The short version

Every external number on this desk carries a named source, a retrievable link, a sample size where one exists, and the date somebody last checked it by hand. If a page states a figure and you cannot get from the figure to its origin in one click, that is a defect.

The four dates

Pages here carry up to four separate dates, and conflating them is how reference sites go quietly stale.

Published is when the page first appeared. It never changes.

Updated is when the content materially changed. It is never bumped cosmetically to look fresh, because a dateModified that moves without the content moving is a lie told to a crawler.

Current as of is the content currency date. It answers the question a reader actually has, which is whether the analysis still reflects the world.

Verified sits on each individual source, not on the page. It records when that specific link and that specific figure were last confirmed. Two sources on the same page routinely carry different verification dates, and showing both is more honest than averaging them into one.

What blocks publication

These run as build gates rather than as a checklist somebody remembers. A page that violates one of them does not ship, because a rule enforced by a human is a rule that decays.

  • Meta title over 60 characters, or meta description over 160
  • Any em dash or en dash in a title, excerpt, or body
  • Any banned phrase from the editorial list
  • An external statistic whose source has not been verified within the last 90 days
  • Fewer than three FAQ pairs on an editorial page
  • A missing content currency date
  • A decision brief with no stated verdict
  • An internal link that does not resolve

Vendor research

Vendor-published surveys are used here. They are frequently the only recent data that exists on a question, and refusing them on principle would mean writing about tool sprawl using figures from 2019.

They are labelled instead. Every source drawn from a company with a commercial interest in the answer carries a visible vendor research tag and a note on the sampling bias that follows. A cloud security vendor surveying its own customer base will find a cloud-heavy sample; that does not make the finding useless, it makes it a finding about a particular population.

What does not happen is laundering. A vendor survey never appears as an unattributed claim, and a number never travels from a vendor report into a sentence here without the vendor's name attached to it.

Secondary sourcing

Some of the most cited figures in this field sit behind analyst paywalls. Where a number is only publicly available through a press release or through secondary reporting, the source note says so and states what is not publicly checkable.

The specific case that comes up most: several widely quoted claims about cybersecurity buying committee size are synthesis by third-party marketers rather than figures the underlying analyst publishes. Where that is true, this desk cites the range the analyst does publish and says explicitly that the narrower figure is an estimate.

Re-verification

Benchmark cards are re-checked quarterly. The whole set was last swept on the date shown on the benchmarks index.

Re-verification means opening the source, confirming the figure has not been revised, and confirming the link still resolves. When a source revises a number, the card is updated and the revision is stated rather than silently replaced, because the fact that a figure moved is itself information.

Corrections

Errors get fixed in place, with the change noted on the page. Nothing is quietly deleted. If a claim here is wrong, the fastest way to get it fixed is to say so.