How we test
How we assess security products: which criteria count, how a score is formed – and what our ratings explicitly are not.
Why publish a method at all
A recommendation is only worth as much as the path that led to it. So we set out how we assess, what we look at – and just as importantly, what our scores are not.
What our rating is – and is not
| What we do | What we don’t do |
|---|---|
| Set up and use products ourselves | Invent measurements or pass off vendor figures as our own |
| Check documentation, pricing and terms | Rank by commission |
| Read independent security audits | List providers we have not assessed, to pad the table |
| Try the support and the cancellation path | Sell “test winner” badges |
| Apply exclusion criteria consistently | Change a rating to suit a partner |
Our criteria
We assess products for everyday users, not IT professionals. What matters in a data center is often irrelevant at a kitchen table.
| Criterion | What we look at | Weight |
|---|---|---|
| Security | Encryption, zero-knowledge design, handling of vulnerabilities, independent audits, ownership and jurisdiction | high |
| Usability | Setup, day-to-day use, comprehensibility without prior knowledge | high |
| Value for money | Cost against benefit, fairness at renewal and cancellation | medium |
| Features | Useful functions without bloat, family and emergency access | medium |
| Support | Availability, responsiveness, quality of documentation | medium |
Why security and usability carry equal weight: the most secure tool protects nobody if it is uninstalled after two weeks. A password manager somebody actually uses beats one with a better spec sheet.
Exclusion criteria
Some findings do not cost points – they keep a provider out of a recommendation entirely:
Not recommendable when …
- Marketing by fear (“Your device is infected!”) or constant warnings without cause.
- Cancellation made difficult, or automatic renewal at a much higher price without clear notice.
- Opaque ownership or unclear jurisdiction for a service that processes personal data.
- Promised features missing, or marketing claims contradicting the documentation.
- Unresolved security incidents without open communication and remediation.
- Data collection beyond the stated purpose, particularly in free tiers.
How a score is formed
We combine the individual criteria into an overall score from 1 to 5, with the high-weighted criteria counting double. The score is an assessment, not a measurement: it answers “how well does this fit an everyday user?”, not “which product has the better datasheet”.
That is why every comparison also states who a product is right for. A provider scoring 4.4 may suit you better than one scoring 4.6, if it matches what you actually need.
When a product is not needed
Not every problem needs a purchase. Where a free setting, a habit or a built-in operating system feature is enough, we say so – even when it costs us commission. That is why the free self-checks are more prominent here than any buying advice.
Keeping it current
- Regularly: comparison and review pages are re-checked at least every six months.
- On event: immediately after security incidents, ownership changes, audit results or significant price changes.
- Visibly: the date of the last update appears on every page.
- Consistently: a provider that meets an exclusion criterion is dropped – partner or not.
Independence
We take no payment for good ratings, and providers do not see our texts before publication. There are no sponsored posts, no paid guest articles and no “test winner” badges for sale.
The principles behind all of our content are in our editorial standards .
Found a mistake?
If you spot an error, an outdated figure or a blind spot, tell us. Demonstrable errors are corrected promptly and reflected in the update date. Reader corrections are the most effective quality mechanism a small editorial team has.
Frequently asked questions
Are these lab tests with measured results?
No. Our scores are editorial assessments against fixed, published criteria – based on our own use, provider documentation and independent audits. Where we quote third-party measurements, we name the source. We do not present our own speed tests as laboratory data.
Do commissions influence the ratings?
No. The criteria and their weighting are fixed before any provider is assessed, and apply equally to all. Providers without an affiliate programme can and do win our comparisons.
How often do you re-check recommendations?
Comparison and review pages at least every six months, plus immediately after security incidents, ownership changes or significant price changes. The date of the last update is shown on every page.