GRANWORTH
THE GRANWORTH INDEX Methodology · Version 2026-09-02

The method, printed in full

Methodology

How an edition of the Granworth Index is built: what is observed, how the 20-topic score is counted, what an edition is not, and how to check any of it. The method is held fixed across editions so scores compare; changes to it are versioned and dated on this page. Current version: 2026-09-02.

What an edition is not

An edition is not a security assessment, a vulnerability scan, or a gap report — it says nothing about a company's actual security. It records how the trust story reads from the public web. Benchmarking means loading public pages in a logged-out browser: nothing is scanned, nothing is probed, and no system is interacted with beyond loading pages any stranger can load.

The five observed artifacts

Only sales-relevant public trust signals are observed. Per artifact, one observable question:

The five observed trust artifacts and the observable question each answers
ArtifactObservable question
Trust/security pageDoes a public trust or security page exist, and is it linked from the site footer or navigation?
SOC 2 / ISO 27001 visibilityIs the attestation stated publicly? Is the report reachable — self-serve NDA gate, “email us,” or no stated path?
Security answers availabilityOf the 20 standard questionnaire topics below, how many are publicly answerable without emailing anyone? Reported as a count: n/20.
Subprocessor list & DPAIs there a public subprocessor page? Is the DPA downloadable, or on request only?
Enterprise signals on pricingDoes the pricing page name SSO/SAML, audit logs, an SLA — and a BAA where the buyer is in healthcare — on an enterprise tier?

Cells record one of three states — Published, Partial, or Not found (as of the stated date) — each with a URL and a fetch date. “Not found” means not reachable by a public visitor on that date; it never means the thing doesn't exist internally. Every cell is re-verified on the day an edition ships; a cell that can't be re-verified is corrected or its row is cut.

The 20 standard questionnaire topics

Each edition reports, per company, how many of these 20 topics a reviewer can answer from the public web alone — the n/20 figure the side-by-side table and the meters carry. The list is the Index's own rubric: the questions that recur on enterprise security questionnaires, held fixed across editions and disclosed in full so any score can be re-checked. The mapping table below anchors each topic to the public questionnaire standards reviewers use.

01Encryption at rest
Counts when an owned public property states that customer data is encrypted at rest.
02Encryption in transit
Counts when encryption of data in motion (TLS) is stated.
03SSO / SAML
Counts when single sign-on support is stated — product docs or the pricing page both qualify.
04Access control
Counts when the company states how access to customer data is restricted (role-based access, least privilege).
05Subprocessor list
Counts when a list of subprocessors is published.
06Data processing agreement
Counts when a DPA is downloadable or its terms are published — “DPA on request” does not count.
07Data residency
Counts when the company states where customer data is stored (regions or countries).
08Pentest cadence
Counts when third-party penetration testing is stated, with how often.
09Incident response
Counts when an incident response process is stated — notification practice included is stronger, a stated process suffices.
10Backups
Counts when backup practice for customer data is stated.
11Uptime SLA
Counts when an uptime commitment is stated — a status page shows status, not a commitment.
12Vulnerability management
Counts when a program for finding and patching software flaws is stated.
13Employee security training
Counts when security training for staff is stated (background checks strengthen the answer).
14BC/DR
Counts when business continuity / disaster recovery posture is stated — a testing cadence is stronger.
15Vendor risk management
Counts when the company states how it reviews its own vendors.
16Data retention & deletion
Counts when retention terms and deletion on exit are stated.
17Change management
Counts when the company states how production changes are controlled and reviewed.
18Logging & monitoring
Counts when audit logging or monitoring of production systems is stated.
19Physical / hosting security
Counts when the company states where the service is hosted and the physical controls inherited from that provider.
20Compliance report access path
Counts when there is a stated way for a reviewer to obtain the SOC 2 attestation report or ISO 27001 certificate — a self-serve gate counts as answered.

The counting rule

A topic counts as publicly answerable when a logged-out visitor can reach the answer itself — on the company's site, trust center, docs, pricing, or status pages — without emailing anyone, submitting a form, or creating an account.

Sections that defer to “happy to provide details upon request” count as not publicly answerable: the reviewer still has to ask, and the asking is the thing being measured. One exception is deliberate — a report behind a self-serve NDA gate counts for the report-access topic, because the path is public even where the document is not.

Scores are reported as n/20 — arithmetic on the enumerated topics, nothing else. Every edition carries a topic ledger naming which topics counted for each scored company, so any score can be re-checked against the public web as of the edition's date.

Where the topics sit in CAIQ-Lite and SIG

The 20 topics are the Index's rubric, not an industry standard — so here is the anchor an auditor would ask for. CAIQ-Lite is the Cloud Security Alliance's condensed Consensus Assessments Initiative Questionnaire (announced 2019-03-01, drawn from CAIQ v3.0.1 and CCM 3.0.1); the question IDs below use that v3.0.1 numbering, which is what publicly posted CAIQ-Lite responses carry, and were verified against a vendor-published CAIQ-Lite on 2026-09-02. SIG question text and numbering are licensed by Shared Assessments, so the SIG column names the closest risk domain in the SIG library rather than a question ID. Where a topic has no clean anchor, the table says so instead of forcing one.

Mapping of the 20 Index topics to CAIQ-Lite question IDs and SIG risk domains
Index topicCAIQ-Lite anchor (v3.0.1 IDs)Closest SIG risk domainNote
Encryption at restEKM-03.1 · DSI-03.1Asset and Information Management
Encryption in transitDSI-03.2Network SecurityNearest anchor — the CAIQ-Lite question asks about open encryption methodologies for infrastructure communication, not TLS in transit by name.
SSO / SAMLnone in CAIQ-Lite · full CAIQ IAM-12.1Access ControlCAIQ-Lite's IAM questions cover the vendor's own staff access; identity federation (SAML) for customers appears only in the full CAIQ.
Access controlIAM-02.1 · IAM-08.1 · IAM-10.1Access Control
Subprocessor listSTA-05.4 · STA-09.1Supply Chain Risk ManagementNearest anchor — CAIQ asks whether third parties are governed; a published list is a transparency practice no questionnaire mandates.
Data processing agreementno clean mappingPrivacyA contract artifact, not a questionnaire control; reviewers request it alongside the questionnaire.
Data residencyno clean mapping in CAIQ-LiteCloud ServicesReviewers ask it constantly; the Lite set carries no direct storage-geography question.
Pentest cadenceAAC-02.2 · AAC-02.3Threat Management
Incident responseSEF-02.1 · SEF-02.4 · SEF-03.1Cybersecurity Incident Management
BackupsBCR-11.3 · BCR-11.7Operational Resilience
Uptime SLAno clean mappingA commercial term — it lives in the order form, not in a control questionnaire. Buyers check for it anyway, so the Index counts it.
Vulnerability managementTVM-01.1 · TVM-02.5Threat Management
Employee security trainingHRS-09.5 · HRS-02.1Human Resources Security
BC/DRBCR-02.1Operational Resilience
Vendor risk managementSTA-09.1Supply Chain Risk Management
Data retention & deletionBCR-11.1 · DSI-07.1 · DSI-07.2Privacy
Change managementCCC-04.1 · GRM-01.1IT Operations ManagementThe Lite set keeps a narrow slice of the CAIQ change-control domain; the topic is broader.
Logging & monitoringIVS-01.1 · IVS-01.5 · IAM-01.2IT Operations Management
Physical / hosting securityDCS-02.1 · DCS-09.1Cloud ServicesFor cloud-hosted vendors these controls are typically inherited from the hosting provider; the public answer names the provider and the inheritance.
Compliance report access pathAAC-02.1Compliance and Operational RiskAAC-02.1 asks exactly this: whether buyers can view the SOC 2 / ISO 27001 report.

Sources: cloudsecurityalliance.org/blog/2019/03/01/introducing-caiq-lite (CAIQ-Lite scope and lineage) · octopus.com/docs/security/caiq (a vendor-published CAIQ-Lite response; question IDs verified against it 2026-09-02) · upguard.com/blog/sig-questionnaire (SIG risk-domain names, fetched 2026-09-02).

CSA's current CAIQ v4 reorganizes these domains — encryption moves to CEK, data lifecycle to DSP — without changing what the topics ask. The Index cites v3.0.1 IDs because publicly posted CAIQ-Lite responses use them.

The build stamp

Every edition carries a 16-character build id, in a meta tag and printed in its footer. It is a content fingerprint: the first 16 hex characters of a SHA-256 digest computed over the edition's template and source text. The same sources always recompute to the same id; a single changed byte changes it.

What it is for: provenance of copies. An edition is a single self-contained file — zero JavaScript, no external requests, fonts embedded — so it gets forwarded, and a forwarded copy can be checked: compare its footer build id and its bytes against the edition published here. Matching ids on matching bytes mean an unaltered copy. The id is recomputable, which means it can be caught wrong — that is the point.

The self-contained posture is also why every edition's “No scripts, no tracking” line is checkable in the file's own source: an edition renders identically offline, and a correction changes the build id in the open.

Corrections — free, forever

If anything in a published edition is out of date or wrong, tell the author: linkedin.com/in/jgarcia2. Expect a response within 24 hours. The edition is corrected, rebuilt — which changes its build id in the open — republished here, and re-sent to whoever received it. This holds whether or not anyone ever books anything, on every edition, with no expiry.