Evidence checklist and sample
The sample includes all 22 security and compliance records in the 201-company corpus, including the historical Silk Security record. Researchers reviewed the company files from 3 to 9 July 2026. We searched every distinct first-party URL cited in each saved research record and retained the matched URL in the download.
The checklist records discoverability: a dedicated trust/security page, a named assurance claim or status such as SOC 2, ISO 27001, HIPAA, or FedRAMP, technical documentation, customer proof, and public pricing. A source can satisfy more than one item. Upwind's cited FedRAMP source said it was pursuing certification, so a named framework mention must not be read as authorization achieved.
Evidence found in the reviewed records
| Evidence item | Companies | What it can answer |
|---|---|---|
| Customer or case-study page | 13 / 22 | Named workload, organization, or reported use |
| Public pricing page | 8 / 22 | Entry packaging or a route to a quote |
| Named assurance claim or status | 9 / 22 | A framework, certification, authorization, or pursuit statement to verify |
| Dedicated trust or security page | 7 / 22 | A starting point for policies, controls, or gated documents |
| Technical documentation | 5 / 22 | Deployment, integration, or operating detail |
Turn a public claim into reviewable evidence
- Record the exact assurance state: certified, attested, authorized, compliant, in process, or merely mapped to a framework.
- Ask for scope, entity, product, region, audit period, report date, and exceptions. A logo or framework name does not supply these fields.
- Separate product-security claims from the vendor's own security controls and from customer outcome claims.
- Use documentation to assign customer and vendor operating responsibilities before accepting a broad security statement.
Current example
Promptfoo's page checked on 8 September separates a free Community product, custom Enterprise, and custom On-Premise. The page names SSO, permissions, monitoring, support, and deployment isolation. These are useful evaluation facts, while actual control evidence and contract terms still require separate review.
Limits
The audit measures evidence cited in the research files, not the full live web and not actual security quality. Research depth varies. Empty cells are unanswered in this dataset, not proof of absence.
Sources and dates
- Promptfoo pricing and enterprise comparison ↗Reviewed 2026-09-08
- ConductorOne security ↗Reviewed 2026-07-03
- Riot security ↗Reviewed 2026-07-03
- Token Security trust center ↗Reviewed 2026-07-09
Found an error or a changed source? Send a correction.
Apply this to your company
Prepare materials for your next buyer conversation.
Accountmade helps technical B2B teams prepare demo decks, technical blueprints, business cases and security materials.
Explore Accountmade →