Skip to main content

New in August: Password manager research and finders updated Read more

Independent reviews. Real tests. Smarter security decisions.

SecurityChecklist

How We Test Security Products

Tested means a signed record with scope, date, environment and limits. Templates and score chrome alone never imply hands-on work.

Scope beats hour counts

We do not invent testing hours, malware sample theatre or detection percentages for marketing. Hands-on language publishes only with a signed test record. Vendor stats stay labeled as vendor claims.

Testing process

Six stages from research to updates. Hands-on steps publish only with a record.

  1. Research

    Identify products, features and claims that need verification.

  2. Product setup

    Install, configure and prepare environments for the scoped scenario.

  3. Hands-on testing

    Run approved scenarios only after a signed record is filed.

  4. Evidence review

    Separate vendor claims, independent sources and our own records.

  5. Scoring

    Apply category rubrics only when evidence clears; otherwise leave scores unassigned.

  6. Ongoing updates

    Re-check volatile prices and retire unsupported tested language promptly.

What “tested” means here

On SecurityCheckli.st, “tested” means a signed test record exists for the scenario described. The record states scope, date, environment and limitations. Score rings, comparison tables and shield graphics alone never imply hands-on work.

This page is the hands-on companion to Review methodology, which covers how pages are structured, sourced and disclosed.

Category criteria we prepare for

Illustrative criterion weights show relative importance inside a category. They are structure, not published product scores.

  • Data removal - broker coverage, removal success, time to removal, transparency, data handling. See best data removal services.
  • Password managers - security model, passkeys and MFA, autofill, sharing and recovery, platforms. See best password managers.
  • Antivirus - malware protection, web and phishing shields, performance impact, cleanup, support. See best antivirus software.
  • Identity protection - breach monitoring, alert quality, recovery support, coverage scope, pricing clarity. See best identity theft protection.

Environments we plan around

When a signed record exists, it names the environment used for that scenario. Planned coverage includes common consumer platforms rather than every device on earth:

  • Devices: Windows 11, macOS, Android, iOS
  • Browsers: Chrome, Firefox, Edge, Safari
  • Networks: home Wi-Fi, public Wi-Fi, VPN path checks where relevant
  • Regions commonly referenced in pricing and availability notes: US, UK, Canada, EU, Australia

Evidence types

Source type What it is When we publish from it
Hands-on test Signed scenario with scope, date, environment, limitations Required before “we tested” wording
Vendor documentation Official plan, feature or pricing pages Attributed as vendor claim with access date
Public record Independent reporting or regulatory filings Cited with limitations
Third-party lab External detection or privacy studies Named study and date; never re-labelled as ours

What we will not claim

  • Invented hours-tested counts or malware sample theatre
  • Detection percentages without a named, dated source
  • Vendor marketing restated as our independent lab result
  • Hands-on language implied by empty score chrome alone

Products, tools and next steps

Launch-set consumer research spans privacy, passwords and antivirus clusters, with VPN coverage and SecShield as the SecurityCheckli.st VPN privacy product. Cross-category navigation starts at best security products.

Organisation buyers should use Business Security rather than consumer shortlists. Interactive privacy and fit tools live under tools, including the Personal Security Checkup.

Challenge unsupported testing language

Send sourced challenges via Corrections or Contact. Security vulnerabilities for our own systems go to Security disclosure. Role-based attribution (not fabricated bios) is described on Experts.

Limitations

  • This page explains testing rules; it is not a shopping list or live lab dashboard.
  • Sample “example record” layouts elsewhere on the site are format illustrations only when labeled as such.
  • Anyone mid-compromise needs bank, platform or local-authority help, not a deal-link click.

Testing FAQ

When can a page say we tested a product?
Only when a signed test record exists for the scenario described: scope, date, environment and limitations. Templates and score chrome alone never imply testing.
Do you publish hours-tested or malware sample counts?
No. When a signed record exists, we publish scoped outcomes and limits, not marketing hour counts or sample theatre.
Why do many pages show scores not assigned?
Overall scores remain unassigned until verification clears. That is intentional claim safety.
How should I use the site while scores are unassigned?
Start with free controls and the Personal Security Checkup. Treat paid shortlists as optional after those remedies. Re-check prices at vendor checkout.

Prefer a practical next step?

Run the checkup, then open the category that matches your leftover job.

Page information & sources Updated 2026-08-17

About this page

What SecurityCheckli.st means by tested: signed records with scope and limits, labeled vendor claims, and no invented lab scores or hour counts.

Methodology

Editorial responsibility

Published by SecurityChecklist editorial

Editorial policy

Publication history

First published:

Last updated:

Corrections

Request a correction

Commercial disclosure

Some product links may be commercial. Affiliate relationships never set rankings. See the affiliate disclosure.