Skip to content
← Home

Methodology

How Entropy scores vendors

Every vendor in the directory is scored against a versioned rubric across five categories. Scores are computed from publicly observable signals — no vendor self-reporting, no marketing copy. Grades reflect what can actually be verified.

What these signals measure

Entropy measures observable security hygiene and organizational transparency practices — not the internal code of an AI product. This is a deliberate and defensible choice.

Security researchers have long recognized that observable practices are meaningful proxies for security culture. Companies that implement responsible disclosure programs, maintain credential hygiene, and publish security transparency artifacts are demonstrably more likely to invest in the security practices CISOs can't directly audit: secure development processes, internal access controls, and incident response maturity.

The automated signals are the first layer. The full rubric — AI safety transparency, governance certifications, and verified incident history — requires vendor participation via profile claiming and evidence upload. That's where the deeper picture comes from.

Key principle

Grades are computed against implemented signals only. As new signals are added, the denominator grows and scores become more precise. A company scoring 18/28 today — some of the automated signals in place, others not — shows B-, not F, because the comparison is honest about what has been measured.

Grade scale

Thresholds are calibrated for automated-signal scoring — "F" means genuinely poor security hygiene, not just "below average on partial data." As more signals are added, thresholds will be reviewed and published with the rubric version.

A+≥ 95%
A≥ 87%
A−≥ 80%
B+≥ 73%
B≥ 67%
B−≥ 60%
C+≥ 54%
C≥ 48%
C−≥ 42%
D+≥ 36%
D≥ 30%
D−≥ 24%
F< 24%

Verified potential score

Every company profile shows a current grade (automated scan only) and a potential grade (what they could achieve by claiming their profile).

The Verification Bonus category is worth up to +5 pts5pts for confirming domain ownership. This is a bonus point: it lifts the score but not the grade denominator, so an unclaimed vendor is never penalised. It gives vendors a clear, actionable path to improve their grade without waiting for automated signals to detect new practices, and it applies within minutes of a claim.

Category benchmark

Each profile shows a relative benchmark — "Top 23% of AI vendors measured" — alongside the absolute grade.

This tells you where a vendor sits relative to their peers in the same category, independent of the absolute grade scale. It's a useful signal for procurement decisions: even if most vendors in a category score D+, knowing which one scores in the top 10% is actionable information.

Scoring categories

Security hygiene & transparency

35 pts max · 28 live

Observable security practices on the vendor's public domain. These are proven proxies for organizational security culture — not direct audits of product code. Companies that implement responsible disclosure, security headers, and maintain credential hygiene demonstrate security-aware culture at the organizational level.

+5pts
security.txtValid file at /.well-known/security.txt with Contact, Expires, and Encryption fields.
+5pts
HTTPS + HSTSHTTP redirects to HTTPS; Strict-Transport-Security header enforced.
+8pts
Security headersContent-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy.
+5pts
Disclosure policyPublic security/vulnerability disclosure page with relevant contact information.
+5pts
Trust pageA public trust/security page exists. Scored on existence only — what it says is never scored (see the Governance section above).
soon
CVE exposureKnown CVE exposure in public-facing software and libraries.

AI safety practices

25 pts max · 0 live

Whether the vendor publishes meaningful transparency artifacts about their models — not marketing copy.

soon
Model cardsPublished model cards for production models covering limitations, intended use, and bias evaluation.
soon
Training data disclosureDocumentation of training data sources, licensing, and consent practices.
soon
Red-team resultsPublished results from adversarial testing or independent red-team exercises.

Governance

31 pts max · bonus

Certifications and organizational structures that demonstrate institutionalized security — not just one engineer caring. Every certification signal here is bonus-only: a verified one raises the score, but a missing one never lowers a grade, because the market is still early on independent verification and we won't penalise a company for a gap it may have good reasons for. Credit is only ever earned two ways: an Entropy admin has reviewed the underlying document — after a claimed vendor uploads the actual report — which earns full points, or an Entropy admin has independently confirmed the certification against a real registry or the issuing firm, which earns partial credit. A certification named on a vendor's own public trust page but not independently confirmed earns nothing on its own — Entropy no longer scores trust-page content directly, since a page's own prose isn't verifiable from the page alone. Uploading a document by itself earns no points either — full credit requires admin review — and anyone can flag a certification that looks wrong.

+10pts
SOC 2 Type IIFull credit once a claimed vendor uploads the report and an Entropy admin reviews it, or partial credit once an admin independently confirms it directly with the issuing firm. A mention on the vendor's public trust page alone earns nothing.
+3pts
SOC 2 Type IScored separately from, and lower than, Type II — a point-in-time design assessment rather than a sustained-period operating-effectiveness audit.
+5pts
ISO 27001Full credit once a claimed vendor uploads the certificate and an Entropy admin reviews it, or partial credit once an admin independently confirms it against a real accreditation-body registry. A mention on the vendor's public trust page alone earns nothing.
+5pts
ISO 42001AI management system certification, scored the same way as ISO 27001 — a trust-page mention alone earns nothing; admin verification or a reviewed upload does.
+3pts
HIPAACompliance attestation for vendors handling health data; narrower applicability than the other governance signals, so weighted lower.
soon
Board-level oversightBoard committee or C-level executive with explicit security/AI-safety accountability.

Incident history

15 pts max · 0 live

How a company has handled security incidents says more than any certification. Response quality matters as much as frequency.

soon
Breach historyNo major data breaches in the past 24 months involving customer data.
soon
Response qualityTimely, transparent, and complete public disclosure of past incidents.

Verification bonus

5 pts max · bonus

Bonus points for vendor engagement that can't be automated: verifying domain ownership by claiming the profile. Bonus-only — it can raise a grade but never lower one — and it applies within minutes of a claim, not just on the weekly rescan.

+5pts
Claimed profileVendor has verified domain ownership and claimed their Entropy profile.

Reading a certification gap

Why doesn't every vendor have every certification?

A vendor with a missing certification isn't automatically a weaker choice. Certifications differ in what they cover, how long they take to earn, and who they even apply to — so the same blank entry can mean very different things depending on the standard.

SOC 2. An independent auditor's report on a company's security controls. The Type II report most enterprise buyers ask for assesses how controls operated over an observation window of several months to a year, so it can't be produced on demand: published industry breakdowns put the end-to-end effort at roughly 6–12 months or more, with audit costs that run into the tens of thousands and up depending on company size and auditor (Drata, Secureframe). A company that is a couple of years old and sells mostly to small businesses may simply not have reached the point where a customer required one. The learn guide covers this in more detail.

HIPAA. A U.S. law rather than a certification. Its Privacy and Security Rules bind “covered entities” — health plans, most healthcare providers, and clearinghouses — and the business associates that handle protected health information on their behalf (HHS.gov). A vendor that never touches health data has no obligation under HIPAA and no reason to seek an attestation, so its absence on a general-purpose tool is expected rather than a gap.

ISO 27001. The international standard for information security management systems. Certification is an audited process that takes months to reach and is renewed on a three-year cycle with annual surveillance audits. It is most common among companies selling into large enterprises or European markets, where it is frequently contractually required; a capable vendor whose buyers don't ask for it often hasn't pursued it (ISO).

ISO 42001. The international standard for AI management systems, published in December 2023 (ISO). It is newer than the others by years, and the number of certified organizations is still very small. For now, its absence tells you little; its presence is a strong early signal.

Entropy grades against implemented signals only, and its rubric separates holding a certification from disclosing honestly. A vendor with no SOC 2 but a clear privacy policy and disclosed subprocessors can score better than one with neither. A governance score reflects silence and evasion — not a young company still working toward an audit. See reading your own Entropy score and the Governance category above.

Rubric versioning

Every score document records the rubric version it was computed against. This means historical scores remain comparable even as the rubric evolves — you can always know whether a score was computed before or after a methodology change. The current rubric is v1.3.0. Grade thresholds are also versioned — changes to thresholds are announced with the rubric version and applied only to new scans, not retroactively.