How we evaluate

Methodology

Products on this site are evaluated on published evidence — independent security audits, certifications, transparency reports, warrant canaries, public privacy policies, and documented pricing and renewal terms — linked inline where each claim lands. We do not run hands-on lab tests, and no page on this site implies that we do.

The evaluation basis

  • Independent security audits. Engagement scope, auditor, dates, and findings — with the auditor's own report linked wherever a public PDF exists. When a report is only distributed through a vendor dashboard or account portal, we say so instead of implying it's publicly downloadable.
  • Certifications. ISO/IEC 27001, SOC 2 attestations, and AV-TEST / AV-Comparatives results are recorded as company-published claims, with the certification or attestation page linked.
  • Incident history. Disclosed breaches and policy changes are part of the record and appear in reviews, with coverage linked — including where the outcome of a remediation is not yet independently verified.
  • Pricing and renewals. Prices are documented snapshots with the retrieval date stated; every review carries a re-verify-on-the-official-page note, because promo pricing and renewal jumps are the vertical's most common complaint.
  • Jurisdiction. Registration country, parent-company structure, and surveillance-alliance membership are stated from the vendor's own legal pages and coverage.

What we did not do

The honest limits, spelled out because they matter to trust:

  • No hands-on performance testing — no speed runs, no lab benches.
  • No user-rating collection; no scores derived from other sites' ratings.
  • No anonymous “expert” personas or invented author bios.
  • No claims that we purchased and used a product anonymously.

Where an audit fact exists only as a company-published claim without a public auditor URL, the page says exactly that. Audit facts are relayed claims unless the underlying report is linked — we mark the difference rather than blurring it.

Ratings and schema policy

We publish no star ratings and no ranking scores, and our structured data contains no Review, Product, or AggregateRating markup — because markup must mirror visible content, and we have no rating basis to mirror. When a verified user-review mechanism exists, this policy gets revisited — not before.

Affiliate disclosure standard

Affiliate links appear only where a program is approved, always carry rel="sponsored nofollow", and sit below a plain-language disclosure placed above the first affiliate link on every page — not footer-only. Commissions never influence what an evaluation says, which products get evaluated, or how negatives are reported. Undisclosed affiliate promotion is deceptive; visible disclosure is the fix we practice.

Updates

Each page carries a visible last-reviewed date. When evidence changes materially (a new audit, a disclosed incident, a pricing restructure), the page is updated and the date moves. Pricing snapshots are re-verified on official pages before they matter to a purchase decision.

Found a claim without a source, or a source that doesn't support its claim? contact@settleoak.com — corrections get the same visibility as the original.