How we score

SHORT ANSWER

Each topic page scores four to six products on six criteria, out of 10, with the weights printed on the page. Every score has a one-line reason and a link to the public page it came from. Where a vendor's public material says nothing about a criterion, we say so and score it low rather than guess.

Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29

What goes into a score?

We read the vendor's own product pages, documentation, pricing pages and press releases, and the standards the category depends on: the MCP specification, the OWASP Non-Human Identities Top 10 and NIST SP 800-207. We do not run the products, we do not interview vendors, and we do not use analyst reports we cannot link to.

A score reflects what the public material states. A product can be better in practice than its website suggests. When that happens, the fix is for the vendor to publish the detail, and we will re-score from it.

How are the criteria chosen?

Each topic has six criteria that a buyer would ask about before a trial. They are weighted by how much a wrong answer would cost: credentials and enforcement weigh more than packaging. The weights for each topic are listed at the top of its scorecard.

How are totals calculated?

The total is the weighted average of the six criterion scores. It is computed in code from the scores and weights on the page, so the published numbers always add up. Equal totals share a rank.

AI agent security and identity

  • c1 No standing credentials for agents 20%
  • c2 Per-call authorization 20%
  • c3 Human accountability and approval 15%
  • c4 Finding agents you did not register 15%
  • c5 Standards and ecosystem 15%
  • c6 Maturity and buying clarity 15%

Totals are the weighted average of the criterion scores, computed from the weights shown. Nothing is adjusted by hand.

ITDR and identity security

  • c1 Detection breadth 25%
  • c2 Stopping attacks at sign-in 20%
  • c3 Token and session attacks 20%
  • c4 Response and recovery 15%
  • c5 Posture and attack paths 10%
  • c6 Maturity and buying clarity 10%

Totals are the weighted average of the criterion scores, computed from the weights shown. Nothing is adjusted by hand.

Non-human and machine identities

  • c1 Discovery breadth 25%
  • c2 Owner for every identity 15%
  • c3 Removing long-lived secrets 25%
  • c4 Runtime enforcement 15%
  • c5 AI agents as non-human identities 10%
  • c6 Maturity and buying clarity 10%

Totals are the weighted average of the criterion scores, computed from the weights shown. Nothing is adjusted by hand.

MCP security

  • c1 Credentials kept from the agent 25%
  • c2 Policy per tool call 25%
  • c3 User and agent bound together 15%
  • c4 Audit trail 10%
  • c5 Server isolation and approval 15%
  • c6 Deployment choice and buying clarity 10%

Totals are the weighted average of the criterion scores, computed from the weights shown. Nothing is adjusted by hand.

Workforce IAM

  • c1 App integration breadth 20%
  • c2 Phishing-resistant sign-in 20%
  • c3 Protection of token signing 10%
  • c4 Provisioning to apps 15%
  • c5 AI agent identities 15%
  • c6 Pricing transparency 20%

Totals are the weighted average of the criterion scores, computed from the weights shown. Nothing is adjusted by hand.

Identity visibility and hygiene

  • c1 Breadth of sources 25%
  • c2 People, machines and agents in one view 20%
  • c3 Hygiene findings 20%
  • c4 Acting on findings 15%
  • c5 Effort to start 10%
  • c6 Maturity and buying clarity 10%

Totals are the weighted average of the criterion scores, computed from the weights shown. Nothing is adjusted by hand.

What does the "Gap in public material" tag mean?

It marks a cell where the reason says the vendor's public pages do not describe the capability. It does not mean the capability is missing from the product. It means a buyer will need to ask.

Limitations

  • Public sources only, read between 27 and 29 September 2026.
  • No hands-on testing, no vendor interviews, no customer interviews.
  • Pricing changes often; check the vendor's page before relying on a figure.
  • Vendors that publish little are at a disadvantage on the buying-clarity criteria. That is intended: it is information a buyer does not have either.

Corrections

If a score depends on something that has changed, or on a page we misread, the corrected score and the date of the change will appear on the page. We do not accept payment to change a score.

Questions

Can a vendor pay to change a score?

No. We do not accept payment to change a score. Corrections are made when a vendor publishes new information or when we misread a page, and the change is dated.

Why do vendors with little public material score low?

Because a buyer does not have that information either. When a vendor publishes the detail, we re-score from it.