Encryption model & independent audits
How this is scored
What the vendor can prove about its security design: end-to-end encryption with named algorithms and key derivation, which fields are encrypted on the device and which are not, independent audits and penetration tests with published results, a bug bounty, and incident history disclosed.
0 — Security described in adjectives ("bank-grade", "military encryption") with no architecture, no audit and no statement of what the vendor can read.
3 — Encryption algorithms named and "zero knowledge" claimed, but no whitepaper, no statement of which fields stay unencrypted, and audits mentioned without dates, auditors or results.
5 — A published security whitepaper naming algorithms, key derivation and the client-side encryption model, a stated list of what is and is not encrypted (including URLs and metadata), and a named independent audit or certification (ISO 27001, SOC 2) with its date.
8 — Recurring independent penetration tests or code audits with reports or summaries published, a public bug bounty or vulnerability disclosure policy, past security incidents documented with their impact, and open-source clients or cryptography that can be reviewed.
10 — The design is verifiable end to end: full source or cryptographic design public, every field encrypted client-side including metadata, audits by named firms repeated yearly with full reports, a threat model that states what a compromise of the vendor's servers would expose, and incident post-mortems published.
The SME Owner
The encryption model is specific, not adjectives: AES-256 with elliptic-curve keys and PBKDF2 at one million iterations, record-level keys generated on the client, and a stated list of encrypted contents including URLs, custom fields and attachments, backed by annually audited ISO 27001 certification, FIPS 140-3 validated crypto modules, named penetration-testing firms and a public bug bounty on Bugcrowd. We found no public information on published audit report summaries, a documented incident history, or reviewable source code. 6 12 3