Review Methodology
How we structure product research, what evidence we require, and when we refuse to invent a score.
Structure before theatre
Free controls come first on commercial pages. Material claims need dated sources. Overall product scores publish only when category criteria and supporting research justify them. Affiliate payout never sets order.
How a page is built
Five editorial stages from research brief to update.
-
Frame the job
Define the reader problem, free remedies and who should not buy.
-
Gather sources
Separate vendor claims, independent sources and our own records.
-
Compare with category criteria
Use hub-appropriate rubrics without forcing a fake overall champion.
-
Disclose and limit
Place affiliate disclosure near commercial CTAs and state gaps plainly.
-
Revisit when plans change
Re-check volatile prices and retire unsupported claims promptly.
What this page covers
This methodology explains how SecurityCheckli.st structures public research: evidence standards, free-first commercial order, when scores appear, and how affiliate relationships stay separate from editorial decisions.
It is the page-structure companion to How we test, which covers hands-on testing language and lab-style claims. Together with the editorial policy, these pages define what readers should expect.
Evidence rules
Material claims need a source type, a description and a verification state. We separate:
- Vendor documentation - plan, feature or pricing pages, attributed as vendor claims
- Independent public records - reporting or regulatory filings cited with limitations
- Our hands-on records - only when a signed test record exists (see How we test)
- Third-party labs - named studies with dates; never re-labelled as ours
If a material claim cannot be sourced, it is not published. Empty or “not assigned” score chrome is intentional claim safety, not a missing widget.
Free remedies before paid recommendations
Commercial pages present free controls before paid shortlists: MFA on critical accounts, OS and browser updates, built-in malware baselines, credit freezes where available, and practical manual opt-outs when they still scale.
Paid products are optional next steps after those remedies. Pages state who should not buy when a commercial CTA appears.
Scoring philosophy
Category rubrics exist for data removal, password managers, antivirus and identity protection. Illustrative weights describe relative importance inside a category. They are not live product dossiers.
Overall scores publish only after dated sources and, when hands-on language is used, a signed test record clear editorial review. Until then, pages may still explain qualitative fit, platforms and verified starting prices without inventing a champion number.
Commercial independence
SecurityCheckli.st may earn compensation when you purchase through links on the site. That compensation does not change testing criteria, scores or recommendation order. Disclosures appear near commercial recommendations, not only in footers. Read the affiliate disclosure.
We do not invent coupons, fabricate scarcity, cloak destinations or publish hours-tested marketing theatre.
How tools fit
Interactive tools such as the Personal Security Checkup and category finders compute basic results in your browser from your answers. They present free remedies before paid notes, never ask for passwords or identity documents, and do not invent live scans or detection rates.
Tool fit figures are self-reported readiness estimates, not published editorial product scores. Browse all tools at /tools/.
Where research lives
- Data privacy - removal, brokers and identity protection
- Password managers - vaults for people and teams
- Antivirus - endpoint and suite research
- VPN - network privacy research
- Best security products - cross-category shortlist
- Business Security - organisation evaluation support
- SecShield - SecurityCheckli.st VPN privacy product
Corrections and accountability
Challenge stale prices, missing sources or unsupported testing language via Corrections or Contact. Security vulnerabilities go to Security disclosure. Named expert bios appear only when verified; see Experts.
Limitations
- This page does not publish finished product scores or detection rates.
- It is not emergency incident response, legal advice or procurement certification.
- Anyone mid-compromise should contact their bank, platform or local authorities as appropriate.
- Enterprise MDR/EDR and compliance attestations belong under Business Security workflows, not consumer shortlists.
Methodology FAQ
Do you publish product scores on every page?
Do affiliate commissions affect rankings?
How is this different from How we test?
Where should I start as a reader?
Related standards
Put the methodology to work
Start with a free checkup, then open the category that matches your leftover job.
Page information & sources
About this page
How SecurityCheckli.st structures reviews: evidence rules, free-first order, scoring only when verified, affiliate independence and clear limitations.
Publication history
First published:
Last updated:
Corrections
Commercial disclosure
Some product links may be commercial. Affiliate relationships never set rankings. See the affiliate disclosure.