Methodology v1.0 · Released August 2026

How we inspect a hardware-confidence claim.

Our reviews separate what a mechanism technically produces from the institutional conclusion placed on top of it. Scores describe the claim; they are not a composite quality grade.

01

Review sequence

  1. Locate the primitive.

    Identify the counter, key, enclave, timing protocol, verifier, or license mechanism doing the technical work.

  2. Draw the claim boundary.

    Record what the primitive can establish and what remains a decision about identity, policy, legitimacy, intent, or enforcement.

  3. Register trust.

    List the independent systems and institutions that must remain correct, available, uncompromised, and mutually consistent.

  4. Present caveats first.

    State the source’s strongest limitations and explicit exclusions before adding editorial assessment.

  5. Specify falsifiers.

    Describe tests or evidence that would materially change the assessment.

02

Three descriptive scores

Adversary realism

How closely the analyzed adversary matches the actor relevant to the policy claim.

  1. 1Benign faults
  2. 2Remote outsider
  3. 3Bounded insider
  4. 4Malicious operator
  5. 5State-scale physical or supply-chain actor

Trusted dependency count

The number of independent trust domains that must hold for the claimed assurance.

  1. 1Primitive alone
  2. 21–2 domains
  3. 33–4 domains
  4. 45–7 domains
  5. 58+ or strongly correlated domains

Policy reach

The distance between the technical observation and the policy outcome it is asked to support.

  1. 1Local machine property
  2. 2Execution or anomaly claim
  3. 3Workload compliance
  4. 4Usage or export-control outcome
  5. 5Safety or international-governance conclusion
03

Interpretive limits

A high adversary-realism score is not criticism. A high dependency score does not mean those dependencies are implausible. A high policy-reach score does not mean the policy objective is undesirable. The useful question is whether the dependency chain is visible and whether the mechanism is being credited with more assurance than it produces.

When a limitation cannot be found in the reviewed material, records say “not located.” They do not say the authors ignored it. Case files are versioned because source revisions may change the assessment.