Adversary realism
How closely the analyzed adversary matches the actor relevant to the policy claim.
- 1Benign faults
- 2Remote outsider
- 3Bounded insider
- 4Malicious operator
- 5State-scale physical or supply-chain actor
Methodology v1.0 · Released August 2026
Our reviews separate what a mechanism technically produces from the institutional conclusion placed on top of it. Scores describe the claim; they are not a composite quality grade.
Identify the counter, key, enclave, timing protocol, verifier, or license mechanism doing the technical work.
Record what the primitive can establish and what remains a decision about identity, policy, legitimacy, intent, or enforcement.
List the independent systems and institutions that must remain correct, available, uncompromised, and mutually consistent.
State the source’s strongest limitations and explicit exclusions before adding editorial assessment.
Describe tests or evidence that would materially change the assessment.
How closely the analyzed adversary matches the actor relevant to the policy claim.
The number of independent trust domains that must hold for the claimed assurance.
The distance between the technical observation and the policy outcome it is asked to support.
A high adversary-realism score is not criticism. A high dependency score does not mean those dependencies are implausible. A high policy-reach score does not mean the policy objective is undesirable. The useful question is whether the dependency chain is visible and whether the mechanism is being credited with more assurance than it produces.
When a limitation cannot be found in the reviewed material, records say “not located.” They do not say the authors ignored it. Case files are versioned because source revisions may change the assessment.