 Type 1 certification.

Neither Elastic nor PageUp holds SOC 2 Type 2 certification.

Neither Elastic nor PageUp holds ISO 27001 certification.

Neither Elastic nor PageUp holds PCI DSS certification.

Neither Elastic nor PageUp holds HIPAA certification.

Neither Elastic nor PageUp holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.

Description

XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services

Description

Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.

Description

A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.