Plain language
What the words mean
This site talks about rubrics, criteria, scope and drift. Those are ordinary words in this trade and nowhere else, and a page that uses them without explaining them is a page written for the people who built it.
- Assessment
- One run of our checks against one application, on one day, covering what its owner said we could look at. Everything else on this site is either something that leads to an assessment or something that comes out of one.
- Rubric
- The list of things we check, and how much each one counts towards the score. We publish it in full and it has version numbers, so you can see exactly what an application was measured against and when that changed.
- Criterion
- One item on that list. "Does the sign-in form work" is a criterion. Each one has an identifier such as SEC-02, so a finding can point at the thing it failed rather than at a general area.
- Criteria
- More than one criterion. The word has an awkward plural and that is all it means.
- Scope
- What the owner of an application allowed us to open, and nothing beyond it. If a part of an application was not in scope, we do not test it and the report says so rather than leaving you to assume it passed.
- Authorisation
- Proof that the person asking for an assessment is entitled to allow one. Nothing is opened until it exists, because testing software you do not own is not something a company should do for a fee.
- Evidence
- What we kept to show a finding is real: a screenshot, a recorded request, a page as it was at the time. A finding with no evidence never reaches a report, however confident anything was about it.
- Finding
- One thing we found, written down with what it was, where, how sure we are, and what to do about it. A report is mostly a list of these.
- Badge
- The mark an application can show on its own site once it has passed. It is served from us every time somebody loads it, which is how it can be taken down the moment it stops being true.
- Drift
- An application changing after it was assessed, in a way that affects what the badge stands on. We re-check on a schedule, and a badge is suspended when what earned it is no longer there.
- Remediation
- Fixing what an assessment found. We sell help with it, and we say plainly that a company which rates applications and also sells repairs has a reason to find more to repair.
- Methodology
- How we work something out, written down so you can check it. Our rating methodology page is the rubric plus the arithmetic that turns findings into a score.
- Point-in-time
- True on the day it was measured and not a promise about tomorrow. An application assessed in March can be different in April, which is why every badge carries a date and an expiry.
- Provenance
- Where something came from and how you can tell. A badge carries a signature that proves it came from us, so a picture of one copied from somebody else does not verify.
- Attestation
- A statement that something was checked, by someone willing to be named for it. A badge is one. It is not the same as a promise that nothing is wrong.
- Deterministic
- Gives the same answer every time it is run on the same thing. Some of our checks are like this and some involve a language model, which is not, and the report says which was which.
- Heuristic
- A rule of thumb that is usually right rather than always right. Where we use one, we say so and we say how sure we are, because a rule of thumb reported as a fact is how a report becomes untrustworthy.
- Canonical
- The one official version of something, written in one agreed way so that two copies can be compared. We use it about the rubric: the same rubric written out in the same order every time, so its fingerprint can be checked.
- Idempotent
- Doing it twice has the same result as doing it once. Running something idempotent again changes nothing, which is what you want from anything that might stop halfway through.
- Taxonomy
- A way of sorting things into named groups. Ours sorts findings into areas such as security, privacy and how usable an application is.
A word that sent you here and is not on the list
That is a fault on our side rather than yours. The list is meant to hold every word on this site that is not ordinary English, and a gap in it means a page is using a word we never explained. Our contact details are here.