Methodology · Open rule
“Verified by Enterno” methodology v1.0
What earns the mark, what revokes it, and what it deliberately does not claim.
1. Required checks and minimums
These are the live values the scheduled re-check enforces right now — this table is generated from the same configuration, not transcribed from it.
| Check | Minimum score | Evidence |
|---|---|---|
| SSL/TLS certificate | 90/100 | /report/{domain}/ssl |
| Security headers | 70/100 | /report/{domain}/security |
| Health Score | 80/100 | /report/{domain}/health |
Content-Security-Policy and SEO tags are measured by Enterno but are not requirements here: CSP is already a weighted component of the security-headers grade, and SEO markup says nothing about whether a site is safe or reliable. Padding the requirement list with checks that do not bear on trust would make the mark look more rigorous while measuring the wrong things.
2. An unperformed check is never a pass
If a required check cannot be completed — the host is unreachable, the handshake fails, the response is unparseable — the domain is not verified. It does not pass by default, and the missing check is not dropped from the requirement set to let the rest carry the verdict. Absence of evidence is recorded as absence, never as a pass.
3. Re-measurement and automatic revocation
- Every domain in the catalog is re-measured on a rolling schedule, roughly every 30 days.
- Drop below the minimum on any required check → the mark is revoked on that pass, with the failing check recorded.
- If we could not re-confirm within 45 days, the verdict expires. A mark granted once and never re-tested would be a claim about the past presented as a claim about the present.
- Revocation reaches embedded badges within minutes: the badge endpoint reads the live catalog rather than a snapshot taken when the mark was granted.
4. What the mark does not claim
It is a measurement of publicly observable technical characteristics on a given date. It is not an endorsement of the organisation behind the domain, not an audit of private configuration, and not a judgement about content, products or business practices. Domains are measured from public data and can appear in the catalog without having requested it — the same standing as any public SSL or security-headers grader.