Methodology
How the Trust Index collects, verifies, and corrects its data.
What the Trust Index measures
The Trust Index catalogs the publicly advertised security and compliance posture of companies that maintain a public compliance footprint. It reports what organizations say about themselves in public: trust center pages and security.txt files. It does not audit companies, review private reports, or assess whether controls actually operate.
What our language means
- "Publicly advertises" means the claim appeared on the organization’s public trust center on the observation date shown.
- A missing framework means no public claim was observed. It never means an organization is non-compliant. Many compliant companies simply do not publish their posture.
- HIPAA entries reflect a public claim of compliance. No HIPAA certification exists; HIPAA compliance is self-attested.
- "First observed" dates come from public web archives and reflect the earliest capture we found. Archive coverage is incomplete, so pages may have existed earlier.
How data is collected
Companies enter the index when a public trust center is discovered on their domain
(for example trust.example.com), confirmed by DNS and page content.
Framework claims are extracted from the trust center itself. Identity details
(founding year, industry, external profiles) come from open sources such as Wikidata.
Hiring signals come from the organization’s own public job board. Every data
point carries the date it was observed.
Corrections and claims
Corrections are welcome and are verified against public evidence before publication: use the correction form, citing the public page that shows the corrected value. Claims of compliance that are not publicly verifiable are not published; the fastest way to update your profile is to publish the claim on your trust center, and the next refresh will pick it up.
About this dataset
Profiles refresh monthly from an automated pipeline; corrections deploy when they are verified and merged. Coverage and enrichment expand with each refresh.