How we research and publish
This page describes how Attestd produces security research posts, API examples, and detection-ledger claims. It is the reference linked from research bylines.
Validation
Incident and vulnerability claims prefer primary sources: vendor advisories, registry security actions, OSV MAL advisories, NVD CVE records, and CISA KEV entries. Secondary reporting (blogs, news) is used for timeline context and is cited when it is the earliest public confirmation.
Detection timestamps in the ledger reflect when Attestd's systems flagged a condition, not when a journalist published. Where both are relevant, both are stated.
API examples
Product and package docs label constructed samples as example responses unless a page states a live verification date. Featured supply-chain packages always show supply_chain_monitored: true because they are on the watchlist. CVE-only product examples use supply_chain_monitored: false with a null supply_chain object.
Corrections and updates
Material corrections are applied to the article and reflected in the visible Updated date. Report factual errors to [email protected].
Competitor comparison pages carry a last-verified date and primary source links. Pricing and packaging claims are re-checked at least quarterly.
Conflicts of interest
Attestd sells a commercial API. Comparison and research pages state product differences in that context. We do not accept payment for favorable coverage of third-party products. Sponsored content, if ever published, will be labeled as such.