Skip to content Editorial policy
- Independence. Rankings are set by the public methodology before monetization is considered. Vendors cannot buy placement, scores, or softer criticism. Affiliate status is disclosed per page and per link.
- Evidence. Claims are labeled by testing status. Prices carry a checked-on date. Statistics link to primary sources. We do not publish reviews of products we have not evaluated.
- Vendor contact. We accept briefings and label them. Vendors may flag factual errors before publication; they never see scores in advance and never hold editorial control. Free review access is accepted only with disclosure and returns/cancellation after testing.
- No fear-mongering. Security content explains real risk plainly; we never use fear plus an affiliate button, and we never promise any product prevents an incident.
- Scope honesty. We serve 1-25 person businesses. Regulated industries (healthcare, legal, finance) get pointers to specialists, not pretend expertise.
- Categories we deliberately don't cover. We do not review compliance and GRC platforms, vulnerability management and scanning, patch management, attack-surface management, or endpoint detection and response. The author works in the enterprise security industry, and no amount of disclosure would make a recommendation in a category his employer competes in genuinely neutral — so we decline the category rather than caveat it. These are also overwhelmingly enterprise purchases, not decisions a 1-25 person business is making.
- AI assistance. Drafting tools may be used for structure and editing; every fact, test result, screenshot, and recommendation is human-verified. We do not publish scaled AI content.
- Corrections. See the corrections policy.