How we collect data
Every provider profile is built from publicly available sources:
- Vendor documentation: product pages, datasheets, integration guides, pricing pages.
- Third-party evaluations: MITRE Engenuity ATT&CK evaluations, Gartner Peer Insights, Forrester Wave.
- User reviews from PeerSpot, G2, Reddit (r/msp, r/cybersecurity), and TrustRadius.
- Practitioner blogs and guides, including CISO evaluation frameworks and vendor switching stories.
- Careers pages and LinkedIn for SOC team composition signals.
We don't rank providers
We deliberately avoid ranking MDR providers. “Best MDR” depends entirely on your stack, your team size, your budget, and your compliance requirements. Instead, we surface structured, comparable facts and let you filter by what matters to your organization.
Community sentiment
We aggregate community sentiment from multiple platforms:
- Reddit (r/msp, r/cybersecurity, and related subreddits): we look for recurring themes across multiple threads, not isolated opinions.
- PeerSpot and G2: we focus on low-star reviews to surface post-purchase regrets and common complaints.
- Gartner Peer Insights: verified practitioner reviews with organizational context.
Sentiment labels (Very Positive, Positive, Mixed, Negative) reflect aggregated themes, not star rating averages. A provider rated “Mixed” may have passionate advocates and vocal critics. That context matters more than a number.
The "not published" signal
When a field shows “Not published,” that is itself a data point. A provider that doesn’t publish MTTD/MTTR, disclose analyst-to-customer ratios, or share pricing ranges is making a choice about transparency. We show this absence rather than hiding it.
Editorial policy
Vendors cannot pay to be included in the directory or to change profile facts. Sponsored placements are clearly labeled and do not affect how data is presented, how filtering works, or which providers appear in editorial picks.
How we handle "questions to ask"
Each provider profile includes provider-specific evaluation questions. These are synthesized from:
- Common blind spots identified in user reviews and complaints.
- Areas where the provider’s public documentation is vague or incomplete.
- Known friction points from vendor switching stories.
- Due diligence gaps that CISO evaluation guides highlight.
Update cadence
Provider data is reviewed and updated regularly. The “Last Updated” date on each profile reflects the most recent verification pass. If you notice incorrect or outdated information, we welcome corrections.
For MDR providers
If you’re an MDR provider, you can claim your profile and submit updates. To keep the directory independent, there are clear limits on what a claim can change, and every submission is reviewed before it publishes.
What a vendor can change:
- Factual corrections backed by a public source: coverage, integrations, certifications, regions, response model, and similar structured fields.
- Logo, website link, and the plain description of what the product does.
- With a verified profile, vendor-supplied media in a labeled “From the vendor” section.
What a vendor cannot change:
- Community sentiment. Recurring praise and complaint themes come from real reviews, not from the vendor.
- Caveats, limitations, and the “Not published” markers.
- The editorial fit assessment (“good fit / watch out”) and any comparison verdicts.
- Ranking or ordering. There is none to buy, and a claim does not create one.
No vendor, paying or not, can edit a profile directly. Every submission goes through editorial review, is checked against public sources, and only then publishes. Paying for a sponsorship or a verified profile does not change any of these limits; see the sponsorship policy.