Skip to content
← Security 101 for Founders

Learn

Reading your own Entropy score, and what to fix first

Your Entropy grade is a letter from A+ to F, computed from a versioned rubric across five categories: technical security, AI safety, governance, incident history, and a verification bonus. The full category weights and every individual signal are on the methodology page — this guide is about reading what you already have and deciding what to act on first. The point values below are pulled from the live rubric.

Your grade is computed against what's implemented, not the full rubric

Entropy's rubric is still growing — several signals (AI safety, incident history) are defined but not yet scored. Your grade is computed against the signals that are actually live today, not the full eventual rubric. That's the implemented max score concept: a company scoring 28 out of 28 currently-implemented technical-security points shows a strong grade, not a penalized one, just because more categories haven't shipped yet. Practically, this means two things worth knowing before you read too much into a specific number:

  • Your grade today reflects technical security and governance most heavily, since those are the categories with live signals.
  • As new signals ship, the denominator changes and grades get recalculated against a more complete picture — a grade isn't a permanent verdict, it's a snapshot against the current rubric version.

What's actually scored right now, and what isn't

Technical security (28 of 35 points implemented) is fully automated — Entropy checks your domain directly, no action required beyond fixing what's missing: security.txt (5 pts, checks for Contact, Expires, and Encryption fields), HTTPS + HSTS (5 pts), security headers — Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy (8 pts), a public disclosure policy page (5 pts), and a public trust/security page existing at all (5 pts — existence only, never what it says: see the governance paragraph below for why). These are the cheapest points to close if your grade is lower than you'd expect: they're standard web security hygiene, not something that requires a vendor relationship with Entropy at all.

Governance (0 of 31 points implemented) is earned only through independent verification, never from your public trust page's own prose: SOC 2 Type II (10 pts) and Type I (3 pts), ISO 27001 (5 pts), and ISO 42001 (5 pts), plus HIPAA (3 pts) for vendors handling health data. Every certification is scored as bonus points — they add to your score but aren't counted in the implemented denominator, which is why governance contributes nothing to the implemented total despite its 31-point cap. A verified certification can only raise your grade, never lower it. Credit here comes two ways: an Entropy admin independently confirms a certification against a real registry or the issuing firm directly, which earns partial credit, or you upload the actual report through your claimed profile and an Entropy admin reviews it, which earns full credit — and that lands within a few minutes of the review. A certification named on your own trust page that hasn't been independently confirmed earns nothing on its own, in either direction — Entropy doesn't score what a trust page merely claims. Anyone signed in can flag a certification that looks wrong from the profile, and an admin pulls the credit if it doesn't hold up.

AI safety and incident history are not yet scored at all — both categories are fully pending (model cards, training data disclosure, and red-team results for AI safety; breach history and incident response quality for incident history). If your grade looks capped by these categories, that's expected — there's nothing to fix here yet because nothing is being measured yet.

Claiming your profile

The verification bonus (5 points — 5 for confirming domain ownership via a DNS TXT check) is scored as of rubric v1.3.0. It's bonus-only: the points add to your score but not to the implemented denominator, so claiming can only raise your grade — an unclaimed vendor is never marked down for not having done it.

Credit lands within a few minutes of claiming, not just on the next weekly rescan. Uploading a document doesn't earn any bonus points on its own — an uploaded SOC 2 or ISO 27001 report is a self-attestation until an Entropy admin reviews it, at which point that certification's governance credit (a separate category from this bonus) moves to full. Other document types have no governance signal to upgrade.

Claiming also unlocks the non-scoring things — disputing a finding you think is wrong, editing your profile details, posting a public response to a review, and the embeddable Verified badge.

A suggested order, if you're starting from zero

  1. Fix any failing technical security checks — these are automated, binary, currently scored, and typically the fastest to close: security.txt fields, HSTS, the four security headers, a disclosure policy page.
  2. Check your category benchmark — each profile shows how your score in a category compares to other vendors in the same category, which is a useful signal for where you're already ahead versus where you're behind peers, not just behind a theoretical maximum.
  3. Claim your profile, then upload what you have — DNS-verifying your domain is 5 bonus points, applied within minutes; it can lift your grade but its absence never counts against you. Uploading a SOC 2 or ISO 27001 report doesn't earn points by itself, but it's what starts the admin review that can move that certification's governance credit to full. Claiming also lets you dispute findings and edit your profile.

For the full point-by-point rubric, including everything still pending, see the methodology page.