How we work
Public data only. Every study on this page is built from records that are world-readable by design — DNS, certificate transparency logs, published disclosures. No system is accessed, scanned, or tested. Where we assess a client’s infrastructure directly, that is an engagement under contract, and it does not become research.
Anonymised before publication. Names, sector detail, and anything reconstructible come out first. Publishing a list of named organisations next to the specific gap in their defences serves attackers more efficiently than defenders, and we will not make that trade for a marketing asset.
Limitations stated, not buried. Each report carries a section describing what the method cannot show and where the sample is weak. If a finding is softer than the headline suggests, the report says so.
Point-in-time, and dated. Infrastructure changes. Every figure carries the date it was measured.
If you want to know where your own organisation sits on any of this, ask us. We will run it and send you the result.