Methodology
The short version
Breachfolio is a small independent site. Articles are drafted with AI assistance and reviewed by a person before they go live. We write from documentation, vendor sources, and public research rather than from original lab benchmarks, and we say so on every page that needs it. Where we have not tested something ourselves, we do not claim that we have.
Where our information comes from
Most of what we publish is explanatory: how a technique works, how a scam is structured, what a tool is for, what separates two tools that are often confused. That material is built from:
- Official vendor and project documentation.
- Primary sources from government and industry bodies, linked inline where we rely on them.
- Published security research and advisories.
- Hands-on familiarity with the tools, where we have it.
When a claim comes from a specific source, we link that source in the sentence that makes the claim, so you can check it rather than take our word for it.
What our comparisons are, and are not
Our comparisons set tools side by side on the things that actually decide which one you should pick: what each is designed for, licensing and real cost, where each breaks down, and who each suits. They are researched comparisons, not benchmark results.
They are not lab benchmarks. We do not publish timing figures, throughput numbers, or scores from a controlled test rig, because we do not run one. If you need reproducible performance numbers for a purchasing decision, benchmark the tools yourself on your own hardware and workload. Anyone quoting exact figures without publishing the rig, the versions, and the method is asking you to trust a number you cannot check.
Lab walkthroughs
The Lab section is different. Those are step-by-step guides for building an isolated practice environment on your own machine, using intentionally-vulnerable targets made for training. Everything there is meant to run on hardware you own, on a network segment that touches nothing else. We never scan, probe, or interact with a system we do not own, and neither should you.
Use of AI tooling
This matters enough to state plainly rather than bury. Articles on Breachfolio are drafted with AI assistance. Drafting, editing, translation between English and Spanish, and some illustrations are produced that way. A person selects each topic, reviews the draft, and approves publication; nothing publishes automatically.
What AI assistance does not do is turn research into testing. It speeds up writing an explanation; it does not give us numbers we did not measure. That is why this page no longer claims a test rig we do not have.
Independence
We take no payment from vendors for coverage, ratings, mentions, or placement, and nothing here is sponsored. The site carries third-party display advertising, which is served by an ad network and has no bearing on what we write or how a tool is assessed. Details are on the disclosures page.
When we are wrong
If a vendor or reader points out a factual error, we correct the article, note the correction at the top, and keep the original wording visible. We do not silently rewrite history. Corrections and questions go to the contact page.