Comparison Overview

VIPSHOP

VS

Zomato

VIPSHOP

8 MARINA BOULEVARD, MARINA BAY FINANCIAL CENTRE , Singapore, 018981, SG
Last Update: 2025-12-11
Between 750 and 799

VIPSHOP is the official South East Asia headquarters of VIP.com (唯品会) (https://ir.vip.com/), which was founded in 2008. It has been listed on New York Stock Exchange (NYSE) since 2012 and works with over 41,000 brands, offering a curated selection of products in fashion apparel, shoes & bags, cosmetics, mother & kids, home & living, and more. Since its listing, VIP.com (唯品会) has achieved profitability for 42 consecutive quarters and counting, with US$15 billion in total net revenue for 2022. It has received worldwide recognition on Fortune China 500, Dow Jones Sustainability Index (DJSI), Forbes China and more. VIPSHOP is the official South East Asia headquarters of VIP.com (唯品会). Established in 2022, it aims to bring 100% Authentic, high-quality products from premium brands to Southeast Asian consumers, at accessible prices. VIPSHOP strives to find the best deals and aims to connect the world’s top brands to make people feel their best.

NAICS: 513
NAICS Definition: Others
Employees: 78
Subsidiaries: 1
12-month incidents
0
Known data breaches
0
Attack type number
0

Zomato

Last Update: 2025-12-09
Between 800 and 849

Zomato’s mission statement is “better food for more people.” Since our inception in 2010, we have grown tremendously, both in scope and scale - and emerged as India’s most trusted brand during the pandemic, along with being one of the largest hyperlocal delivery networks in the country. Today, Zomato represents a wide range of cultures through its diversified 5000+ team members, 3.5 lakh+ delivery partners, and our biggest collective of the finest restaurant partners. We are grateful that our business is able to provide upward social and economic movement for millions of households – of our delivery partners, as well as restaurant staff. We think of all of us as one big family! Our passion is driven by purpose and we take immense pride in our initiative ‘Feeding India’, one of India’s largest not-for-profits working to ensure that nobody in India goes to bed hungry. As of now, Feeding India provides over 150,000 nutritious meals to the underprivileged every day. In April 2020, Feeding India ran one of the largest food distribution drives in the world during the first wave of COVID, and distributed 78 million meals to daily wagers across the length and breadth of the country. During the second wave of COVID-19, Feeding India was again the first to act. We were able to source over 9,000 oxygen concentrators and distributed them for free to government hospitals across the country. This helped save millions of lives during one of the worst humanitarian crises faced by India in the recent times. We’re innovating hard to make last-mile delivery carbon neutral, to eliminate the use of plastic packaging, create meaningful opportunities in the gig economy, and to feed our country’s ever-growing appetite for high-quality, affordable, and hygienic food, one delivery at a time!

NAICS: 513
NAICS Definition: Others
Employees: 14,195
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/vipshopofficial.jpeg
VIPSHOP
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/zomato.jpeg
Zomato
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
VIPSHOP
100%
Compliance Rate
0/4 Standards Verified
Zomato
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Technology, Information and Internet Industry Average (This Year)

No incidents recorded for VIPSHOP in 2025.

Incidents vs Technology, Information and Internet Industry Average (This Year)

No incidents recorded for Zomato in 2025.

Incident History — VIPSHOP (X = Date, Y = Severity)

VIPSHOP cyber incidents detection timeline including parent company and subsidiaries

Incident History — Zomato (X = Date, Y = Severity)

Zomato cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/vipshopofficial.jpeg
VIPSHOP
Incidents

No Incident

https://images.rankiteo.com/companyimages/zomato.jpeg
Zomato
Incidents

Date Detected: 05/2017
Type:Data Leak
Blog: Blog

FAQ

Zomato company demonstrates a stronger AI Cybersecurity Score compared to VIPSHOP company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Zomato company has historically faced a number of disclosed cyber incidents, whereas VIPSHOP company has not reported any.

In the current year, Zomato company and VIPSHOP company have not reported any cyber incidents.

Neither Zomato company nor VIPSHOP company has reported experiencing a ransomware attack publicly.

Neither Zomato company nor VIPSHOP company has reported experiencing a data breach publicly.

Neither Zomato company nor VIPSHOP company has reported experiencing targeted cyberattacks publicly.

Neither VIPSHOP company nor Zomato company has reported experiencing or disclosing vulnerabilities publicly.

Neither VIPSHOP nor Zomato holds any compliance certifications.

Neither company holds any compliance certifications.

VIPSHOP company has more subsidiaries worldwide compared to Zomato company.

Zomato company employs more people globally than VIPSHOP company, reflecting its scale as a Technology, Information and Internet.

Neither VIPSHOP nor Zomato holds SOC 2 Type 1 certification.

Neither VIPSHOP nor Zomato holds SOC 2 Type 2 certification.

Neither VIPSHOP nor Zomato holds ISO 27001 certification.

Neither VIPSHOP nor Zomato holds PCI DSS certification.

Neither VIPSHOP nor Zomato holds HIPAA certification.

Neither VIPSHOP nor Zomato holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

Risk Information
cvss3
Base: 8.1
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Risk Information
cvss3
Base: 2.9
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.10.2 is sufficient to fix this issue. You should upgrade the affected component. The vendor confirms that this is "[f]ixed in version 4.10.2". Furthermore, that "[b]ackports for older versions in process and will be out as soon as their respective CI pipelines complete."

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

Risk Information
cvss3
Base: 4.5
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Risk Information
cvss3
Base: 5.8
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N