The Method, In Public
Method 2.1 · Rule Set 6fd4f6
This page states what an assessment does, what its words mean, and what every result carries so it can be checked or corrected. The rules it runs are not published — see the last section for what is held back and why.
1. What This Is, And What It Is Not
This method reads what a company has published about how it handles data, and records what was found. It is a reading of documents. It is not an audit, not a rating, and not an opinion about whether a company is safe to buy from.
Three things follow from that, and they hold everywhere:
- Silence is recorded as silence. A question with no published answer is Not Published. It is never recorded as a No, and never as a failure.
- An absence is only an absence where the document was read. Where a document was behind a request, or could not be read by a machine, the state is Not Determined with the reason named — never Not Published.
- No vocabulary here says Compliant, Pass or Fail. Those are legal conclusions about a company. This is a record of what is on its pages.
Every finding carries the source address, the words that matched, and the sentence around them. A reader who disagrees with a finding is looking at the same evidence it was made from.
2. The Five Words We Use
Five words, and they never change meaning — not between rules, not between countries, and not between a free check and a paid assessment.
| Shown As | Means |
|---|---|
| ▲ Not Published | Documents were read, and none of them says it. |
| ◐ Partly | Something is said, and it stops short of the question asked. |
| ● Published | The document says it, and the words are quotable. |
| ◆ Consistent | Nothing published contradicts what is claimed, or the question does not arise for this company. |
| ○ Not Determined | The document could not be read, and the reason is named. Never a polite way of saying we did not look. |
3. What Is Read
A company's own published pages, fetched from its own domain, and nothing else. No questionnaire, no interview, nothing bought from a third party, and nothing asked of the company itself.
A page that cannot be found, is behind a login or a request form, or is assembled in the browser where a machine never sees the text, is recorded as exactly that. Which documents are looked for, at which addresses, how they are found, and the guards that decide whether what came back is the document at all are part of the engine and are not published.
4. The Data Usage Lifecycle
Called the Data Usage Lifecycle Stages in a result. A result reports how much of that lifecycle a company’s own documents actually describe — the path data takes from the reason it was collected to the moment it is deleted. Each stage is reported Published where a document read says it, Not Published where documents were read and none of them does, and Not Determined where no document could be read at all.
A result names the stages it examined, because those are the labels on that company’s own finding. What the full set is, what a document has to say for a stage to count as described, and how one stage bears on the next are part of the method and are not published here.
5. The Observation Points
Called the Observation Points in a result: the questions a reader asks first, whichever country they are reading from. Each one is answered in one of the five words above, with the evidence attached.
A result names the points it examined for that company. Which questions make up the set, what a page has to say to answer each one, and the order they are asked in are not published here.
6. The Prime Jurisdictions
Called the Prime Jurisdictions in a result. The same read, answered from more than one position. The facts do not change between them; the question being asked of those facts does.
Which positions are read, which obligations each one turns on, what a page has to say to answer it, and in what order the questions are asked are part of the rule set and are not published.
A country card never says a law applies to a company. It records what that company’s pages establish for a reader in that country. Whether the law actually applies is a legal question about the company, and this assessment does not answer it.
7. How Far A Read Got
Called the AI Reading Gates in a result. Reading a document runs as a chain of steps in a fixed order. The steps are not a second opinion about the document. They are the record of how far the read actually got with it. A step is never marked Failed. A read that stops partway never tried what came after, and never tried is reported as never tried — because “we could not read it” and “it is not there” are different findings that reach most readers as the same sentence.
A result shows where its own read stopped, and says of everything after that point that it is untested rather than failed. It also marks a step Not In Scope where a Quick Review deliberately leaves it out — not failed, and not missed. How many steps there are, what each one tests, what counts as clearing it, and the order the tests inside it run in are part of the rule set and are not published.
8. Who Reads The Result
Called the Business Uses in a result. This is not three checks. It is one check, read by three different people. The facts do not change between them. Each person asks a different question of the same evidence; none of them gets a different answer.
- Sales And Procurement — Can this vendor be evaluated without contacting them?
- Operations And Delivery — Who actually delivers this, and where does the work happen?
- Risk, Legal And Compliance — What must a legal reviewer establish before signing?
9. The Companies We Compare You With
Called the Peers in a result. Three companies we have already assessed that publish the most similar answers at the points being compared. They are picked by a written rule, not chosen by hand, so the same company always draws the same three.
No name, no count, and no population figure is shown — only what each of the three publishes at the point being compared. How many companies have been assessed, who they are, and how they answered in aggregate are the research, and the research is not published. Naming a peer is part of the paid review.
10. What Every Result Carries
A result is meant to be argued with, so it is stamped:
- The rule set id (
6fd4f6today) — a six-character fingerprint of the exact rules that ran. Two results carrying the same id were produced by identical rules. A different id means something in the method moved, and it is meant to be visible. - The reference and the date — which run this was, and when the pages were fetched. Evidence is dated, because a website changes.
- The evidence behind each finding — the source address, the matched words and the sentence around them.
Right of reply. Anything recorded here was read off a public page, and pages change. A correction with evidence is made before anything else, free, and the record says it was corrected. Write to ror@blacksnowintel.com.
11. How We Track Changes To The Method
Two ids, published separately, because they move for different reasons.
- The rule set id changes when a judgement we wrote changes — a phrase, a country, the order the tests run in, how much a point counts, or the wording published beside one. Rules change when the judgement changes, never quietly.
- The corpus id changes when more companies are assessed. Its contents — which companies, and how they answered — are not published. A single headline count of companies assessed is, and is the only figure taken from it.
A result that cites an id can always be placed against the version that produced it, which is the part that makes an old finding auditable rather than deniable.
12. What Is Not Published Here, And Why
Held back, deliberately:
- The phrases the engine looks for, and the documents each phrase is legitimate on.
- The country list and the wording that decides what a country name on a page means.
- The order the tests inside each rule are run in.
- How many steps a read runs, what each one tests, and what counts as clearing it.
- Which questions make up the set, which of them each country reads, in what order, and what a page has to say to answer each one.
- How much each point counts for each reader, and how that is decided.
- The research behind the assessments: which companies are in it, how they answered, and any rate drawn from them. One headline count of companies assessed is published, and nothing beneath it — no names, no breakdown, no base rate beside a result.
These are the method. Published in full, they would let anyone re-run the judgement without the work that produced it — and the work is the product. What is published instead is everything a reader needs to check a finding about themselves: the evidence it rests on, the vocabulary it uses, the id of the rules that produced it, and a free route to correct it.
Any company assessed can have the full method, applied to its own record, in the paid review.