Every vendor grade on Entropy is computed against a versioned rubric, not a gut feeling. Here's what actually goes into it.
Five categories, one grade
A company's score is a weighted combination of five categories. The point values below are pulled straight from the live rubric (currently v1.3.0); the methodology page has the authoritative, signal-by-signal breakdown.
- Security hygiene & transparency (35 pts) — observable practices on a vendor's public domain: a valid
security.txtfile, HTTPS enforced with HSTS, correctly configured security headers, a public disclosure policy, and a public trust/security page existing at all (existence only — what the page actually claims is never scored). These are proven proxies for organizational security culture, not a substitute for a code audit. - AI safety practices (25 pts) — whether a vendor publishes meaningful transparency artifacts about their models: model cards, training data disclosure, red-team results. Marketing copy about "responsible AI" doesn't count; a published artifact does.
- Governance (31 pts) — certifications and organizational structures that show institutionalized security, like SOC 2 Type II or ISO 27001, or board-level security oversight. Every certification here is scored as a bonus: a verified one raises the score, but a missing one never lowers a grade.
- Incident history (15 pts) — how a company has actually handled security incidents. Response quality matters as much as whether an incident happened at all.
- Verification bonus (5 pts) — bonus points added when a vendor confirms domain ownership by claiming their profile. They lift a score without ever lowering one, so a vendor who hasn't claimed is never penalised for it.
We grade against what's actually measured, not the full eventual rubric
Not every signal in the rubric is live yet — some, like CVE exposure tracking or model card verification, are still being built. Rather than pretend those categories score zero for everyone (which would flatten every vendor's grade toward the same misleadingly low number), Entropy grades against implemented signals only. A company with a partial technical-security profile — say 18 of 28 implemented points, some signals in place and others not — shows a B-, not an F, because the comparison is honest about what's actually been measured so far. As we add signal categories, the denominator grows and grades get more precise — but a vendor's grade today reflects real, verified data, not a placeholder.
Current grade vs. potential score
Every profile shows a current grade, computed purely from automated signals with no vendor involvement required, and — where a concrete, currently-scored fix would change the grade — a potential grade showing what closing that gap would reach. The verification bonus (up to 5 points, for confirming domain ownership via DNS) gives vendors a direct, actionable lever on their own standing rather than an opaque score they can't influence. It's bonus-only — it lifts a score without moving the grade denominator, so it never penalises a vendor who hasn't claimed — and it applies within minutes of a claim, not just on the weekly rescan.
Versioned, so history stays comparable
Every score is tied to the rubric version it was computed against. That means as the methodology evolves — new signals, adjusted weights, refined grade thresholds — historical scores remain comparable, and you can always tell whether a given score reflects the current rubric or an earlier one. Grade threshold changes are announced with the rubric version and only apply going forward, never retroactively.
Want the full live breakdown, signal by signal? See the methodology page.