Methodology

Source Policy: Discovery Sources vs Verified Trust Evidence

Trust Signal Directory separates candidate discovery from evidence classification. Public product lists, launch pages, category pages, startup databases, and manual research may help identify companies for review. They are not treated as trust, security, privacy, compliance, or enterprise-readiness evidence.

Discovery Used to find candidates for review
Evidence Verified from official public sources
Boundary No buying-intent claims from listings

Why discovery sources are not evidence

A discovery source can help identify a company, product, or category that may deserve review. It does not prove that the entity is a company, a B2B software vendor, an enterprise-facing vendor, or a trust-evidence subject.

Listings are candidate inputs

A third-party listing, launch page, product directory, or category page can place an entity into a review queue. It does not create an evidence object by itself.

Company status is verified separately

A product name may refer to a company, a feature, an open-source project, a side project, a model release, a consumer app, or a discontinued product.

Trust evidence requires official sources

Evidence classification requires public, company-controlled sources that can be reviewed independently and tied to a specific vendor.

What discovery sources are used for

Discovery sources support coverage and category research. They help build candidate pools, identify adjacent vendors, and avoid relying only on already-known companies.

A

Candidate discovery

Find companies, products, and projects that may belong to SaaS, AI, developer tooling, data, security, workflow automation, or other relevant software categories.

B

Category mapping

Group candidates by market context so evidence patterns can be reviewed within categories rather than as an undifferentiated list.

C

Review prioritization

Prioritize likely B2B and enterprise-facing vendors for manual review before any evidence status or signal role is assigned.

What qualifies as verified public trust evidence

Verified public trust evidence must come from official or company-controlled public sources, or from public announcements that can be tied directly to the company and reviewed by another reader.

Primary official sources

  • Company websites
  • Trust Centers
  • Security pages
  • Privacy Policies and Terms
  • DPA and Subprocessor pages
  • SOC 2, ISO, HIPAA, GDPR, or framework statement pages
  • AI data usage, Responsible AI, model governance, or data retention pages

Supporting official sources

  • Product documentation
  • Changelogs and release notes
  • Status pages
  • Careers pages and public job posts
  • Enterprise pricing or procurement-readiness pages
  • Public customer assurance or security questionnaire workflows
  • Public announcements relevant to trust, security, privacy, or compliance evidence

Official-source verification rule

A candidate is not classified as a trust signal until official public evidence has been reviewed. The classification stays close to the evidence and avoids unsupported conclusions.

Candidate discovered
A company or product is identified through a public discovery source, category list, startup list, launch page, or manual research.
Entity reviewed
The reviewer checks whether the candidate appears to be a company, product, project, or unrelated entry and whether it is relevant to the monitored software categories.
Official source found
The reviewer identifies company-controlled public pages such as a website, Trust Center, Security page, Legal page, DPA, Subprocessor page, documentation, changelog, or careers page.
Evidence object created
The observation is recorded with source URL, page type, company, captured date, review note, evidence status, and interpretation caveats.
Signal role assigned
Only after evidence review may the item be classified as current public baseline, candidate signal, maturity benchmark, adjacent monitoring seed, or another public-safe signal role.

What not to infer from discovery sources

Discovery sources can expand the review universe. They do not support conclusions about a vendor's trust posture or commercial intent.

Not company verification

A listing does not prove the entity is an active company or that it has a current official website.

Not B2B verification

A software or AI category listing does not prove the vendor sells to businesses, enterprise buyers, or regulated customers.

Not trust maturity

A candidate appearing in a category does not prove the presence of a Trust Center, Security page, DPA, SOC 2 statement, AI policy, or enterprise controls.

Not buying intent

Discovery does not imply budget, active procurement, vendor search, customer pressure, compliance gaps, or need for a specific product or service.

How missing evidence is handled

When an expected trust surface is not observed, the site treats it as not observed or not verified. It does not claim the evidence is absent, that the company lacks the control, or that the company is non-compliant.

Practical implication for this directory

The site may use broad public discovery sources to build candidate review pools, but public company profiles, directories, examples, and reports should rely on official public evidence before assigning evidence status or signal role.

Candidate pools stay internal

Large discovery pools are used for review prioritization and coverage planning. They are not published as evidence directories without verification.

Public pages require review

Published entries should include official source URLs, evidence status, last checked dates when available, and a clear note on what should not be inferred.

Interpretation remains conservative

The directory may describe public evidence surfaces and signal roles, but it does not claim active buying intent, non-compliance, vendor risk, or procurement pressure.