{
  "$schema": "https://securitystackcompare.com/data/ratings.schema.json",
  "dataset": "security-stack-compare-open-ratings",
  "version": "2026-06-02",
  "lastModified": "2026-06-02",
  "publisher": "Security Stack Compare",
  "methodologyUrl": "https://securitystackcompare.com/en/methodology",
  "disclaimer": "Editorial buyer guidance only. The ratings are not certification, legal advice, audit opinion or proof of compliance. Verify legal scope, implementation evidence and current vendor terms directly.",
  "scoreScale": {
    "minimum": 0,
    "maximum": 100,
    "meaning": "Directional editorial score for buyer fit and evidence quality, not a compliance certificate."
  },
  "scoreDimensions": [
    {
      "key": "compliance",
      "label": "Compliance Readiness"
    },
    {
      "key": "evidence",
      "label": "Evidence Completeness"
    },
    {
      "key": "ops",
      "label": "Operational Coverage"
    },
    {
      "key": "remediation",
      "label": "Remediation Workflow"
    },
    {
      "key": "smb",
      "label": "SMB Practicality"
    },
    {
      "key": "price",
      "label": "Price / TCO clarity"
    },
    {
      "key": "byok",
      "label": "Data Control / BYOK"
    },
    {
      "key": "region",
      "label": "Regional Fit"
    }
  ],
  "ratings": [
    {
      "vendorId": "shielda",
      "vendorName": "Shielda",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/shielda",
      "overallScore": 93,
      "confidence": "directional",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "transparencyNoteOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "vendorStatement",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 96,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 98,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 88,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 95,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 92,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 88,
          "receipts": [
            {
              "type": "vendorStatement",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 95,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 92,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        }
      ],
      "knownGaps": [
        "Specialist endpoint, cloud, AppSec or backup tools can go deeper; large teams with budget and security engineers may prefer best-of-breed",
        "Flat commercial offer, but not independently verifiable on a public pricing page; confirm current terms directly."
      ],
      "bestFitUseCases": [
        "SMBs that want security switched on quickly: all-in-one tools, evidence, tasks and engineer-like guidance without hiring a security team first"
      ],
      "notEnoughFor": [
        "Not enough when the primary need is specialist EDR, CNAPP, SAST, backup depth or an enterprise SOC instead of a broad evidence and remediation layer."
      ],
      "sourceLinks": [
        {
          "label": "Shielda",
          "url": "https://shielda.ai/"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Shielda&body=Vendor%3A%20Shielda%0APage%3A%20%2Fvendors%2Fshielda%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "defender",
      "vendorName": "Microsoft Defender for Business",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/defender",
      "overallScore": 71,
      "confidence": "high",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "pricingPage",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 62,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 78,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 60,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 86,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 92,
          "receipts": [
            {
              "type": "pricingPage",
              "confidence": "high"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 60,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        }
      ],
      "knownGaps": [
        "Great inside Microsoft, weaker for cross-tool evidence, supplier risk and audit workflow",
        "Published SMB price is paid yearly and limited to the business plan scope; check user caps, device coverage and taxes."
      ],
      "bestFitUseCases": [
        "Microsoft-first SMBs that want a credible endpoint, identity and email baseline from tools they may already own"
      ],
      "notEnoughFor": [
        "Not enough when the buying problem is audit evidence, supplier risk, backup proof or cross-tool remediation rather than endpoint and XDR coverage."
      ],
      "sourceLinks": [
        {
          "label": "Microsoft Defender for Business",
          "url": "https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-business"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Microsoft%20Defender%20for%20Business&body=Vendor%3A%20Microsoft%20Defender%20for%20Business%0APage%3A%20%2Fvendors%2Fdefender%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "crowdstrike",
      "vendorName": "CrowdStrike Falcon",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/crowdstrike",
      "overallScore": 66,
      "confidence": "high",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "pricingPage",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 70,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 60,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 88,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 70,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 50,
          "receipts": [
            {
              "type": "pricingPage",
              "confidence": "high"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        }
      ],
      "knownGaps": [
        "Premium endpoint depth, but not a full compliance, supplier-risk or SMB operating layer",
        "Public entry price is Falcon Go; larger device counts, Pro/Enterprise tiers and MDR change the bill."
      ],
      "bestFitUseCases": [
        "Teams where endpoint breach risk is a board-level worry and budget exists for premium EDR/MDR"
      ],
      "notEnoughFor": [
        "Not enough when the buying problem is audit evidence, supplier risk, backup proof or cross-tool remediation rather than endpoint and XDR coverage."
      ],
      "sourceLinks": [
        {
          "label": "CrowdStrike Falcon pricing",
          "url": "https://www.crowdstrike.com/en-us/pricing/bundles/falcon-go/"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20CrowdStrike%20Falcon&body=Vendor%3A%20CrowdStrike%20Falcon%0APage%3A%20%2Fvendors%2Fcrowdstrike%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "sentinelone",
      "vendorName": "SentinelOne Singularity",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/sentinelone",
      "overallScore": 66,
      "confidence": "high",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "pricingPage",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 68,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 58,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 86,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 68,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 58,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 55,
          "receipts": [
            {
              "type": "pricingPage",
              "confidence": "high"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 58,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        }
      ],
      "knownGaps": [
        "Strong autonomous endpoint response, weaker as a broad compliance and evidence operating layer",
        "Published entry price is Singularity Core; higher tiers, MDR and enterprise packaging can move to custom pricing."
      ],
      "bestFitUseCases": [
        "Security teams that want strong endpoint response and automation without hand-tuning every incident"
      ],
      "notEnoughFor": [
        "Not enough when the buying problem is audit evidence, supplier risk, backup proof or cross-tool remediation rather than endpoint and XDR coverage."
      ],
      "sourceLinks": [
        {
          "label": "SentinelOne platform packages",
          "url": "https://www.sentinelone.com/platform-packages/"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20SentinelOne%20Singularity&body=Vendor%3A%20SentinelOne%20Singularity%0APage%3A%20%2Fvendors%2Fsentinelone%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "sophos",
      "vendorName": "Sophos MDR / Intercept X",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/sophos",
      "overallScore": 67,
      "confidence": "medium",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "vendorStatement",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 64,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 56,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 65,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 78,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 60,
          "receipts": [
            {
              "type": "vendorStatement",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        }
      ],
      "knownGaps": [
        "Good protection bundle, but evidence depth, supplier risk and governance still need a broader workflow",
        "Sophos routes Endpoint and MDR through a quote flow; ask for users, servers, MDR scope, onboarding and renewal terms."
      ],
      "bestFitUseCases": [
        "SMBs that want endpoint, firewall and MDR help from one practical vendor rather than stitching everything alone"
      ],
      "notEnoughFor": [
        "Not enough when the buying problem is audit evidence, supplier risk, backup proof or cross-tool remediation rather than endpoint and XDR coverage."
      ],
      "sourceLinks": [
        {
          "label": "Sophos Endpoint quote",
          "url": "https://www.sophos.com/en-us/products/endpoint-antivirus/request-pricing"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Sophos%20MDR%20%2F%20Intercept%20X&body=Vendor%3A%20Sophos%20MDR%20%2F%20Intercept%20X%0APage%3A%20%2Fvendors%2Fsophos%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "eset",
      "vendorName": "ESET PROTECT",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/eset",
      "overallScore": 65,
      "confidence": "high",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "pricingPage",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 58,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 50,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 70,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 72,
          "receipts": [
            {
              "type": "pricingPage",
              "confidence": "high"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 88,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        }
      ],
      "knownGaps": [
        "Endpoint protection is the center; broad compliance operations and proof still need another layer",
        "Online cart changes with device count, term and region; first-term discounts may not equal renewal cost."
      ],
      "bestFitUseCases": [
        "EU-based SMBs that want dependable endpoint protection with a familiar, low-drama buying motion"
      ],
      "notEnoughFor": [
        "Not enough when the buying problem is audit evidence, supplier risk, backup proof or cross-tool remediation rather than endpoint and XDR coverage."
      ],
      "sourceLinks": [
        {
          "label": "ESET PROTECT Entry",
          "url": "https://www.eset.com/us/business/entry-protection/"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20ESET%20PROTECT&body=Vendor%3A%20ESET%20PROTECT%0APage%3A%20%2Fvendors%2Feset%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "bitdefender",
      "vendorName": "Bitdefender GravityZone",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/bitdefender",
      "overallScore": 65,
      "confidence": "high",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "pricingPage",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 56,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 48,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 70,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 82,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 76,
          "receipts": [
            {
              "type": "pricingPage",
              "confidence": "high"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 84,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        }
      ],
      "knownGaps": [
        "Strong protection value, but compliance evidence and remediation ownership remain scattered",
        "Cart pricing depends on selected package, device count, term, discounts and region; over 100 devices can move to sales."
      ],
      "bestFitUseCases": [
        "Cost-conscious SMBs that want strong malware prevention quickly without a complex security platform rollout"
      ],
      "notEnoughFor": [
        "Not enough when the buying problem is audit evidence, supplier risk, backup proof or cross-tool remediation rather than endpoint and XDR coverage."
      ],
      "sourceLinks": [
        {
          "label": "Bitdefender business comparison",
          "url": "https://www.bitdefender.com/en-us/business/compare"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Bitdefender%20GravityZone&body=Vendor%3A%20Bitdefender%20GravityZone%0APage%3A%20%2Fvendors%2Fbitdefender%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "acronis",
      "vendorName": "Acronis Cyber Protect",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/acronis",
      "overallScore": 64,
      "confidence": "medium",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "vendorStatement",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 60,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 72,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 58,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 78,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 58,
          "receipts": [
            {
              "type": "vendorStatement",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 60,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 78,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        }
      ],
      "knownGaps": [
        "Great resilience component, but not a full security/compliance operating layer",
        "Acronis licensing can be per-workload or per-GB through service-provider and partner models; compare protected workloads and storage."
      ],
      "bestFitUseCases": [
        "Teams that fear downtime and ransomware recovery as much as the initial attack"
      ],
      "notEnoughFor": [
        "Not enough when the team expects one tool to cover evidence, remediation, endpoint, cloud, code, backup and supplier risk at once."
      ],
      "sourceLinks": [
        {
          "label": "Acronis Cyber Protect Cloud pricing",
          "url": "https://www.acronis.com/en/products/cloud/cyber-protect/pricing/"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Acronis%20Cyber%20Protect&body=Vendor%3A%20Acronis%20Cyber%20Protect%0APage%3A%20%2Fvendors%2Facronis%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "wazuh",
      "vendorName": "Wazuh + osquery",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/wazuh",
      "overallScore": 63,
      "confidence": "high",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "pricingPage",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 70,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 40,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 50,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 74,
          "receipts": [
            {
              "type": "pricingPage",
              "confidence": "high"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 95,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        }
      ],
      "knownGaps": [
        "Free software, but not free operations; workflow, reporting and remediation are buyer-owned",
        "License can be free when self-hosted, but hosting, tuning, triage, reporting and ownership are real operational costs."
      ],
      "bestFitUseCases": [
        "Technical teams that want open-source visibility and are willing to own the engineering work"
      ],
      "notEnoughFor": [
        "Not enough when the team expects one tool to cover evidence, remediation, endpoint, cloud, code, backup and supplier risk at once."
      ],
      "sourceLinks": [
        {
          "label": "Wazuh Cloud",
          "url": "https://wazuh.com/cloud/"
        },
        {
          "label": "osquery",
          "url": "https://osquery.io/"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Wazuh%20%2B%20osquery&body=Vendor%3A%20Wazuh%20%2B%20osquery%0APage%3A%20%2Fvendors%2Fwazuh%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "gws-m365",
      "vendorName": "Google Workspace / M365 Security",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/gws-m365",
      "overallScore": 62,
      "confidence": "high",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "pricingPage",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 50,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 45,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 60,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 45,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 88,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 90,
          "receipts": [
            {
              "type": "pricingPage",
              "confidence": "high"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 50,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        }
      ],
      "knownGaps": [
        "Useful baseline controls, but not a complete security program or evidence workflow",
        "Controls are bundled into Google Workspace or Microsoft 365 plans, so the useful price is the suite you actually own."
      ],
      "bestFitUseCases": [
        "Companies that want to squeeze more security from the productivity suite they already run every day"
      ],
      "notEnoughFor": [
        "Not enough when the team expects one tool to cover evidence, remediation, endpoint, cloud, code, backup and supplier risk at once."
      ],
      "sourceLinks": [
        {
          "label": "Google Workspace pricing",
          "url": "https://workspace.google.com/pricing.html"
        },
        {
          "label": "Microsoft 365 business pricing",
          "url": "https://www.microsoft.com/en-us/microsoft-365/business/compare-all-microsoft-365-business-products"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Google%20Workspace%20%2F%20M365%20Security&body=Vendor%3A%20Google%20Workspace%20%2F%20M365%20Security%0APage%3A%20%2Fvendors%2Fgws-m365%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "wiz",
      "vendorName": "Wiz",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/wiz",
      "overallScore": 64,
      "confidence": "medium",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "vendorStatement",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 72,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 65,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 70,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 50,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 35,
          "receipts": [
            {
              "type": "vendorStatement",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 60,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        }
      ],
      "knownGaps": [
        "Excellent cloud depth, but expensive and not an all-in-one SMB security workflow",
        "Wiz pricing is modular and quote-led; workloads, developers, log ingestion, sensors and SMB bundles can all change scope."
      ],
      "bestFitUseCases": [
        "Cloud-heavy companies that need deep cloud risk visibility and have budget for a serious CNAPP"
      ],
      "notEnoughFor": [
        "Not enough when the team needs hands-on technical remediation, endpoint/cloud/AppSec protection or backup proof inside the same workflow."
      ],
      "sourceLinks": [
        {
          "label": "Wiz pricing",
          "url": "https://www.wiz.io/pricing"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Wiz&body=Vendor%3A%20Wiz%0APage%3A%20%2Fvendors%2Fwiz%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "snyk",
      "vendorName": "Snyk",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/snyk",
      "overallScore": 61,
      "confidence": "high",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "pricingPage",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 58,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 50,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 60,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 60,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 65,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 70,
          "receipts": [
            {
              "type": "pricingPage",
              "confidence": "high"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        }
      ],
      "knownGaps": [
        "Excellent AppSec signal, but little help for endpoint, suppliers, backup or broad compliance operations",
        "Team price is per contributing developer, with minimum contributors and products purchased separately."
      ],
      "bestFitUseCases": [
        "Developer-led teams that want security to show up inside code, dependencies and CI before release"
      ],
      "notEnoughFor": [
        "Not enough when endpoint protection, backup proof, supplier risk or broad compliance evidence are the main pressure."
      ],
      "sourceLinks": [
        {
          "label": "Snyk plans",
          "url": "https://snyk.io/plans/"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Snyk&body=Vendor%3A%20Snyk%0APage%3A%20%2Fvendors%2Fsnyk%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "semgrep",
      "vendorName": "Semgrep",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/semgrep",
      "overallScore": 59,
      "confidence": "high",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "pricingPage",
        "vendorStatement",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 48,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 45,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 50,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 70,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 82,
          "receipts": [
            {
              "type": "pricingPage",
              "confidence": "high"
            },
            {
              "type": "vendorStatement",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "high"
            }
          ]
        }
      ],
      "knownGaps": [
        "Narrow code-security scope; value depends on rule quality and engineering ownership",
        "Teams pricing is per contributor and product line; Code, Supply Chain and Secrets have different price points and limits."
      ],
      "bestFitUseCases": [
        "Engineering teams that want customizable code scanning and are willing to tune rules around how they build"
      ],
      "notEnoughFor": [
        "Not enough when endpoint protection, backup proof, supplier risk or broad compliance evidence are the main pressure."
      ],
      "sourceLinks": [
        {
          "label": "Semgrep pricing",
          "url": "https://semgrep.dev/pricing/"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Semgrep&body=Vendor%3A%20Semgrep%0APage%3A%20%2Fvendors%2Fsemgrep%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "vanta",
      "vendorName": "Vanta",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/vanta",
      "overallScore": 68,
      "confidence": "medium",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "vendorStatement",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 84,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 88,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 50,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 78,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 45,
          "receipts": [
            {
              "type": "vendorStatement",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        }
      ],
      "knownGaps": [
        "Strong audit workflow, weaker for hands-on technical remediation and security operations",
        "Vanta now uses personalized pricing; confirm frameworks, employee count, integrations, add-ons and renewal terms."
      ],
      "bestFitUseCases": [
        "Startups and growing companies that need SOC 2 or ISO evidence to look organized quickly"
      ],
      "notEnoughFor": [
        "Not enough when the team needs hands-on technical remediation, endpoint/cloud/AppSec protection or backup proof inside the same workflow."
      ],
      "sourceLinks": [
        {
          "label": "Vanta pricing",
          "url": "https://www.vanta.com/pricing"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Vanta&body=Vendor%3A%20Vanta%0APage%3A%20%2Fvendors%2Fvanta%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "drata",
      "vendorName": "Drata",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/drata",
      "overallScore": 68,
      "confidence": "medium",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "vendorStatement",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 86,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 88,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 52,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 78,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 45,
          "receipts": [
            {
              "type": "vendorStatement",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        }
      ],
      "knownGaps": [
        "Compliance workflow is strong, but technical remediation still depends on connected tools and owners",
        "Drata packages are quote-led; confirm FTE limits, frameworks, Trust Center, add-ons and renewal assumptions."
      ],
      "bestFitUseCases": [
        "Teams that want polished continuous compliance and a cleaner audit room across multiple frameworks"
      ],
      "notEnoughFor": [
        "Not enough when the team needs hands-on technical remediation, endpoint/cloud/AppSec protection or backup proof inside the same workflow."
      ],
      "sourceLinks": [
        {
          "label": "Drata plans",
          "url": "https://drata.com/plans"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Drata&body=Vendor%3A%20Drata%0APage%3A%20%2Fvendors%2Fdrata%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "onetrust",
      "vendorName": "OneTrust",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/onetrust",
      "overallScore": 58,
      "confidence": "medium",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "vendorStatement",
        "publicDocs"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 82,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 50,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 48,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 35,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 30,
          "receipts": [
            {
              "type": "vendorStatement",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 55,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 80,
          "receipts": [
            {
              "type": "publicDocs",
              "confidence": "medium"
            },
            {
              "type": "editorialInference",
              "confidence": "medium"
            }
          ]
        }
      ],
      "knownGaps": [
        "Enterprise governance depth, but heavy for SMB security setup and not a technical protection stack",
        "OneTrust uses value-based usage meters; compare admin users, inventory size, visitors, profiles and data volume before comparing totals."
      ],
      "bestFitUseCases": [
        "Large organizations that need privacy, GRC and governance workflows across many teams and regions"
      ],
      "notEnoughFor": [
        "Not enough when the team needs hands-on technical remediation, endpoint/cloud/AppSec protection or backup proof inside the same workflow."
      ],
      "sourceLinks": [
        {
          "label": "OneTrust pricing",
          "url": "https://www.onetrust.com/pricing/"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20OneTrust&body=Vendor%3A%20OneTrust%0APage%3A%20%2Fvendors%2Fonetrust%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    },
    {
      "vendorId": "msp",
      "vendorName": "Typical MSP stack",
      "vendorUrl": "https://securitystackcompare.com/en/vendors/msp",
      "overallScore": 62,
      "confidence": "directional",
      "lastReviewed": "2026-05-19",
      "vendorResponseStatus": "notOnFile",
      "evidenceSourceTypes": [
        "editorialInference",
        "vendorStatement",
        "practitionerSignal"
      ],
      "scoreBasis": "Weighted editorial score across eight visible dimensions: compliance readiness, evidence completeness, operational coverage, remediation workflow, SMB practicality, price clarity, data control and regional fit.",
      "scoreClaims": [
        {
          "scoreKey": "compliance",
          "label": "Compliance Readiness",
          "value": 55,
          "receipts": [
            {
              "type": "practitionerSignal",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "evidence",
          "label": "Evidence Completeness",
          "value": 50,
          "receipts": [
            {
              "type": "practitionerSignal",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "ops",
          "label": "Operational Coverage",
          "value": 65,
          "receipts": [
            {
              "type": "practitionerSignal",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "remediation",
          "label": "Remediation Workflow",
          "value": 55,
          "receipts": [
            {
              "type": "practitionerSignal",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "smb",
          "label": "SMB Practicality",
          "value": 80,
          "receipts": [
            {
              "type": "practitionerSignal",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "price",
          "label": "Price / TCO clarity",
          "value": 70,
          "receipts": [
            {
              "type": "vendorStatement",
              "confidence": "directional"
            },
            {
              "type": "practitionerSignal",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "byok",
          "label": "Data Control / BYOK",
          "value": 50,
          "receipts": [
            {
              "type": "practitionerSignal",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        },
        {
          "scoreKey": "region",
          "label": "Regional Fit",
          "value": 75,
          "receipts": [
            {
              "type": "practitionerSignal",
              "confidence": "directional"
            },
            {
              "type": "editorialInference",
              "confidence": "directional"
            }
          ]
        }
      ],
      "knownGaps": [
        "Quality varies by provider; evidence, documentation and accountability can be inconsistent",
        "MSP pricing is only meaningful with a tool list, runbook, response SLA, reporting sample and evidence sample."
      ],
      "bestFitUseCases": [
        "Small companies that want a human partner to run day-to-day IT and basic security without hiring internally"
      ],
      "notEnoughFor": [
        "Not enough when the team expects one tool to cover evidence, remediation, endpoint, cloud, code, backup and supplier risk at once."
      ],
      "sourceLinks": [
        {
          "label": "Methodology",
          "url": "https://securitystackcompare.com/methodology"
        }
      ],
      "challengeUrl": "mailto:updates@securitystackcompare.com?subject=Challenge%20open%20rating%3A%20Typical%20MSP%20stack&body=Vendor%3A%20Typical%20MSP%20stack%0APage%3A%20%2Fvendors%2Fmsp%0A%0AWhat%20should%20change%20and%20which%20public%20source%20supports%20it%3F%0A"
    }
  ]
}
