Security & authorization evidence
How we record a security, compliance, or authorization claim so that a reader can see exactly what it covers, who says so, and when we checked.
What every record contains
Record fields
- Claim
- The exact statement being evaluated, in the words of its source.
- Exact product or service
- The specific product, not the vendor. A vendor can hold a status for one service and not another.
- Deployment environment
- Commercial cloud, government cloud, on-premises, or self-managed.
- Program or standard
- The authorization program, certification, or standard, and any level or category.
- Status
- As stated by the authoritative source: for example authorized, in process, or not listed.
- Scope and exclusions
- What the status covers, and what it explicitly does not.
- Authoritative source
- A link to the record kept by the program or issuing body, not only the vendor.
- Source organization and dates
- Who published it, when it was published, and when we last checked it.
- Classification
- One of the six evidence classes below.
- Limitations
- What the evidence does not show.
Evidence classes
Each statement carries one of these labels as visible text.
Evidence classes
- Vendor-reported claim
A statement made by the company that sells the product. Useful as a lead, not as a finding.
- Independently observed
Behaviour a reviewer saw directly but did not measure under a repeatable protocol.
- Independently measured
A result produced under a documented, repeatable protocol run by someone independent of the vendor.
- Third-party research
Work published by researchers or institutions other than us or the vendor. We link it; we have not reproduced it.
- Editorial interpretation
Our reading of what the evidence means. Judgment, clearly separated from the evidence itself.
- Unverified
A claim we could not confirm, or have not yet checked. It should not be relied on.
Rules we apply
Rules
- A status is called verified only when a current authoritative source supports the exact product, deployment, and scope.
- Vendor statements are always labelled as vendor statements.
- An authorization held by one service is never presented as covering another.
- If we cannot confirm a status, the page says it is unverified or unknown.
- Where a program publishes its own listing (for example the FedRAMP Marketplace for FedRAMP), we link to that listing and not to a vendor summary of it.
Record template
The layout of a record, with placeholders. This is not a real record and describes no product.
Record template
| Field | Example placeholder |
|---|---|
| Product / service | [Exact product name and edition] |
| Deployment | [e.g. vendor-hosted, government cloud] |
| Program and status | [Program name, level, status as stated by the program] |
| Scope / exclusions | [What is covered, and what is not] |
| Source | [Link to the authoritative listing] |
| Classification | [Independently observed, third-party research, vendor-reported claim…] |
| Verified on | [YYYY-MM-DD] |