Skip to content

How We Test

Method

Every rating is earned through repeatable, hands-on security checks.

See Reviews
Summary

What «Tested» Means Here

  • We verify security claims with hands-on setup, not screenshots or marketing decks.
  • We score what changes user risk: key control, recovery, and attack surface.
  • We re-check critical settings after updates to catch regressions and new defaults.
  • We separate facts, vendor claims, and our observations so readers can audit us.
  • We look for independent evidence like public registries and documented audits.
  • We disclose conflicts, affiliate relationships, and what we could not test.

Our Testing Workflow

Each review follows the same sequence so scores stay comparable across wallets and exchanges, even when products target different types of users.

  1. Scope the threat model

    We define who the product is for, what it protects (keys, identity, funds), and the realistic attacker paths before we touch settings.

  2. Validate key control

    We confirm where secrets live, how approvals work, how recovery is performed, and what happens under device loss, phishing, or compromised endpoints.

  3. Attack-surface review

    We test security-critical flows (signing, withdrawals, device pairing, backups), check permissions and network behavior, and look for unsafe defaults and foot-guns.

  4. Score and document

    We translate findings into a consistent scorecard, publish evidence notes, list limitations, and update the review when major releases change security posture.

If we cannot verify a claim, we label it unverified.

9 / 10

Methodology Scorecard

A repeatable process designed to reduce hype, surface risk, and stay comparable over time.

Rigor
9
Evidence
9
Repeatability
8
Bias
9
Clarity
10

Lab Setup

Time 3–7 days Difficulty Intermediate Budget $0 to read

Tools

  • iOS device
  • Android device
  • Clean laptop profile
  • Password manager
  • Hardware security key
  • Network monitor
  • Test email inbox
  • 2FA authenticator

Materials

  • Burner accounts
  • Test seed backup
  • Offline notes
  • Update log
  • Threat checklist
  • Recovery checklist
  • Screenshot archive
  • Change tracker

Common Questions About Our Testing

These are the questions we get most often about how our scores are produced and maintained.

Do you do hands-on testing?

Yes. We install, configure, and use the product on real devices, walk through backups and recovery, and exercise security-critical flows. We avoid «review by press release» whenever possible.

How do you handle updates?

We track meaningful updates and re-check the security controls that tend to change: authentication options, recovery paths, approval steps, and default settings. If an update changes risk, we update the review.

Do you use security standards?

We use checklists inspired by widely used security verification standards for web and mobile apps to avoid blind spots, while still focusing on user-impact risks.

What about identity and authentication?

We evaluate the strength and usability of authentication, account recovery, and lifecycle controls (including lockouts and reset paths) because those are frequent real-world failure points.

How do affiliate links affect scores?

They do not. Scoring is driven by the same rubric and evidence notes regardless of monetization. If a page contains affiliate links, we disclose it clearly so readers can factor it in.

Disclosure Some pages may contain affiliate links. If you use those links, CryptoGuardian may earn a commission at no extra cost to you. Our methodology and scores are designed to remain independent of compensation.