What «Tested» Means Here
- We verify security claims with hands-on setup, not screenshots or marketing decks.
- We score what changes user risk: key control, recovery, and attack surface.
- We re-check critical settings after updates to catch regressions and new defaults.
- We separate facts, vendor claims, and our observations so readers can audit us.
- We look for independent evidence like public registries and documented audits.
- We disclose conflicts, affiliate relationships, and what we could not test.