How we audit
Every fact on a vendor profile traces back to something you can check yourself: a measurement we ran, or a quote from the vendor’s own public page with a link to where it came from. This page documents exactly how that works, so you can decide for yourself how much weight to put on it before it goes in front of your review committee.
What we check
Vendor profiles are organized around the same areas a procurement review actually covers, so the shape of an audit matches the shape of the meeting you’ll walk it into.
- Security
- TLS configuration, security headers, DMARC enforcement, MFA, penetration testing, encryption, incident response — the questions your security review asks first.
- Compliance & legal
- SOC 2, ISO 27001, GDPR posture, a Data Processing Agreement, sub-processor lists, data residency — what legal and data-governance reviewers need on file.
- AI governance
- Whether the vendor trains its models on your data, output labeling, human oversight, and EU AI Act posture — the AI-specific questions a review committee now routinely adds.
- Risk & viability
- Business-continuity planning, published financial reporting, uptime SLAs — the operational-risk side of a procurement decision.
- Technical fit
- API surface, hosting model, integration capability — what an architecture reviewer checks before a shortlist becomes a pilot.
Where the evidence comes from
Every claim comes from the vendor’s own public pages — never from a third-party directory, a review site, or our own assumption about a category. Every claim on a profile links to the exact page it came from, so you can open it and read the same sentence we did.
A quote is only counted as evidence if it is found word for word on the page it is said to come from. If our extraction cannot confirm a quote against the vendor’s own saved page text, that quote does not count as evidence — the claim falls back to “not found” rather than being shown as if the vendor said it.
Some vendors are products of a parent company, and the only page that states a given policy is the parent’s, not the product’s own. When that happens, the claim is labelled “parent company” on the profile, with a note that the statement may not apply to the specific product — we do not fold a parent-company statement into the vendor’s own record silently.
What the four statuses mean
- Verified
- Measured directly by our own systems — not taken on the vendor's word. Today that covers the externally measurable Tier-0 facts: TLS grade, DMARC enforcement, security-headers grade, and robots/AI-crawler directives.
- Self-attested
- The vendor says so, on its own public page, and we show the exact quote with a link to where it came from. You are reading the vendor's claim, sourced — not our opinion of it.
- Contradictory
- Two things the vendor publishes about the same claim disagree with each other. We surface the conflict rather than picking a side.
- Not found
- We could not find published evidence for this claim on the vendor's public pages. That is an absence, not a “no” — plenty of vendors hold a certification or policy they simply have not put on their website. Treat it as a question for the vendor, not a mark against them.
What we measure ourselves, weekly
A small set of facts is measured directly from outside the vendor’s site, on a weekly cadence, rather than read off a page:
- TLS certificate grade
- DMARC enforcement
- Security-headers grade (HSTS, CSP, X-Content-Type-Options, and the rest of the set)
- robots.txt and AI-crawler directives (GPTBot, ClaudeBot, and any TDM opt-out)
- llms.txt / llms-full.txt presence
If a site cannot be reached during a weekly check, that is reported as unknown, not as a bad grade. A network hiccup or a temporary outage on our end is not evidence that a vendor’s security posture is poor, and we do not treat it as one.
How we respect vendors’ sites
- We honour robots.txt and machine-readable AI-crawler directives, including a TDM/AI-training opt-out. If a vendor’s site disallows AI crawlers, we do not scrape it — we flag that and move on.
- There is no bypass path: a disallow is respected, not worked around.
- We do not train any model on a vendor’s content.
- Outbound links to a vendor’s own site carry
rel="nofollow"— we do not pass link authority to the vendors we audit. - A vendor who finds something wrong on its profile has a correction channel, set out in our Terms of Service.
Freshness
The weekly external scan re-checks the catalog on that cadence. Every vendor row in the catalog carries the date it was last verified, and every category page shows the date of its freshest verified record at the top — so you can see how current the page is before you rely on it, without opening every row.
What we do not do
- No ratings or scores that are our own opinion. Every status on this site traces back to a measurement or a sourced quote, never a subjective score we assign.
- No pay-to-play. A vendor cannot buy a better status, a higher position, or a hidden gap.
- No personal data collection from vendor pages. The audit reads published product, security and compliance information — not personal profiles, and not the people behind a vendor.
- No claim of completeness. The catalog reflects the vendors we have audited, not “every vendor” in a category — and where coverage is thin, the category page says so rather than padding it out.