Corrections
Every number on this site is a claim about a published record, and a claim can be wrong: the record can have moved, the source can say something else, or we can simply have read it badly. This page is how that gets fixed — and the log of every time it already has.
A factual correction with a source behind it is made the day it arrives, and the record’s updated date moves with it. Nothing waits for a release.
Rank is derived by sorting on the security score, so a correction that changes a field can change the score and reorder the register. There is no version of this where we quietly keep the old order.
Every change to a scored field is recorded with what it was, what it became and when — and published in the log. A site that scores others on transparency does not get to edit itself silently.
The model scores the state of the published evidence, not our opinion of a provider. So a correction has to arrive in the same currency: a source we can read. “This is wrong” cannot enter the pipeline; “this is wrong, here is the page that says so” can be acted on the same day.
If you have found a vulnerability in this site — not in a VPN we review — send it through the third form, Something else, with A security problem as its kind. Leave an address if you want to hear back, and we will confirm within two working days.
We do not run a bounty programme and will not pretend otherwise, but we will credit you on this page if you want the credit and will not chase anyone who reports in good faith.
If the vulnerability is in a provider’s service rather than ours, report it to them. If they have no route for that, tell us — the absence of one is itself a fact about that provider.
One field, one record. If you arrived from a provider page the field is already filled in below and you can go straight to the evidence.
If this is your service, you can dispute anything on its record. Two things worth knowing before you write, because they decide how far it gets.
+A published document anyone can open — an audit report, a policy page, a transparency report with numbers in it
+Telling us a field is out of date and pointing at what replaced it
+Filling a field we recorded as unknown, which is usually the fastest way to move a score upward
−An assurance sent to us privately. If it is not published, it cannot be scored — that is what the ignorance channel measures
−Disagreement with the methodology itself. That argument is welcome, but it belongs on the model, not on your record
−A request to remove a criticism, a label, or a competitor
Not a claim about a provider — a problem with the site itself.
We answer within five working days. If the record changes, the change is logged below with your name nowhere in it — the log records what moved, not who asked.