FAQ
Frequently asked questions
How scoring works, what a missing certification means, how to claim a profile, and how Entropy handles data. For the full scoring rubric see the methodology page; for Entropy's own security posture see the trust center.
Scoring & methodology
How does Entropy score a vendor?
Every vendor is scored against a versioned rubric across five categories — security hygiene & transparency, AI safety practices, governance, incident history, and a verification bonus. The baseline grade is computed only from publicly observable signals (a vendor's security.txt, HTTPS and HSTS configuration, published disclosure policy, security headers, discovered certifications, and more) — never from vendor self-reporting or marketing copy. The full breakdown is on the methodology page.
What do the letter grades mean?
Grades run on a 13-band scale from A+ to F. They are computed against implemented signals only — the denominator is what Entropy can currently measure, not the entire planned rubric — so a vendor is never marked down for signals that haven't been built yet. The exact percentage bands are listed on the methodology page.
Can a vendor pay to raise its grade?
No. A vendor can claim its profile and upload supporting evidence, and that earns a capped verification bonus — a few points for proving domain ownership, a few more for putting at least one document on file. Those points are bonus-only: they can lift a score but never lower one, and the baseline grade stands on the automated signals with or without a vendor's cooperation. There is no way to buy a better automated score.
How often are scores updated?
Entropy re-scans every vendor on a weekly cycle. When a vendor claims its profile or changes its uploaded evidence, the verification-bonus and governance portions of its score are recomputed within minutes rather than waiting for the weekly pass.
Why did a vendor’s grade change?
Usually one of three reasons: Entropy added a new signal (which grows the denominator and makes every score more precise), a weekly re-scan picked up a new practice or a newly published certification, or a vendor claimed its profile or changed its evidence. Every score records the rubric version it was computed against, and each profile has a score changelog showing what moved and when.
Certifications
A vendor I’m evaluating has no SOC 2 — is that a red flag?
Not on its own. A SOC 2 report takes months of evidence collection over a defined audit window, so a genuinely well-run early-stage company often just hasn't completed one yet. HIPAA only applies to organizations that handle protected health information, and ISO 27001 / ISO 42001 have their own scoping. A missing certification is a reason to ask why it's missing, not an automatic disqualifier. The methodology page explains how to read a certification gap in context.
How does Entropy know whether a vendor holds a certification?
Only through independent confirmation — never from a vendor's own trust-page prose alone. If Entropy's scanner finds a certification named on a vendor's public trust page, that's flagged for an Entropy admin to independently check against a real registry or the issuing firm directly; confirmed, it earns partial credit. If a vendor claims its profile and uploads the actual report, and an Entropy administrator reviews that document, the certification earns full credit. A trust-page mention that hasn't been independently confirmed earns nothing on its own. Anyone can report a certification that looks wrong using the button on the vendor's profile.
Does Entropy audit these certifications itself?
No. Entropy is not an auditor. It reviews an uploaded document for authenticity and scope before granting full credit, and it labels anything found only on a public trust page as “publicly attested, unverified.” The underlying audit is always performed by an accredited third party, not by Entropy.
Claiming a profile
How do I claim my company’s profile?
Create an account, open your company's profile, and choose “Claim this profile.” You prove domain ownership by adding a DNS TXT record at _entropy-verify.{yourdomain}; once Entropy's verification check sees it, the profile is marked claimed and linked to your account. Claims on a short list of high-profile domains are held for manual review before they're finalized. Claiming and verifying a profile is a Vendor-plan feature, and paid plans are not yet active, so it isn't generally available yet.
What can I do once my profile is claimed?
Edit your profile details, upload supporting evidence (SOC 2 reports, ISO certificates, model cards), enroll in multi-factor authentication, generate an embeddable “Entropy Verified” badge, respond publicly to reviews of your company, and dispute a specific finding you believe is wrong.
Does claiming my profile change my grade?
The baseline grade doesn't change — it's computed the same way whether or not a profile is claimed. Claiming adds the capped verification bonus, and any evidence you upload can earn governance credit once an Entropy administrator has reviewed it. Nothing about claiming can reduce a score.
Billing & plans
Is Entropy free to use?
Browsing the directory, viewing every public score, comparing vendors, keeping a watchlist, and rating vendors are all free. Entropy also publishes paid Vendor and Buyer Pro plans on the pricing page; paid plans are not yet active.
What’s included in the paid plans?
The Vendor plan covers profile claiming and editing, evidence upload, the embeddable verified badge, review responses, and watcher updates. Buyer Pro adds an unlimited watchlist, score-drop email alerts, a team shared watchlist, and priority support. The public API is not currently available on any plan. The pricing page has the full comparison.
How do I sign up for a paid plan or manage my subscription?
Paid plans aren't active yet, so the plan cards on the pricing page currently read “Coming soon.” Once billing is live, you'll choose a plan there and manage it — including cancellation — from the billing page in your account, through Stripe's hosted customer portal.
Privacy & data handling
Where is Entropy’s data stored?
In Google Cloud (Firestore and Cloud Storage), in the United States. Uploaded evidence files are encrypted at rest and access-controlled by Firestore security rules.
Can other users see the evidence documents I upload?
No. Uploaded certificates and audit reports are readable only by the vendor account that uploaded them and the Entropy administrators reviewing a claim. A public profile shows only that a document is on file — never the document itself.
Does Entropy use my data to train AI models?
No. Vendor scores are computed from publicly observable signals — not from account data, uploaded evidence, or the private notes you keep on profiles.
How do I report a security vulnerability in Entropy?
Email security@entropy.com. Full scope and our response commitments are on the vulnerability disclosure page, and the machine-readable version is at /.well-known/security.txt.
Does Entropy use cookies or track me?
Entropy sets one necessary cookie, which only stores your cookie choice itself. Anonymized, cookieless page-view analytics load only if you opt in. Entropy never uses cookies for advertising or cross-site tracking. See the privacy policy for detail.
How do I delete my account and data?
Email security@entropy.com or write to the postal address in the privacy policy. Company score data is derived from public signals and isn't treated as personal data, so it stays in the directory.
Who does Entropy share data with?
Only the subprocessors listed on the trust center — the infrastructure, payment, and email vendors that run the service. Entropy does not sell personal data or share it with third parties for advertising.