Methodology

Source-scope Evidence Policy

Trust Signal Directory separates public evidence from interpretation. This policy explains how a source is scoped before it is used on a company profile, category snapshot, comparison page, or public evidence matrix.

Scope Product, parent, acquisition, hub, or review-required
Boundary Observed evidence is not a vendor conclusion
Control High-risk evidence requires conservative labeling

Why source scope matters

A public page can belong to a product, a parent vendor, an acquired brand, a shared trust portal, or a general legal hub. The same URL can support different public statements depending on its scope. The directory therefore records what the source can support and what should not be inferred from it.

Evidence is not flattened

Official source URLs are not treated as a generic link list when the claim is sensitive or entity scope is unclear.

Labels are visible

Where scope-sensitive evidence is rendered, the public page should show whether the source is product-specific, parent-vendor scoped, hub-referenced, or still requiring review.

Ambiguity is preserved

If a source does not clearly support a public statement, the directory should hold the stronger claim rather than convert uncertainty into a vendor conclusion.

Source-scope labels used by the directory

These labels describe how an official source relates to the company or product being reviewed. They do not describe security quality, control quality, sales timing, or procurement status.

Product-specific evidence
The official source explicitly names the product, service, or product family being profiled. This can support product-scoped public copy when the evidence surface is otherwise reviewed.
Parent-vendor evidence
The official source belongs to a parent company, cloud platform, corporate legal page, or shared security program. It may be useful context, but it should not be displayed as if it only applies to the specific product being profiled.
Acquisition or redirect scope
The company or product has been acquired, redirected, renamed, merged, or absorbed into another entity. Public rendering should remain conservative until the current entity scope is reviewed.
Hub-referenced evidence
A trust portal, legal hub, or documentation hub points to a policy, report, list, or request flow. The hub itself is not automatically treated as the direct document.
Evidence requiring review
The source may be relevant, but the scope is mixed, unclear, or not yet reviewed. It should not support a stronger public evidence label until review is complete.

High-risk evidence surfaces

Some evidence surfaces require stricter handling because readers may overinterpret them. The directory treats these fields conservatively and avoids converting public claims into certification, control, or vendor-quality conclusions.

Requires exact source review

  • SOC 2, ISO, HIPAA, GDPR, PCI DSS, or similar framework statements
  • DPA and subprocessor pages
  • AI data usage, model training, responsible AI, or model safety pages
  • Enterprise controls such as SSO, SCIM, RBAC, audit logs, and data residency
  • Vulnerability disclosure, security questionnaire, and trust portal flows

Public page must not infer

  • The vendor is secure or insecure
  • The vendor meets or fails compliance requirements
  • The vendor lacks a control
  • The vendor is ready for procurement
  • The vendor is buying or seeking a specific tool or service

Analytics and discovery boundary

Search queries, impressions, public launch lists, category pages, startup databases, and manual research can help prioritize review. They do not establish evidence scope and must not be rendered as vendor evidence.

Allowed use

Use analytics and discovery sources to decide which company, category, source field, or comparison page should be reviewed next.

Forbidden use

Do not use query wording, impression volume, or a third-party listing to claim that a vendor has a trust surface, lacks a control, faces procurement pressure, or is buying anything.

Review still controls

Official source review, source-role classification, source-scope classification, and public-output validation determine what can be published.

Public rendering rule

A public rendering input is a publication act. Scope-sensitive evidence should only appear on a public page when the renderer can preserve the scope label, source role, review state, and forbidden inference note.

01

Review official source

Confirm the source URL is official or company-controlled and relevant to the evidence surface.

02

Classify source scope

Determine whether the source is product-specific, parent-vendor scoped, acquisition scoped, hub-referenced, mixed, or unclear.

03

Apply rendering gate

Render only if the public page can show the label and avoid unsupported compliance, security, procurement, or buying-intent conclusions.