How We Test Security Products
Tested means a signed record with scope, date, environment and limits. Templates and score chrome alone never imply hands-on work.
Scope beats hour counts
We do not invent testing hours, malware sample theatre or detection percentages for marketing. Hands-on language publishes only with a signed test record. Vendor stats stay labeled as vendor claims.
Testing process
Six stages from research to updates. Hands-on steps publish only with a record.
-
Research
Identify products, features and claims that need verification.
-
Product setup
Install, configure and prepare environments for the scoped scenario.
-
Hands-on testing
Run approved scenarios only after a signed record is filed.
-
Evidence review
Separate vendor claims, independent sources and our own records.
-
Scoring
Apply category rubrics only when evidence clears; otherwise leave scores unassigned.
-
Ongoing updates
Re-check volatile prices and retire unsupported tested language promptly.
What “tested” means here
On SecurityCheckli.st, “tested” means a signed test record exists for the scenario described. The record states scope, date, environment and limitations. Score rings, comparison tables and shield graphics alone never imply hands-on work.
This page is the hands-on companion to Review methodology, which covers how pages are structured, sourced and disclosed.
Category criteria we prepare for
Illustrative criterion weights show relative importance inside a category. They are structure, not published product scores.
- Data removal - broker coverage, removal success, time to removal, transparency, data handling. See best data removal services.
- Password managers - security model, passkeys and MFA, autofill, sharing and recovery, platforms. See best password managers.
- Antivirus - malware protection, web and phishing shields, performance impact, cleanup, support. See best antivirus software.
- Identity protection - breach monitoring, alert quality, recovery support, coverage scope, pricing clarity. See best identity theft protection.
Environments we plan around
When a signed record exists, it names the environment used for that scenario. Planned coverage includes common consumer platforms rather than every device on earth:
- Devices: Windows 11, macOS, Android, iOS
- Browsers: Chrome, Firefox, Edge, Safari
- Networks: home Wi-Fi, public Wi-Fi, VPN path checks where relevant
- Regions commonly referenced in pricing and availability notes: US, UK, Canada, EU, Australia
Evidence types
| Source type | What it is | When we publish from it |
|---|---|---|
| Hands-on test | Signed scenario with scope, date, environment, limitations | Required before “we tested” wording |
| Vendor documentation | Official plan, feature or pricing pages | Attributed as vendor claim with access date |
| Public record | Independent reporting or regulatory filings | Cited with limitations |
| Third-party lab | External detection or privacy studies | Named study and date; never re-labelled as ours |
What we will not claim
- Invented hours-tested counts or malware sample theatre
- Detection percentages without a named, dated source
- Vendor marketing restated as our independent lab result
- Hands-on language implied by empty score chrome alone
Products, tools and next steps
Launch-set consumer research spans privacy, passwords and antivirus clusters, with VPN coverage and SecShield as the SecurityCheckli.st VPN privacy product. Cross-category navigation starts at best security products.
Organisation buyers should use Business Security rather than consumer shortlists. Interactive privacy and fit tools live under tools, including the Personal Security Checkup.
Challenge unsupported testing language
Send sourced challenges via Corrections or Contact. Security vulnerabilities for our own systems go to Security disclosure. Role-based attribution (not fabricated bios) is described on Experts.
Limitations
- This page explains testing rules; it is not a shopping list or live lab dashboard.
- Sample “example record” layouts elsewhere on the site are format illustrations only when labeled as such.
- Anyone mid-compromise needs bank, platform or local-authority help, not a deal-link click.
Testing FAQ
When can a page say we tested a product?
Do you publish hours-tested or malware sample counts?
Why do many pages show scores not assigned?
How should I use the site while scores are unassigned?
Related standards
Prefer a practical next step?
Run the checkup, then open the category that matches your leftover job.
Page information & sources
About this page
What SecurityCheckli.st means by tested: signed records with scope and limits, labeled vendor claims, and no invented lab scores or hour counts.
Publication history
First published:
Last updated:
Corrections
Commercial disclosure
Some product links may be commercial. Affiliate relationships never set rankings. See the affiliate disclosure.