Enterprise & government

Security & authorization evidence

How we record a security, compliance, or authorization claim so that a reader can see exactly what it covers, who says so, and when we checked.

What every record contains

Record fields

Claim
The exact statement being evaluated, in the words of its source.
Exact product or service
The specific product, not the vendor. A vendor can hold a status for one service and not another.
Deployment environment
Commercial cloud, government cloud, on-premises, or self-managed.
Program or standard
The authorization program, certification, or standard, and any level or category.
Status
As stated by the authoritative source: for example authorized, in process, or not listed.
Scope and exclusions
What the status covers, and what it explicitly does not.
Authoritative source
A link to the record kept by the program or issuing body, not only the vendor.
Source organization and dates
Who published it, when it was published, and when we last checked it.
Classification
One of the six evidence classes below.
Limitations
What the evidence does not show.

Evidence classes

Each statement carries one of these labels as visible text.

Evidence classes

  • Vendor-reported claim

    A statement made by the company that sells the product. Useful as a lead, not as a finding.

  • Independently observed

    Behaviour a reviewer saw directly but did not measure under a repeatable protocol.

  • Independently measured

    A result produced under a documented, repeatable protocol run by someone independent of the vendor.

  • Third-party research

    Work published by researchers or institutions other than us or the vendor. We link it; we have not reproduced it.

  • Editorial interpretation

    Our reading of what the evidence means. Judgment, clearly separated from the evidence itself.

  • Unverified

    A claim we could not confirm, or have not yet checked. It should not be relied on.

Rules we apply

Rules

  • A status is called verified only when a current authoritative source supports the exact product, deployment, and scope.
  • Vendor statements are always labelled as vendor statements.
  • An authorization held by one service is never presented as covering another.
  • If we cannot confirm a status, the page says it is unverified or unknown.
  • Where a program publishes its own listing (for example the FedRAMP Marketplace for FedRAMP), we link to that listing and not to a vendor summary of it.

Record template

The layout of a record, with placeholders. This is not a real record and describes no product.

Record template

Template for an evidence record
FieldExample placeholder
Product / service[Exact product name and edition]
Deployment[e.g. vendor-hosted, government cloud]
Program and status[Program name, level, status as stated by the program]
Scope / exclusions[What is covered, and what is not]
Source[Link to the authoritative listing]
Classification[Independently observed, third-party research, vendor-reported claim…]
Verified on[YYYY-MM-DD]