Method · v1.1 · 2026-08-31
The score is a measure of evidence, not a verdict on software.
Everything here is published so you can check our work, disagree with it, or apply your own weighting. If the rubric and a score disagree, the rubric wins and we have a correction to make.
What the score is
The Public-Evidence Fit & Exit Score describes the amount and quality of public evidence we reviewed about a platform on a stated date. That is the whole claim. It is not a security rating, a solvency score, a recommendation, or a prediction about any company’s future.
A vendor can build excellent software and still score in the middle here, because scoring rewards documenting things publicly. A quiet social account, a small audience, or the absence of a public SOC 2 report is not treated as proof that a company is poor, unsafe, or unable to perform.
The one sentence version
A high score means a buyer can find answers without asking. A low score means you will have to ask — so we tell you exactly what to ask.
The 100-point rubric
Seven dimensions, 100 points. Every profile shows its points against these maximums so the arithmetic is checkable.
Within Security, privacy & exit, the 18 points split into third-party assurance evidence (8), privacy and governance evidence (5), and practical data-exit evidence (5).
Assurance evidence tiers
Security claims are the easiest thing on a directory to get wrong, so the tiers are explicit. A self-assessment and an independent attestation never receive the same label or the same points.
| Pts | Evidence level | Label used on the site |
|---|---|---|
| 8 | Current, scope-relevant third-party certification or attestation, verified from an authoritative registry or certificate | Third-party assurance verified |
| 5–6 | A public trust center gives current, specific assurance status and controlled access to artifacts; the underlying report is not reviewed | Trust-center assurance documented |
| 3–4 | A CSA STAR Level 1 CAIQ or equivalent public control self-assessment is located | Public security self-assessment located |
| 1–2 | Detailed vendor controls, a DPA, or a security page, without independent assurance proof | Vendor security controls documented |
| 0 | No qualifying material found in reviewed public sources | Third-party assurance not located in reviewed public sources |
Rules we hold ourselves to
- We never call a vendor “SOC 2 compliant” unless the exact claim, scope, type, and period are confirmed.
- CSA STAR Level 1 is a provider-submitted self-assessment. Level 2 involves third-party attestation. They are labelled differently, always.
- We write “no matching listing was located under the searched name,” never “the vendor is not certified.” We can only report what we found.
Source classes
Every source on a profile carries a class, in descending evidentiary weight.
- ALegal, regulatory, product, or registry material. Terms of service, privacy policies, DPAs, company registry filings, court and regulator records.
- BVendor-published support or product material. Pricing pages, help documentation, security pages, official announcements.
- CIndependent review platform or community source. G2, Capterra, Software Advice, app stores, Trustpilot, and public community discussion.
Ratings are always shown with their review count. We do not host reviews, and we never convert review sentiment into a security or exit-readiness claim.
Grades and evidence confidence
Two separate labels do two separate jobs, and they should not be collapsed.
The grade summarises the documented score. The evidence confidence label — High, Moderate, or Low — describes how complete and consistent our research file is. It says nothing about vendor quality.
- A85–100 · Extensively documented
Most buyer questions are answerable from public sources. - B70–84 · Well documented
Strong public record with identifiable gaps. - C55–69 · Partly documented
Real gaps; expect to ask for terms in writing. - DBelow 55 · Thinly documented
Little is answerable without contacting the vendor. - IEInsufficient public evidence
Where our confidence is Low we publish no letter grade at all. A company with almost no public record has not earned a bad grade; it simply has not been documented, and those two things must never look the same.
The exit checklist
This is the part contractors most often discover too late. Before you sign, ask for a real export and confirm each line below in writing. A vendor with nothing to hide will find this a boring conversation.
- Every customer record, with contact history and notes
- Every job, work order, and its status history
- Estimates, invoices, payments, and credits, reconcilable to your accounting system
- Photos and file attachments, at original resolution, with the job they belong to
- Time entries, crew assignments, and payroll-relevant records
- The export format, and whether it re-imports into another system without manual repair
- How many days after termination you keep access to run the export
- What it costs, if anything, and how long the vendor takes to produce it
- When your data is deleted afterwards, and whether that includes backups
One practical test
Ask for a sample export from a demo account before your data is inside the system. What arrives tells you more than any policy page will.
Limits and cautions
- This is a snapshot. Every finding is tied to 2026-08-31. Vendors publish new terms, earn certifications, and change pricing. Check the vendor’s current material before deciding.
- Not-found is not absent. Where a profile says something was not verified, we looked in public sources and did not find it. Many of those things exist and simply are not published.
- 10 platforms is not the whole market. This directory covers the platforms we have researched, not every option worth considering.
- Ranking is not endorsement. Order reflects the depth of the public record under our method. The best-fitting product for your trade, size, and workflow may sit lower on this list.
- We are not your advisor. Nothing here is legal, security, financial, or procurement advice.
Found something wrong? Tell us and we will fix it. Our editorial policy covers independence, and our disclosures page lists every commercial relationship we have with a listed vendor.