Skip to content

Plain language

What the words mean

This site talks about rubrics, criteria, scope and drift. Those are ordinary words in this trade and nowhere else, and a page that uses them without explaining them is a page written for the people who built it.

Assessment
One run of our checks against one application, on one day, covering what its owner said we could look at. Everything else on this site is either something that leads to an assessment or something that comes out of one.
Rubric
The list of things we check, and how much each one counts towards the score. We publish it in full and it has version numbers, so you can see exactly what an application was measured against and when that changed.
Criterion
One item on that list. "Does the sign-in form work" is a criterion. Each one has an identifier such as SEC-02, so a finding can point at the thing it failed rather than at a general area.
Criteria
More than one criterion. The word has an awkward plural and that is all it means.
Scope
What the owner of an application allowed us to open, and nothing beyond it. If a part of an application was not in scope, we do not test it and the report says so rather than leaving you to assume it passed.
Authorisation
Proof that the person asking for an assessment is entitled to allow one. Nothing is opened until it exists, because testing software you do not own is not something a company should do for a fee.
Evidence
What we kept to show a finding is real: a screenshot, a recorded request, a page as it was at the time. A finding with no evidence never reaches a report, however confident anything was about it.
Finding
One thing we found, written down with what it was, where, how sure we are, and what to do about it. A report is mostly a list of these.
Badge
The mark an application can show on its own site once it has passed. It is served from us every time somebody loads it, which is how it can be taken down the moment it stops being true.
Drift
An application changing after it was assessed, in a way that affects what the badge stands on. We re-check on a schedule, and a badge is suspended when what earned it is no longer there.
Remediation
Fixing what an assessment found. We sell help with it, and we say plainly that a company which rates applications and also sells repairs has a reason to find more to repair.
Methodology
How we work something out, written down so you can check it. Our rating methodology page is the rubric plus the arithmetic that turns findings into a score.
Point-in-time
True on the day it was measured and not a promise about tomorrow. An application assessed in March can be different in April, which is why every badge carries a date and an expiry.
Provenance
Where something came from and how you can tell. A badge carries a signature that proves it came from us, so a picture of one copied from somebody else does not verify.
Attestation
A statement that something was checked, by someone willing to be named for it. A badge is one. It is not the same as a promise that nothing is wrong.
Deterministic
Gives the same answer every time it is run on the same thing. Some of our checks are like this and some involve a language model, which is not, and the report says which was which.
Heuristic
A rule of thumb that is usually right rather than always right. Where we use one, we say so and we say how sure we are, because a rule of thumb reported as a fact is how a report becomes untrustworthy.
Canonical
The one official version of something, written in one agreed way so that two copies can be compared. We use it about the rubric: the same rubric written out in the same order every time, so its fingerprint can be checked.
Idempotent
Doing it twice has the same result as doing it once. Running something idempotent again changes nothing, which is what you want from anything that might stop halfway through.
Taxonomy
A way of sorting things into named groups. Ours sorts findings into areas such as security, privacy and how usable an application is.

A word that sent you here and is not on the list

That is a fault on our side rather than yours. The list is meant to hold every word on this site that is not ordinary English, and a gap in it means a page is using a word we never explained. Our contact details are here.