The rule
How it is enforced
Policy alone does not survive a quarter with a revenue target, and an open codebase does not enforce it either. Four mechanisms carry the boundary instead.Partly built. The public policy page and the block-level rule are live — the code knows that the Business block never feeds a rating, and a test holds it there. The rest arrives with the rating engine, which is not built yet: there is nothing to isolate from until there is a rating to protect.
Separate data paths
The rating engine and the vendor-commercial modules run as separate services. The commercial tables are not reachable from the rating path — and a test proves the unreachability rather than asserting it.
Restricted inputs
The rating engine accepts
verified and crowd provenance plus analyst inputs. vendor_claimed commercial fields are structurally ineligible as inputs, not filtered out downstream.Isolation tests in CI
Any change touching the boundary requires a test demonstrating the isolation and a second reviewer. Every paid surface is audited in CI as orthogonal to score and to ranking.
A public policy
The ratings-independence policy and the methodology publish as public pages — live now, ahead of the first rating, so the rule is checkable from outside before there is anything to check it against.
Why ratings are framed as opinion
Publishing a named company’s security posture invites a defamation claim. The posture that survives one is well established, and ATX follows it:- Factual, dated, and source-linked. Every rating input traces to a specific public source with the date it was confirmed.
- Opinion grounded in disclosed facts, never an editorialized verdict. The methodology is public and versioned, so a reader can see how facts became a score.
- Right-to-respond, exercised before publication. A vendor sees findings and can respond on the record ahead of a rating going live, not after.
Keeping the layers distinct
Crowd reviews and trust ratings answer different questions and are kept visually and structurally separate on a profile. An aggregated review score reflects practitioner experience; a trust rating reflects source-cited posture. Blending them would let sentiment leak into a security verdict — and would make a brigading campaign a way to move a rating.The commercial argument
The firewall is usually described as a constraint on the business model. It is better read as the business model. Independence is the only reason a buyer would consult a public trust directory rather than a vendor’s own marketing, and it is the thing incumbents extending into this space would find hardest to retrofit. Published as a policy and demonstrated in code, it is a differentiator — which is why it ships on day one rather than once ratings arrive.Pricing and support
Open source, and why paying for support still buys no influence over a score.
Back to the overview
What ATX is, the gap it fills, and the regulation driving it.