How we test and rank

Every recommendation on this site is built for businesses with 1–25 people and no IT department. Here is exactly how we evaluate products — and how you can audit us.

Testing statuses (every product page shows one)

LabelWhat it requires
Hands-on testedWe ran the product in our lab with a simulated small company: signup through cancellation, including user invites, MFA, offboarding, data export, and (for backup) an actual restore. A dated test log exists.
Trial testedWe completed a real trial with core workflows, but not the full lab protocol.
Long-term testedWe have run this product in real use for 6+ months.
Documentation reviewOur assessment is based on official documentation, security whitepapers, and pricing pages — not our own usage. We say so prominently.
Vendor briefingThe vendor demonstrated the product to us. Useful context, weakest evidence — never the basis of a ranking.
Not yet testedOn our list; no evaluation completed. We do not rank untested products above tested ones.

We never label a summary of vendor marketing as a hands-on review.

Scoring categories

Products are scored 1–10 in each category, weighted for small teams:

Every review discloses

What money can never change

Affiliate commissions do not determine rankings. Mechanically: scores are finalized against the rubric above before we check whether a product has an affiliate program, and the ranking is locked at that point. Some of our top recommendations pay us nothing — Bitwarden, for example, has no affiliate program; we recommend it wherever it is genuinely the best fit.

Limits of our testing

We simulate small companies in an isolated lab; we cannot reproduce every environment, and a product that worked flawlessly for us can still fail for you. Nothing here is a guarantee of security, compliance, or fitness — no product makes a business “unhackable,” and anyone who says otherwise is selling something. Found an error? See our corrections policy.