Review Methodology

Evidence rules, scoring structure, and update policy behind every Security Checklist recommendation.

Illustration of an SC Labs workspace with laptop, microscope, and security shield
  • 100% IndependentNo sponsorships or paid placements decide scores.
  • Hands-On TestingReal tools in controlled environments, only when a signed record exists.
  • Transparent Scoring ModelIllustrative 100-point category weights; live product scores stay N/Pub until verified.
  • Scheduled Re-checksPrices, plans, and claims are re-verified on a cadence, not invented for freshness.

Process

Our testing process

Six stages from research to ongoing updates. Hands-on steps only publish when a signed test record exists.

  1. 1

    Research

    Identify products, features, and claims to verify.

  2. 2

    Product Setup

    Install, configure, and prepare test environments.

  3. 3

    Hands-On Testing

    Run real-world scenarios when a signed record is approved.

  4. 4

    Evidence Review

    Verify results and collect supporting evidence.

  5. 5

    Scoring

    Score across categories and calculate published results.

  6. 6

    Ongoing Updates

    Monitor changes, re-test, and update ratings.

Criteria

What we test

Category criteria and illustrative weights. Full criteria pages stay claim-safe until product scores are verified.

Data Removal
  • Broker coverage25
  • Removal success rate25
  • Time to removal20
  • Transparency & support15
  • Privacy & data handling15

25% of total score · illustrative criterion weights

See related criteria →
Password Managers
  • Security & encryption30
  • Passkeys & MFA support20
  • Autofill accuracy20
  • Sharing & recovery15
  • Usability & platforms15

25% of total score · illustrative criterion weights

See related criteria →
Antivirus
  • Malware protection30
  • Web & phishing shields20
  • Performance impact20
  • Cleanup tools15
  • Usability & support15

25% of total score · illustrative criterion weights

See related criteria →
Identity Protection
  • Breach monitoring25
  • Alert quality20
  • Recovery support20
  • Coverage scope20
  • Transparency & pricing clarity15

25% of total score · illustrative criterion weights

See related criteria →

Weights reflect relative importance within a category and are shown here as structure, not as published product scores.

Lab setup

Our testing environments

Devices

  • Windows 11
  • macOS
  • Android
  • iOS

Browsers

  • Chrome
  • Firefox
  • Edge
  • Safari

Networks

  • Home Wi-Fi
  • Public Wi-Fi
  • VPN path checks

Regions

  • US
  • UK
  • Canada
  • EU
  • Australia

Evidence

Evidence & claim ledger

Material claims need a source type, description, and verification state. This table shows the ledger format, not a live product dossier.

Source typeDescriptionEvidenceAccess dateVerified
Hands-on testSigned scenario with scope, date, environment, limitationsTest record (when approved)Per recordRequired before “we tested”
Vendor documentationOfficial plan, feature, or pricing pagesClaim ledger citationCaptured on verify dateAttributed as vendor claim
Public recordIndependent reporting or regulatory filingsLinked sourceCaptured on verify dateCited with limitations
Third-party labExternal detection or privacy studiesNamed study + dateStudy publication dateNever re-labeled as ours

Scoring

Our scoring system

100

points

  • Data Removal 25%
  • Password Managers 25%
  • Antivirus 25%
  • Identity Protection 25%

Equal cluster weights shown for structure. Live pages publish scores only after verification.

Score calculation

  • Criteria scored on a defined rubric within each category.
  • Category totals roll up using documented weights.
  • Overall scores stay unpublished until claim ledgers and (when claimed) test records clear.
  • Free remedies are presented before paid recommendations on commercial pages.

Editorial

Editorial policies

Untested products

We never imply hands-on testing without a signed test record.

Unavailable features

Marketing pages are not treated as verified capability.

Vendor assertions as ours

Vendor stats stay labeled as vendor claims until independently verified.

Editorial independence

Affiliate payout cannot determine score or recommendation order.

Affiliate separation

Commercial links go through first-party tracking with visible disclosure.

Conflict policy

Material conflicts are disclosed; unfinished AI copy is not published.

Updates

Updates & corrections

Price verification

Plan names and starting prices are re-checked before publication when ledgers require it.

Update cadence

Material product changes trigger review of affected pages and claims.

Corrections

Reader challenges route to our corrections process once live.

Reader reports

Send evidence gaps or errors, we prioritize claim-safe fixes over speed theater.

Illustrative example, sample format only

Example test record UI

“SecureShield” below is a fictional sample product used only to show record layout. It is not a Security Checklist finding.

SecureShield Antivirus

Sample format · not a live test record

EXAMPLE ONLY

Test summary

  • Scope: illustrative fields only
  • Environment: sample lab chrome
  • Status: unpublished / not verified

Evidence slots

  • Artifacts attach only after a signed test record is filed
  • Limitations come from the published test protocol
  • Checked date is set when evidence is recorded

Overall score

N/Pub

Real products stay unpublished until verification clears.

Quality

Quality gates

  • Claim ledger completeness for material facts
  • No unfinished AI copy on publishable pages
  • Free remedies before paid recommendations
  • Who-should-not-buy stated on commercial pages
  • Accessibility and metadata gates for publishable routes
  • Portal preview stays noindex until production cutover

Sign-off format

Latest sign-offs

Role titles only for now, no invented reviewer identities or headshots. Named roster publishes with verified bios.

  • Lead reviewer (role)Page claim audit · Format example
  • Methodology editor (role)Test-record gate · Format example
  • Corrections owner (role)Reader challenge intake · Format example

Methodology FAQ

Want launch updates?

The email newsletter is not running yet. Use Contact if you want a human reply when it opens. No fake signup form.