Comparison Overview

Upwork

VS

Databricks

Upwork

475 Brannan St, San Francisco, California, 94107, US
Last Update: 2025-12-09
Between 800 and 849

Upwork is the world’s work marketplace that connects businesses with independent talent from across the globe. We serve everyone from one-person startups to large, Fortune 100 enterprises with a powerful, trust-driven platform that enables companies and talent to work together in new ways that unlock their potential. Our talent community on Upwork encompasses more than 10,000 skills in categories including website & app development, creative & design, customer support, finance & accounting, consulting, and operations.

NAICS: 5112
NAICS Definition: Software Publishers
Employees: 144,138
Subsidiaries: 3
12-month incidents
0
Known data breaches
0
Attack type number
0

Databricks

160 Spear Street, San Francisco, CA, 94105, US
Last Update: 2025-12-09
Between 750 and 799

Databricks is the Data and AI company. More than 10,000 organizations worldwide — including Block, Comcast, Condé Nast, Rivian, Shell and over 60% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to take control of their data and put it to work with AI. Databricks is headquartered in San Francisco, with offices around the globe, and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow. --- Databricks applicants Please apply through our official Careers page at databricks.com/company/careers. All official communication from Databricks will come from email addresses ending with @databricks.com or @goodtime.io (our meeting tool).

NAICS: 5112
NAICS Definition: Software Publishers
Employees: 10,527
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/upwork.jpeg
Upwork
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/databricks.jpeg
Databricks
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Upwork
100%
Compliance Rate
0/4 Standards Verified
Databricks
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Software Development Industry Average (This Year)

No incidents recorded for Upwork in 2025.

Incidents vs Software Development Industry Average (This Year)

No incidents recorded for Databricks in 2025.

Incident History — Upwork (X = Date, Y = Severity)

Upwork cyber incidents detection timeline including parent company and subsidiaries

Incident History — Databricks (X = Date, Y = Severity)

Databricks cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/upwork.jpeg
Upwork
Incidents

No Incident

https://images.rankiteo.com/companyimages/databricks.jpeg
Databricks
Incidents

No Incident

FAQ

Upwork company demonstrates a stronger AI Cybersecurity Score compared to Databricks company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, Databricks company has disclosed a higher number of cyber incidents compared to Upwork company.

In the current year, Databricks company and Upwork company have not reported any cyber incidents.

Neither Databricks company nor Upwork company has reported experiencing a ransomware attack publicly.

Neither Databricks company nor Upwork company has reported experiencing a data breach publicly.

Neither Databricks company nor Upwork company has reported experiencing targeted cyberattacks publicly.

Neither Upwork company nor Databricks company has reported experiencing or disclosing vulnerabilities publicly.

Neither Upwork nor Databricks holds any compliance certifications.

Neither company holds any compliance certifications.

Upwork company has more subsidiaries worldwide compared to Databricks company.

Upwork company employs more people globally than Databricks company, reflecting its scale as a Software Development.

Neither Upwork nor Databricks holds SOC 2 Type 1 certification.

Neither Upwork nor Databricks holds SOC 2 Type 2 certification.

Neither Upwork nor Databricks holds ISO 27001 certification.

Neither Upwork nor Databricks holds PCI DSS certification.

Neither Upwork nor Databricks holds HIPAA certification.

Neither Upwork nor Databricks holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

Risk Information
cvss3
Base: 8.1
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Risk Information
cvss3
Base: 2.9
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.10.2 is sufficient to fix this issue. You should upgrade the affected component. The vendor confirms that this is "[f]ixed in version 4.10.2". Furthermore, that "[b]ackports for older versions in process and will be out as soon as their respective CI pipelines complete."

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

Risk Information
cvss3
Base: 4.5
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Risk Information
cvss3
Base: 5.8
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N