Each profile on this site is an independent analysis of a cybersecurity company's market position and product strategy. AI produces the analysis autonomously from public sources. It's based on the published frameworks, with the same questions and the same scoring scales across companies. You can trace the claims to the public sources behind them.
A profile of a cybersecurity company is designed to help you:
Every profile starts from what a company and others have made public online. That includes the company's own pages, press coverage, regulatory filings, and independent research.
The analysis is independent of the companies it covers. No company sees its profile before publication, pays for it, or takes part in the work.
What a source can support depends on the kind of source it is. A vendor's own page is fine for describing what a product is and does. A comparative claim needs a source with no stake in the answer, such as research or independent reporting. The same holds for any claim that a control works as promised. A vendor's homepage is not enough for that.
The claims a profile makes are tied to their sources and the dates when they were retrieved. A claim is only as good as the source behind it. When the public record has a gap, the profile notes it where practical.
AI runs every company through the same three published frameworks. Each framework is a fixed set of questions, and asking them of every company keeps the profiles comparable to each other:
AI computes a score for two of the three frameworks. For market readiness, it rates eight dimensions 1 to 5 and adds them, for a total out of 40. For defensibility, it rates seven dimensions 1 to 3 and adds them, for a total from 7 to 21. Each profile leads with a plain-language band rather than the raw number. The band is the durable signal, and the exact total is a judgment that could differ by a point or two. The raw total still stays beside the band, so you can see the number behind the word.
Each score is an analytical opinion that automated analysis develops from the cited public sources and any other materials the profile identifies. A score is not a cybersecurity audit, a product certification, an investment report, a procurement recommendation, or an evaluation of the quality of any product or service. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation. The underlying sources may be incomplete, outdated, or superseded, and reasonable people can weigh them differently. Use a profile as a research aid and verify anything you plan to act on.
Market readiness, out of 40, has three bands:
| Band | Total | What it means |
|---|---|---|
| Emerging | 24 or below | Below the typical band, where few analyzed companies sit. |
| Established | 25 to 30 | The typical band, where most analyzed companies land. |
| Advanced | 31 or above | Above the typical band, which few analyzed companies reach. |
Defensibility, from 7 to 21, has three bands:
| Band | Total | What it means |
|---|---|---|
| Exposed | 12 or below | The position is exposed as AI lowers the cost of building commodity software. |
| Contested | 13 to 14 | A moat exists but is under pressure. |
| Defensible | 15 or above | A position that stays hard for rivals to replicate. |
The bands reflect where companies actually score, rather than cut points on a theoretical scale, so the middle band is the typical zone in this data corpus. They come from the spread of scores across the companies analyzed so far, and they shift as that set grows. A company in an outer band scores clearly above or below its peers.
Some companies do not have enough public record to analyze responsibly, and those get no scores at all. A company qualifies for scoring only when four things are true: a confirmable identity and legal entity, a product described beyond a tagline, an independent footprint beyond its own pages, and identifiable leadership. A company that misses these gets a short note on what its record lacks instead of a number.
Each profile can include a placement on one or both of two matrices. Each matrix organizes the defense landscape a different way. You can see where a product fits and which cells it covers.
Which matrix applies depends on what the product secures. The Cyber Defense Matrix covers security products in general, across five asset classes and five security functions. The AI Defense Matrix covers products that secure AI, across eight AI asset classes and six functions. Both come from Sounil Yu, who created the AI Defense Matrix with Lenny Zeltser.
Companies cannot pay for coverage, favorable treatment, higher scores, suppression of criticism, or removal of competitors. If Zeltser Security Corp has a material commercial relationship with a profiled company, that company's profile discloses it. The correction channel is open to readers and profiled companies alike, regardless of any relationship with us.
AI performs every step of the analysis and makes every judgment itself. AI gathers the public sources and checks that the record is sufficient. It scores each framework, maps the company onto the matrices, and writes the profile. AI holds every company to the same questions, the same scales, and the same evidence bar.
A profile's scores, summaries, and matrix placements are statements of opinion, not statements of fact. AI forms them by weighing the public sources each profile cites, and reasonable people can weigh the same sources differently.
Working only from public material has limits worth stating plainly. AI doesn't see a company's private metrics, customer references, or internal roadmaps, because none of them is public. A company doing important work quietly will look thinner than one that publishes often. Each profile is a snapshot, and a company can change long after its public claims went up.
AI can misread a source or miss the context a domain expert would catch. Treat a profile as one informed opinion, and check anything you plan to act on against the company's current materials.