{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "codat",
    "name": "Codat",
    "vendor": "Codat Limited",
    "vendorUrl": "https://codat.io",
    "kind": "http-api",
    "category": "accounting",
    "summary": "Codat connects a business's accounting, banking and commerce software to financial products and banks through one REST API. Product APIs cover bill pay, expenses, bank feeds and lending data, with official SDKs for TypeScript, Python and C#.",
    "url": "https://www.anchorterminal.com/tools/codat",
    "markdownUrl": "https://www.anchorterminal.com/tools/codat.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/codat.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/codat.json",
    "repo": "https://github.com/codatio/oas",
    "license": "Proprietary service under Codat's Master Services Agreement. The documentation repository codatio/codat-docs is Apache-2.0",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.codat.io",
    "packages": [
      {
        "registry": "npm",
        "name": "@codat/platform"
      },
      {
        "registry": "pypi",
        "name": "codat-platform"
      }
    ],
    "auth": "api-key",
    "authNotes": "An API key, Base64 encoded, in an `Authorization: Basic` header on every call to https://api.codat.io. An account comes through Codat's sales team. The docs say to get in touch to create one, and no self-serve signup was found. A client can hold up to 10 named keys, created and deleted in the Portal by Administrator or Developer users or through the /apiKeys endpoints. Keys have no scopes, so each one reaches every company the client has connected. End customers authorise their accounting package through Codat's Link flow.",
    "pricing": "paid",
    "pricingNotes": "No public price. codat.io/pricing returns 404 and the site's buttons ask for a meeting. The standard MSA sets a platform fee invoiced in advance and a unit fee per active company per month, both in an order form. The docs describe a free trial limited to 50 companies, no hourly syncs and 365 days, and a Codat Sandbox integration that is excluded from billing, but an account starts with a request to Codat (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs repository, the OpenAPI specs or the site (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 2690,
      "pypiWeekly": 222,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.codat.io/using-the-api/overview",
    "openapi": "https://raw.githubusercontent.com/codatio/oas/main/json/Codat-Platform.json",
    "capabilities": [
      "accounting.unified",
      "accounting.bills",
      "accounting.reports",
      "accounting.ledger",
      "accounting.invoices"
    ],
    "tags": [
      "hosted",
      "paid",
      "sales-led",
      "api-key",
      "openapi",
      "webhooks",
      "async-jobs",
      "idempotency",
      "sandbox",
      "typescript",
      "python",
      "csharp",
      "status-page",
      "soc2",
      "iso27001",
      "closed-source"
    ],
    "lastRelease": "2026-10-01",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 64.3,
      "grade": "B",
      "agentReady": false,
      "rank": 257,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 81,
        "maintenance": 75,
        "payments": 10,
        "reliability": 80,
        "schema": 77,
        "security": 49,
        "transparency": 71
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 80,
          "points": 16,
          "reason": "Graded on the hosted REST API at api.codat.io. Statuspage at status.codat.io with components per product and per integration (20). In the 90 days to 8 October 2026 the page shows two complete outages of the API and Portal, 14 minutes on 24 July and 12 minutes of errors on 27 July, intermittent Xero failures from 22 to 29 July, and errors on some integrations and sync services for about two hours on 24 August. No single outage of the core API reached an hour, so we scored it as one major (10). Limits published with numbers, 1,000 requests a day times one plus the active connected companies, 10 concurrent per company and 1,000 a minute per IP (15). 429 with Retry-After and X-Rate-Limit headers, and an Idempotency-Key header on POST and PATCH (15). The standard MSA pays service credits below 99 per cent monthly uptime (10). Generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 77,
          "points": 12.51,
          "reason": "Public OpenAPI 3 specs for every API in codatio/oas, in JSON and YAML (25). docs.codat.io/llms.txt returns 404. The docs source is Markdown in a public repository, which is not the same as serving it to agents (0). Operation descriptions are long and state prerequisites, useful queries and traps, for example that data must be refreshed before a list call (16). Typed schemas with enums, but filters go through a free-text `query` string and the required fields of a write differ by accounting package and have to be fetched from an options endpoint (11). Response examples per integration on most operations and a documented status code table with sample error bodies (13). Dated changelog at docs.codat.io/updates and a change policy. The API has no version in the path or a header (12)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 81,
          "points": 13.16,
          "reason": "`pageSize` from 1 to 5,000 with a default of 100, and a `query` filter that cuts results. No field selection found (15). Page and pageSize paging with `_links`, a query language, `orderBy` and modifiedDate filters. Bill Pay uses continuation tokens (20). Errors carry statusCode, service, error, correlationId, canBeRetried and detailedErrorCode with a validation object, though the error text is a string an agent has to read (17). Idempotency-Key on POST and PATCH with a 90-minute cache and documented behaviour after a 429. PUT and DELETE are outside the documented scheme (18). Maintained SDKs for TypeScript, Python and C#, one package per product. Writes need a model lookup per integration and most complete asynchronously (11)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 49,
          "points": 8.57,
          "reason": "Plain API keys in a Basic header, up to 10 per client, named, revocable in the Portal or through the API. No scopes and no documented expiry (20). No read-only key and no confirmation step for writes or deletes. Portal users have roles, and only Administrator and Developer roles see keys (4). The API returns ledger text written by third parties, such as invoice descriptions and supplier names, and no injection guidance was found (3). Read and write history per company and data type in the Portal and through the data history and push endpoints. No log of calls per API key was found (7). Annual SOC 2 Type II and ISO 27001 audits, a yearly penetration test, a private bug bounty and a disclosure form on codat.io/security. No security.txt. The trust centre page did not render for us (15)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 10,
          "points": 1.25,
          "reason": "No x402, MPP or L402 (0). No price is published. The pricing page returns 404 and the MSA leaves the platform fee and the per-company unit fee to an order form (0). The docs describe a free trial of up to 50 companies for 365 days and a sandbox excluded from billing, but the docs say to get in touch to create an account, so half credit (10). Access starts with a person contacting Codat (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "reason": "Latest changelog entry on 1 October 2026 (30). Seven dated entries since 3 August 2026 (20). A dated changelog, a Zendesk help centre and a support address. No public issue tracker for the service was reviewed (10). TypeScript, Python and C# SDKs were last published between April and June 2026. The Java and Go SDKs were archived in April and May 2026 with a month's notice (10). The specs repository runs lint in CI and was last changed on 4 August 2026 (5)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 71,
          "points": 6.21,
          "note": "editorial 59, provenance 82",
          "reason": "Closed service with a published Master Services Agreement, versioned and dated, naming Codat Limited and its company number (15). The MSA has a data processing schedule and deletes company data five business days after termination. The privacy notice of April 2025 is written mainly for website visitors and gives general retention wording, with six years for customer records (16). A change policy with at least three months' notice of breaking changes, a deprecation calendar, quarterly emails, defined lifecycle states and dated notices (20). The privacy notice names Microsoft Azure in the UK as a sub-processor and the MSA promises 10 days' notice of changes. No fuller list or choice of data location was found (8)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`pageSize` from 1 to 5,000 with a default of 100, and a `query` filter that cuts results. No field selection found (15). Page and pageSize paging with `_links`, a query language, `orderBy` and modifiedDate filters. Bill Pay uses continuation tokens (20). Errors carry statusCode, service, error, correlationId, canBeRetried and detailedErrorCode with a validation object, though the error text is a string an agent has to read (17). Idempotency-Key on POST and PATCH with a 90-minute cache and documented behaviour after a 429. PUT and DELETE are outside the documented scheme (18). Maintained SDKs for TypeScript, Python and C#, one package per product. Writes need a model lookup per integration and most complete asynchronously (11).",
          "maintenance": "Latest changelog entry on 1 October 2026 (30). Seven dated entries since 3 August 2026 (20). A dated changelog, a Zendesk help centre and a support address. No public issue tracker for the service was reviewed (10). TypeScript, Python and C# SDKs were last published between April and June 2026. The Java and Go SDKs were archived in April and May 2026 with a month's notice (10). The specs repository runs lint in CI and was last changed on 4 August 2026 (5).",
          "payments": "No x402, MPP or L402 (0). No price is published. The pricing page returns 404 and the MSA leaves the platform fee and the per-company unit fee to an order form (0). The docs describe a free trial of up to 50 companies for 365 days and a sandbox excluded from billing, but the docs say to get in touch to create an account, so half credit (10). Access starts with a person contacting Codat (0).",
          "reliability": "Graded on the hosted REST API at api.codat.io. Statuspage at status.codat.io with components per product and per integration (20). In the 90 days to 8 October 2026 the page shows two complete outages of the API and Portal, 14 minutes on 24 July and 12 minutes of errors on 27 July, intermittent Xero failures from 22 to 29 July, and errors on some integrations and sync services for about two hours on 24 August. No single outage of the core API reached an hour, so we scored it as one major (10). Limits published with numbers, 1,000 requests a day times one plus the active connected companies, 10 concurrent per company and 1,000 a minute per IP (15). 429 with Retry-After and X-Rate-Limit headers, and an Idempotency-Key header on POST and PATCH (15). The standard MSA pays service credits below 99 per cent monthly uptime (10). Generally available (10).",
          "schema": "Public OpenAPI 3 specs for every API in codatio/oas, in JSON and YAML (25). docs.codat.io/llms.txt returns 404. The docs source is Markdown in a public repository, which is not the same as serving it to agents (0). Operation descriptions are long and state prerequisites, useful queries and traps, for example that data must be refreshed before a list call (16). Typed schemas with enums, but filters go through a free-text `query` string and the required fields of a write differ by accounting package and have to be fetched from an options endpoint (11). Response examples per integration on most operations and a documented status code table with sample error bodies (13). Dated changelog at docs.codat.io/updates and a change policy. The API has no version in the path or a header (12).",
          "security": "Plain API keys in a Basic header, up to 10 per client, named, revocable in the Portal or through the API. No scopes and no documented expiry (20). No read-only key and no confirmation step for writes or deletes. Portal users have roles, and only Administrator and Developer roles see keys (4). The API returns ledger text written by third parties, such as invoice descriptions and supplier names, and no injection guidance was found (3). Read and write history per company and data type in the Portal and through the data history and push endpoints. No log of calls per API key was found (7). Annual SOC 2 Type II and ISO 27001 audits, a yearly penetration test, a private bug bounty and a disclosure form on codat.io/security. No security.txt. The trust centre page did not render for us (15).",
          "transparency": "Closed service with a published Master Services Agreement, versioned and dated, naming Codat Limited and its company number (15). The MSA has a data processing schedule and deletes company data five business days after termination. The privacy notice of April 2025 is written mainly for website visitors and gives general retention wording, with six years for customer records (16). A change policy with at least three months' notice of breaking changes, a deprecation calendar, quarterly emails, defined lifecycle states and dated notices (20). The privacy notice names Microsoft Azure in the UK as a sub-processor and the MSA promises 10 days' notice of changes. No fuller list or choice of data location was found (8)."
        },
        "sources": [
          {
            "what": "status incidents (Statuspage API)",
            "url": "https://status.codat.io/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits and 429 handling",
            "url": "https://docs.codat.io/using-the-api/rate-limits",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication and API keys",
            "url": "https://docs.codat.io/using-the-api/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "status codes and errors, free trial limits",
            "url": "https://docs.codat.io/using-the-api/errors",
            "seen": "2026-10-08"
          },
          {
            "what": "idempotency",
            "url": "https://docs.codat.io/using-the-api/write-data/idempotency",
            "seen": "2026-10-08"
          },
          {
            "what": "paging",
            "url": "https://docs.codat.io/using-the-api/paging",
            "seen": "2026-10-08"
          },
          {
            "what": "writes and supported data types",
            "url": "https://docs.codat.io/using-the-api/push",
            "seen": "2026-10-08"
          },
          {
            "what": "change policy",
            "url": "https://docs.codat.io/using-the-api/change-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://docs.codat.io/updates",
            "seen": "2026-10-08"
          },
          {
            "what": "product lifecycle changes",
            "url": "https://docs.codat.io/updates/260330-product-lifecycle-changes",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI specs (cloned, last commit 4 August 2026)",
            "url": "https://github.com/codatio/oas",
            "seen": "2026-10-08"
          },
          {
            "what": "docs source (cloned, last commit 1 October 2026)",
            "url": "https://github.com/codatio/codat-docs",
            "seen": "2026-10-08"
          },
          {
            "what": "first steps, account prerequisite",
            "url": "https://docs.codat.io/get-started/first-steps",
            "seen": "2026-10-08"
          },
          {
            "what": "testing and sandbox",
            "url": "https://docs.codat.io/using-the-api/testing",
            "seen": "2026-10-08"
          },
          {
            "what": "standard MSA, SLA schedule and data processing",
            "url": "https://codat.io/msa-standard/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice",
            "url": "https://codat.io/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://codat.io/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "home page and fintech page",
            "url": "https://codat.io/industries/fintech/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page (404)",
            "url": "https://codat.io/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt (404)",
            "url": "https://docs.codat.io/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "npm @codat/platform",
            "url": "https://registry.npmjs.org/@codat/platform",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI codat-platform",
            "url": "https://pypi.org/pypi/codat-platform/json",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.identitydigital.services/rdap/domain/codat.io",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: whether app.codat.io/signup still opens a free account without sales contact. The page is a JavaScript app we could not read, and the docs say to get in touch",
          "unchecked: the trust centre at trust.codat.io, which did not render, so the sub-processor list and certificates there were not read",
          "unchecked: the official MCP registry for a Codat server. A search returned unrelated results and none was found in Codat's docs",
          "Whether a new client can still buy read access to the full accounting data model outside the Lending product",
          "The enterprise MSA and the Start-up Plan terms were not read in full, and current fees are in order forms only",
          "Idempotency-Key is documented for POST and PATCH, while the Bill Pay spec also lists it on two PUT operations"
        ]
      },
      "negative": 0,
      "verdict": "Public OpenAPI specs, an Idempotency-Key header on writes, Retry-After on 429 and a written three-month deprecation notice suit an agent that retries. Access is the limitation. No price or self-serve signup is published, the general Accounting API is closed to new clients, and API keys carry no scopes.",
      "bestFor": "Banks, lenders, bill pay, expense and card products that already have or will sign a Codat contract and need writes into many accounting packages.",
      "strengths": [
        "Public OpenAPI 3 specs for every API in codatio/oas, with long operation descriptions and per-integration response examples",
        "Idempotency-Key header on POST and PATCH, cached for 90 minutes, and released after a 429 so the same key can be retried",
        "429 responses carry Retry-After, and every response carries X-Rate-Limit-Limit, Remaining and Reset headers",
        "Breaking changes are posted at least three months ahead, with a deprecation calendar and quarterly emails",
        "Annual SOC 2 Type II and ISO 27001 audits and a private bug bounty, per codat.io/security"
      ],
      "weaknesses": [
        "No public price. The pricing page returns 404 and fees are set in an order form",
        "No self-serve signup found. The docs and the site ask new users to get in touch",
        "The general Accounting API spec says it is relevant only to existing clients, and the status page labels it Legacy",
        "API keys have no scopes or read-only mode, and one key reaches every connected company",
        "Two complete API outages in July 2026, of 14 and 12 minutes, and intermittent Xero failures from 22 to 29 July",
        "The Java and Go SDKs were archived in April and May 2026"
      ],
      "agentNotes": [
        "Send `Authorization: Basic \u003cbase64 of the API key\u003e` to https://api.codat.io. The Portal shows the ready-made header value",
        "Send a new GUID as `Idempotency-Key` on every POST and PATCH, and reuse the same key when retrying after a 429",
        "Treat writes as asynchronous on most APIs. Keep the push operation key and wait for the `{dataType}.write.successful` or `.unsuccessful` webhook",
        "Call the Get model (options) endpoint for the connection before a create or update, because required fields differ by accounting package",
        "Filter with `query=modifiedDate\u003e...` and keep `pageSize` at 100. The daily quota is 1,000 requests times one plus the number of active connected companies"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 64.3
        }
      ],
      "editorialScores": {
        "ergonomics": 81,
        "maintenance": 75,
        "payments": 10,
        "reliability": 80,
        "schema": 77,
        "security": 49,
        "transparency": 59
      },
      "provenanceScore": 82
    },
    "connect": {
      "install": "npm install @codat/platform",
      "http": "curl https://api.codat.io/companies \\\n  -H \"Authorization: Basic $CODAT_ENCODED_API_KEY\""
    },
    "letme": {
      "capability": "https://letme.dev/accounting.unified",
      "tool": "https://letme.dev/codat"
    },
    "notable": [
      "Codat rebranded on 20 April 2026 around insight products for commercial banks, and says existing connections, integrations and APIs are unaffected (https://docs.codat.io/updates/260420-codat-rebrand)",
      "The Accounting, Banking, Commerce, Assess and Files API specs open with a notice that they are relevant only to existing clients. New clients are sold Bill Pay, Expenses, Bank Feeds, Lending and Spend Insights (https://github.com/codatio/oas)",
      "Rate limits are 1,000 requests a day times (1 + active connected companies), 10 concurrent requests per active connected company and 1,000 a minute per IP, with Retry-After on 429 (https://docs.codat.io/using-the-api/rate-limits)",
      "Idempotency-Key is accepted on POST and PATCH across the APIs, with a 90-minute cache, 422 for a reused key with a different body and 409 for one still in progress (https://docs.codat.io/using-the-api/write-data/idempotency)",
      "Sync for Payables v1, Sync for Expenses v1 and Sync for Payroll entered a 12-month maintenance period on 1 May 2026 and lose API access from 1 May 2027 (https://docs.codat.io/updates/260330-product-lifecycle-changes)",
      "The standard MSA of 5 September 2022 pays service credits when monthly uptime falls below 99 per cent, and gives five business days to export data after termination before deletion (https://codat.io/msa-standard/)",
      "No MCP server, llms.txt at docs.codat.io or machine payment protocol was found in the docs repository or on the site (https://github.com/codatio/codat-docs)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "APIs for new clients",
        "value": "Platform (52 operations), Lending (156), Bill Pay synchronous (25), Expenses (48), Bank Feeds (33) and Spend Insights (7), all OpenAPI 3 in codatio/oas and served from https://api.codat.io"
      },
      {
        "label": "Legacy APIs",
        "value": "Accounting (135 operations), Banking, Commerce, Assess and Files, each marked as relevant only to existing clients. Sync for Payables v1, Sync for Expenses v1 and Sync for Payroll are in maintenance until 1 May 2027"
      },
      {
        "label": "Accounting packages",
        "value": "22 integration folders in the docs, among them Xero, QuickBooks Online and Desktop, NetSuite, Sage Intacct, Sage 50 and 200, Dynamics 365 Business Central, MYOB, FreshBooks, Zoho Books, Workday and a Codat Sandbox"
      },
      {
        "label": "Credentials",
        "value": "API key, Base64 encoded in an `Authorization: Basic` header. Up to 10 named keys, created and deleted in the Portal or through /apiKeys. No scopes"
      },
      {
        "label": "Rate limits",
        "value": "1,000 requests a day times (1 + active connected companies), reset at 00:00 UTC. 10 concurrent requests per active connected company. 1,000 a minute per IP"
      },
      {
        "label": "Writes",
        "value": "Create, update and delete across 18 accounting data types, asynchronous with a push operation key and write webhooks. The synchronous Bill Pay API answers in the request"
      },
      {
        "label": "Idempotency",
        "value": "`Idempotency-Key` GUID on POST and PATCH, cached 90 minutes, not cached for 429"
      },
      {
        "label": "Paging and filters",
        "value": "`page` and `pageSize` (default 100, maximum 5,000), a `query` filter language and `orderBy`. Bill Pay lists use a continuation token"
      },
      {
        "label": "Errors",
        "value": "JSON with statusCode, service, error, correlationId, canBeRetried, detailedErrorCode and a validation object. 402 marks a free trial limit"
      },
      {
        "label": "SDKs",
        "value": "TypeScript @codat/platform 6.2.1 and Python codat-platform 5.0.1 (23 April 2026), C# Codat.Platform 6.2.1, one package per product. Java archived 2 April 2026, Go 7 May 2026"
      },
      {
        "label": "Sandbox",
        "value": "Codat Sandbox integration with sample companies, no credentials, excluded from billing. Test clients are limited to 50 active connected companies"
      },
      {
        "label": "SLA",
        "value": "Service credits of 10, 30 and 100 per cent of the platform fee when monthly uptime is below 99, 95 and 90 per cent (standard MSA, Schedule 1)"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II and ISO 27001, audited yearly per codat.io/security. Private bug bounty, yearly penetration test. Hosted on Microsoft Azure"
      },
      {
        "label": "MCP server",
        "value": "None found"
      }
    ],
    "provenance": {
      "legalEntity": "Codat Limited",
      "domain": "codat.io",
      "domainRegistered": "2016-10-17",
      "endpointOnVendorDomain": true,
      "terms": "https://codat.io/msa-standard/",
      "privacy": "https://codat.io/privacy-policy/",
      "statusPage": "https://status.codat.io",
      "changelog": "https://docs.codat.io/updates",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The standard MSA (version 2.0, 5 September 2022) names Codat Limited, registered in England and Wales, number 10480375, 6-7 St. Cross Street, London EC1N 8UB, for clients in the UK and the rest of the world outside the USA. The privacy notice also names Codat, Inc., a Delaware corporation.",
        "codat.io/legals lists two agreements, the Master Services Agreement (standard and enterprise versions) and the Start-up Plan terms. The standard MSA is the one recorded here.",
        "The Codat Global Privacy Notice was last updated in April 2025. It is written mainly for website visitors, and the MSA points to the same page for the sub-processor list.",
        "codat.io, app.codat.io and api.codat.io all return 404 for /.well-known/security.txt. codat.io/security has a disclosure form.",
        "RDAP for codat.io gives a registration date of 2016-10-17."
      ],
      "score": 82,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Codat Limited",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "codat.io, registered 2016-10-17 (9 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.codat.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 7.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.codat.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://codat.io/msa-standard/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2022-09-05",
          "words": 8232,
          "points": 7.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Agreement Version: v2.0 dated 5 September 2022.",
              "says": "Last updated 2022-09-05"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "(b) as may be required by law, a court of competent jurisdiction or any governmental or regulatory authority but (to the extent permitted by applicable law or the requesting authority) only after the Disclosing Party has been so notified promptly in writing and has had the opportunity, if possible, to obtain reasonabl…"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "11.3 Subject to clause 11.1, Codat’s total liability to the Client, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, arising out of or in connection with the Agreement shall be limited as follows: a) if Codat Limited is the Codat contracting party, the greater of £50,000 or the…",
              "says": "Capped at the greater of £50,000 and the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "A party may terminate this Agreement by given written notice (i) upon 20 days written notice to the other party of a material breach if such breach remains uncured at the expiration of such period, or (ii) if the other party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency…"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "A party may terminate this Agreement by given written notice (i) upon 20 days written notice to the other party of a material breach if such breach remains uncured at the expiration of such period, or (ii) if the other party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency…",
              "says": "Gives 20 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": false
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Service Credits: means a service credit payable by Codat to the Client where the Codat Products fail to meet the Service Levels, as set out in paragraph ‎2 of Schedule 1."
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(c) access all or any part of Codat Products in order to build a product or service which competes with the Codat Products and/or Codat Services;",
              "costsPoints": true
            },
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Agreement Version: v2.0 dated 5 September 2022."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The client must not use the Codat Products in a way that, in Codat's reasonable opinion, exceeds reasonable request volume or is excessive or abusive.",
              "quote": "(c) not use the Codat Products in a manner that in Codat’s reasonable opinion exceeds reasonable request volume, constitutes excessive or abusive usage, or otherwise fails to comply or is inconsistent with any part of this Agreement;"
            },
            {
              "date": "2026-10-08",
              "text": "The client has 5 business days after termination or expiry to export Company Data, after which Codat deletes it.",
              "quote": "Codat shall afford the Client 5 Business Days following the date of termination or expiry of this Agreement within which the Client may download/export the Company Data, following which time Codat shall delete the Company Data."
            },
            {
              "date": "2026-10-08",
              "text": "If Codat terminates for the client's breach or insolvency, the client pays the unpaid fees for the rest of the term of all order forms.",
              "quote": "If this Agreement is terminated by Codat in accordance with clause 7.3 above, Client will pay any unpaid Fees covering the remainder of the term of all Order Forms to the extent permitted by applicable law."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://codat.io/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-04-01",
          "words": 3913,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "This Privacy Notice was last updated in April 2025",
              "says": "Last updated 2025-04-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Clicking on those links or enabling those connections may allow third parties to collect or share data about you."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You have the right to withdraw consent to marketing at any time by contacting us."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you wish to exercise any of the rights set out above, please contact us using the following form: https://preferences.codat.io/privacy."
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "This will involve transferring your data outside the UK."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/codat.json",
    "live": {
      "slug": "codat",
      "probe": {
        "target": "https://api.codat.io",
        "method": "get",
        "lastAt": "2026-10-08T19:08:43.662253972Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 179,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 68,
        "p95ms24h": 179,
        "samples24h": 19,
        "samples30d": 19,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 19,
            "ok": 19
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.codat.io",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:06:31.533184983Z"
      },
      "pages": [
        {
          "url": "https://docs.codat.io/updates",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:18:26.233949031Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "07529b659c92"
        },
        {
          "url": "https://codat.io/privacy-policy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:16:28.10988641Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "e89a28b3e19e"
        },
        {
          "url": "https://codat.io/msa-standard/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:16:25.833678794Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "a5936b16dc49"
        }
      ],
      "updatedAt": "2026-10-08T19:08:43.662253972Z"
    }
  }
}
