Methodology
Every number on this site is reproducible or cited. Here is exactly how.
The one rule
We never actively bypass a security control on a production system that belongs to a non-consenting third party, and we never name a vendor’s paying customer. Every data point comes from one of three sources below.
1 · Sanctioned bypass proof
Reproducible bypass attempts run only against surfaces the vendor invitestesting on — public bug-bounty / research programs and interactive demo playgrounds (Tier A) — or against our owndeployments on the vendor’s free or trial tier (Tier B). We publish the evidence so anyone can rerun it.
2 · Passive challenge-rate measurement
For real-world coverage we detect which vendor protects a site and send a single honest, default automated client to its public homepage, recording only whether it was served, challenged, or hard-blocked. No bypass, no login, no content stored. Getting challenged is the measurement. Only anonymized per-vendor aggregates are published; site identities never leave our private store.
3 · Cited external benchmarks
Real-world bypass rates are cited from existing published research, never generated by us against non-consenting production systems.
Claim capture & scoring
Vendor claims are screenshotted with a capture date and source URL; when a vendor changes its number we keep the history. The claim-vs-reality gap score (0–100) is editorial but must be justified by linked evidence.