Trust TRU-002

Assessment methodology

Methodology is a public constraint on the product. It defines what is collected, how observations are interpreted and where Domain Signals must stop.

Bounded, non-exploitative Authorised external assessment.

Bounded evidence. Explicit responsibility. No hidden inference.

The useful answer

Assessment methodology explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals.

Assessment methodology explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals. Methodology is a public constraint on the product. It defines what is collected, how observations are interpreted and where Domain Signals must stop.

Route-specific context

The decision this page is designed to support

01
Review audience
Security reviewer, technical evaluator
02
Control objective
Understand collection and interpretation rules. Assessment methodology explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals.
03
Proof boundary
The exact target, source, observation time, responsibility and evidence state remain available to entitled readers. Evidence basis: Product contract and collector capability register.

A deliberate path

From permission to retained evidence

  1. 01

    Review the governed control described by assessment methodology.

  2. 02

    Trace each statement to its stated evidence basis, owner and review date.

  3. 03

    Carry the published limitation into procurement, assurance or technical interpretation rather than treating silence as approval.

Evidence before assertion

What the product can support

Every governed capability ends with an explicit disposition. Current observations can support a strength or an action; missing, stale or unavailable evidence remains an unknown and cannot become reassurance. The exact target, source, observation time, responsibility and evidence state remain available to entitled readers.

Supported capability

Domain Signals performs bounded, non-exploitative authorised external assessments of submitted domains.

Product contract and collector capability register

Supported capability

The assessment uses direct protocol observations and passive intelligence but stops before exploitation, authentication attempts, brute force and fuzzing.

Collector policy and protocol adapter tests

Supported capability

The first-party Signals Exposure Index records governed DNS, certificate, TLS, HTTP, email, service, fingerprint, attribution, dependency, geography and evidence-health observations when applicable.

Capability register and sealed projection

Direct answers

Questions a careful reader should ask

What does Assessment methodology establish?

Assessment methodology explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals. It establishes only what the governed evidence supports.

What does it not establish?

It does not prove complete organisational security, exploitability, breach likelihood or the absence of unobserved weaknesses.

How can I verify the conclusion?

Use the linked evidence or capability record to inspect source, observation time, target, responsibility and the condition required for closure.