Methodology
Endpoint Index is a structured database of endpoint security products for small and mid-size businesses. Every data point is sourced, dated, and verifiable. This page explains how we collect data, calculate scores, and handle sponsorship.
How we collect data
We source facts from five tiers. Only the first three contribute to the fit score.
| Source tier | Description | Used in fit score? |
|---|---|---|
| The vendor's own product page | Published feature lists, specifications, and documentation on the vendor's domain | Yes |
| The vendor's pricing calculator | Price captured from the vendor's online pricing tool; we capture and keep a dated record of every source | Yes |
| Independent test labs | AV-Test, AV-Comparatives, and MITRE ATT&CK Evaluations — independent third-party testing organisations | Yes |
| Vendor press releases | Announcements or blog posts published by the vendor — shown on the page but not scored | No |
| Third-party sites | Review aggregators, analyst reports, or other non-vendor sources — shown on the page but not scored | No |
Every sourced value carries a link to the source page, the tier it came from, and the date we last verified it. If we cannot verify a value from one of the three scored tiers, it contributes zero to the fit score and displays a label explaining why.
Verification cadence
- Every verification date must be within 90 days. Values older than 90 days flag the product as stale and remove it from comparison verdict eligibility until re-verified.
- We run an automated check weekly: it fetches each source page, detects changes, and flags them for human review. Prices are never updated automatically.
SMB Fit Score
The SMB Fit Score measures how well a product fits a small-business buyer based on publicly verifiable evidence: independent lab testing, published pricing, operational requirements, and capability coverage. It is not a measure of absolute product quality or security effectiveness. A product with strong protection but no independent test results, or no published price, will score lower on those components.
The score is a transparent, formula-driven number from 0 to 100. There is no hidden editorial weighting. Every input, its value, its points, and the total are shown on every product page.
| Component | Weight | How it is scored |
|---|---|---|
| Efficacy | 35 | AV-Test protection score (0 to 6, scaled to 0 to 15 points). AV-Comparatives protection rate: 99.5% and above = 10 points; 99.0% and above = 7 points; below 99.0% = 3 points. MITRE participation with 90% or higher analytic coverage = 10, participated without coverage data = 5, none = 0. No public results = 0 with a label. |
| Price transparency and level | 25 | Published price = 10 points; quote-only = 0. Then per-unit monthly cost: $3 or less = 15; above $3 to $6 = 10; above $6 to $10 = 6; above $10 = 2. |
| SMB operability | 25 | Self-serve purchase = 8; no in-house security staff needed = 7; minimum seats 5 or fewer = 5; setup 4 hours or less = 5. |
| Coverage breadth | 15 | 1 point per included capability (max 15); capabilities available as a paid add-on = 0.5. 13 capabilities tracked. |
Total: 0 to 100. Displayed as an integer with a one-line explanation. The score version (fit-v1) is shown next to the score; changing the formula bumps the version and appears in the changelog.
Lab result freshness
A lab result only earns fit-score points if its test round is within 18 months of today. Older results still appear on the product page for reference but display a "dated" label and contribute zero to the score. This ensures the fit score reflects current independent testing, not historical results that may no longer represent the product's capabilities.
AV-Comparatives scoring boundaries
The AV-Comparatives protection rate maps to points using these exact boundaries:
- 99.5% and above: 10 points
- 99.0% and above: 7 points
- below 99.0%: 3 points
A product with 98.8% protection rate scores 3 points (falls in the "below 99.0%" bracket).
Capability states
Every capability uses one of four states — never free-form text:
- Included — part of the base licence at the listed price
- Add-on — available for an additional fee
- Not offered — not available at this product tier
- Unknown — not yet verified (a product cannot be published with this state in any scored field)
How sponsorship works
Paid placement cannot change a product's score, ranking, inclusion, comparison verdict, or editorial text. Sponsors buy a clearly labelled placement outside the ranking.
Commercial data (affiliate links, sponsor tiers) is stored separately from product data. The scoring and ranking system only reads product and lab data; it never sees commercial fields. This separation is enforced automatically during every build.
Sponsorship and affiliate links
- Affiliate links: marked with a disclosure label. Affiliate status never affects data, scores, or rankings.
- Featured placement: one labelled slot per category page, visually distinct, never counted in the ranking. Available via the vendors page.
- What sponsors cannot buy: changes to data, scores, rankings, or editorial judgments. The methodology, all source links, and the fit-score formula are public.
Category rules
- Antivirus (EPP): the product does not include endpoint detection and response
- EDR: the product includes endpoint detection and response
- EDR with managed response: the product includes both EDR and managed detection and response
A product tier that changes any capability from its parent tier is listed as a separate product.