How we work

Editorial policy

Security guidance has consequences. This policy explains how material is selected, reviewed and corrected.

Source standards

Guides should cite primary sources wherever possible: official product documentation, government guidance, standards, original research and documentation from established civil-society organisations. Secondary reporting may provide context but should not be the only support for a consequential instruction.

Directory labels

Recommended
A strong starting point for its stated purpose, subject to the limitations shown.
Useful reference
Worth consulting for information or context, but not necessarily an endorsement of every claim, article or product.
Consider with caveats
May be appropriate for some readers, but the trade-offs deserve particular attention before adoption.

Reviews and stale material

Guides, resources and videos carry a last-reviewed date and a future review date. Material beyond that date is visibly marked. A review checks that links resolve, instructions still match current interfaces, limitations remain accurate and newer evidence has not changed the recommendation.

Product references

A listing is not a guarantee and should not be treated as one. Security changes with product updates, ownership, operational practices and new research. The directory explains why something may be useful and where trust or risk remains.

The site does not currently use affiliate links, accept payment for placement or publish sponsored rankings. If that changes, disclosures will appear both here and beside affected material.

Corrections

Material that could create immediate harm should be corrected or withdrawn promptly. Other corrections are incorporated during review. Readers can report issues through the contact page.

Publication date

This policy was published and reviewed on 26 July 2026.