CertReports is an index of public compliance evidence for B2B software vendors. This policy is modelled on the US Chamber of Commerce Principles for Fair and Accurate Security Ratings, adapted to attestations: transparency of method, dispute resolution, accuracy and validation, independence, and confidentiality.
What a state means
| State | Meaning | Display |
|---|---|---|
| Verified (registry) | Confirmed in an official or scheme-operator registry: FedRAMP data, CSA STAR, the Data Privacy Framework list, the Visa Global Registry, TX-RAMP, Cyber Essentials. | "Listed in [registry] as of [date]" |
| Verified (auditor or CB) | Confirmed in a certification body's or audit firm's public register, or by an auditor-issued public letter or SOC 3. | "Confirmed by [auditor] as of [date]" |
| Vendor-stated | The vendor states it on its own domain or hosted trust centre, with a capture snapshot. | "Vendor states [X] on [page] as of [date]" |
| Reported | A press release, marketplace listing or reputable third-party page reports it, with no primary source. | "Reported by [source] as of [date], not confirmed" |
| Expired | A previously verified or stated attestation passed its expiry or period end without renewal evidence. | "Expiry [date] passed, no renewal found as of [date]" |
| No public evidence | Nothing found across all sources at the last check. | "No public evidence found as of [date]", always with the explanation that this does not mean the vendor is non-compliant |
| Not applicable | The framework does not apply to the vendor type. Set by review or vendor claim, never inferred. | "Not applicable" |
Rules we hold ourselves to
- CertReports publishes only statements of verifiable fact with a date and a source. It never states that a vendor is non-compliant, not certified or has failed anything.
- The word "certified" is never used for SOC 2. SOC 2 is an attestation report; CertReports says "has a SOC 2 Type II report".
- HIPAA has no certification. CertReports records whether a vendor offers a business associate agreement and never shows a "HIPAA certified" seal.
- A state moves from weaker to stronger only through a stronger source. A vendor claim can add evidence but cannot delete registry or auditor evidence.
- Nothing extracted with confidence under 0.7 is published without human review.
- Restricted-use SOC 2 reports are never hosted, cached or summarised beyond facts the vendor or auditor already made public.
- Official framework marks identify the scheme an evidence row is about. They are never used as CertReports branding and never composited with a CertReports seal.
Disputes and corrections
Every row carries a "This is wrong" link. A dispute enters the review queue immediately, the row shows "Under review" while pending, and CertReports commits to a correction or a reasoned response within two business days. Corrections are recorded in the vendor’s change history so the record is complete.
Takedown and legal requests are logged and answered from templates within the same service level. Logo and mark removal requests are actioned without taking the page down; the row falls back to a letter mark or a drawn mark.
Independence
Money comes from workflow, freshness and reach, never from altering a state. Vendors cannot pay to hide, reorder or soften a row. Sponsored placements are labelled and never appear inside the evidence grid.
Validation
Extraction precision is audited on a sample every month against a target of 95 percent at launch rising to 98 percent. Registry parsers are re-verified when a registry changes shape, and a run that returns suspiciously few rows fails loudly rather than publishing an empty result.