Method
How a reading is taken.
Written for the person doing diligence, not for a buyer. It includes what this registry does not establish, because understanding its limits is part of understanding the record.
A reading, not an answer
The registry does not ask an organization whether a safeguard is in place. Wherever it can, it looks at the organization's own systems or at public infrastructure. It records what it found, when it found it, and how.
Each reading is written once and never edited. A correction is a new entry beside the old one, and both stay readable. A finding is addressed by making the change and allowing the next reading to establish the new state.
It is easier to operate the safeguards than to pretend to operate them.
Where readings come from
Sources that need permission
Some readings require the organization to grant read-only access to a system it operates, such as its directory or endpoint platform. The permission requested is the narrowest one that answers the question. Where both a broad and narrow permission would work, the narrow permission is used.
Sources that need none
Some conditions are published by the organization and can be read by anyone. Email sender authentication is the clearest example: the policy lives in public directory records. These readings are available independently of the organization's reporting process.
The five bases, and why they remain separate
Every row on a credential identifies the basis for the reading. The bases are not interchangeable, and the registry keeps them separate.
Observed directly from the system concerned, or verified by an analyst. The strongest basis the registry offers.
A record produced by a third party, such as a roster from the body that ran the training. It stands on that third party's authority: they did the work, they keep the register, and the credential identifies that basis. Where someone independent of both this registry and the holder established a fact, naming them is the most accurate account available.
Established by a procedure the registry itself instruments. The registry may establish the hold period, choose the date a restore must answer, or prompt a rehearsal and record who took part. It is neither a machine reading nor the organization's word alone.
Stated by the account owner. Recorded, dated, and shown as exactly that. An attestation never displaces a measurement, and where the two disagree the disagreement is recorded rather than resolved.
Nothing has been established. This is not the same as a safeguard being absent, and the credential does not imply that it is.
How a claim ages
Each safeguard has a defined interval at which it must be established again. A reading inside that interval counts. A reading past it remains shown, with its date, but is no longer current.
Staleness never deletes or rewrites a reading. The row continues to show what was established and when. Its status changes because the reading is no longer current.
We verified this in March and have not since is a true statement, and this record makes it. That is the property a point-in-time attestation cannot offer at any price.
Time is not the only thing that can age a reading. A new computer may appear that has never been observed; a reporting period may close with no report; a certificate may expire; or a procedure may be adopted that nobody has acknowledged. Each can require the affected safeguard to be established again. The status changes when newer information supports it.
What this registry does not establish
Stated first, because it is what makes the measured facts worth anything.
It proves the hold ran for its full period and that two named people were involved. Whether the phone call reached the right person is beyond anything we can see.
It establishes that a file came back from a date we chose, that retention reached that far, and that someone at the business could operate a recovery. It does not establish that the backup covers all records that matter to the business.
The credential carries two numbers side by side, each on its own authority: the machines this reading reached, which we measured, and the machines the business says are in scope, which they told us. Each number represents exactly what it counts. The record does not determine whether the two populations are the same; it leaves that comparison to the reader.
Where a reading is cut short by a narrow permission or a source that stopped answering, the record marks the total as not established and reports what it reached. The count remains exact for the machines covered, and the boundary is shown.
The registry publishes state with dates. It does not score, grade, rank, rate, approve, certify, or compare one organization with another.
When a reading cannot be taken
A failed reading and an absent safeguard are different facts. A network fault, an expired permission, or a vendor outage means the registry could not establish the state; it does not mean the safeguard is absent.
Where the registry itself is the reason a reading failed, nothing is written to the organization's record. The record gains no entry and its standing does not change. Only a failure actually observed belongs on the organization's record.
The holder's right of reply
When a reading fails or a safeguard ages, the holder is told (in their own portal, through their distributor, and by email) with the reason, where a reason was established.
They may ask for the reading to be taken again. That request is recorded whether or not it succeeds, so an unanswered request is visible rather than silent.
No request can clear a finding. There is no path, for the holder or for us, that removes an entry from a record.
What is published, and what is not
A credential shows whether a safeguard is in place and when it was last established. It does not name an organization's vulnerabilities, hostnames, counts, or what was found on a machine. That detail stays in the sealed record and is disclosed only when the holder authorizes it.
There is no public directory of organizations here, and there never will be. The holder decides who sees their record. A browsable list would take that decision away.