How we review
Last updated: 21 September 2026
Most of the credibility of a review site rests on what it admits it cannot do. This page sets out our method and its limits, so you can weigh what you read here accordingly.
What a review here actually is
It is a documentary review, not a laboratory test. We establish what a product contains, how the category works, where the tier boundaries fall and what the contract commits you to, and we source each of those. We do not produce our own detection or performance numbers.
The method, step by step
- Map the range. Read the vendor’s own product and comparison pages and write down which features sit at which tier. This is where most reader disappointment originates, so it comes first.
- Read the contract. Licence terms, subscription and auto-renewal terms, cancellation and refund conditions, and the text of any “promise” or guarantee. Conditions attached to a guarantee are part of the product.
- Read the privacy notice. Cloud-assisted security software necessarily sends data to the vendor. We look at what and why, and describe it as a trade-off rather than a scandal.
- Consult the independent laboratories. AV-TEST, AV-Comparatives and SE Labs for detection and performance. We read the current round and its methodology, and we point readers at it instead of freezing a score into the page.
- Check the free baseline. What does the operating system already do, and what is the marginal benefit of paying? If the honest answer is “not much, for your situation”, that goes in the article.
- Write the limitations first. We draft the “who should look elsewhere” section before the recommendation. It is a useful discipline: if that section is hard to write, the article is too soft.
- Mark uncertainty in the text. “At the time of writing”, “varies by region”, “we have not measured this”. Hedges are information, not weakness.
- Date it, sign it, cite it. Every article carries a named byline, a publication date and a source list.
What we do not do, and why
- We do not run malware against products ourselves
- Credible detection testing needs a controlled laboratory, a large curated sample set, repeatable infrastructure and full-time staff. We have none of those. A home-made test would produce a number that looked authoritative and meant nothing, so we cite the laboratories that do this properly.
- We do not publish benchmark figures we did not measure
- “Only two per cent CPU impact” is the kind of claim that is easy to write and impossible for a reader to check. If we did not measure it, the number does not appear.
- We do not award scores or stars
- A rating implies a scoring method. Ours would be one person’s judgement dressed as measurement. We write the judgement in sentences instead, where you can see the reasoning and disagree with it.
- We do not publish testimonials
- We have no verified reader base to quote, so any quote would be invented. Invented quotes are fraud, not marketing.
- We do not quote prices
- Prices differ by country, currency and promotion, and go stale within weeks. We send you to the vendor’s page for the current figure and tell you which terms to look at while you are there.
How the commercial side is kept out of the verdict
We are paid a commission on referrals, not on conclusions, and no advertiser reviews our text. In practice the test is whether the unflattering facts survive into the published article. In the current guide they do: it states which advertised features the reviewed tier lacks, notes that a bundled component is available free of charge on its own, and tells readers that the built-in protection in their operating system plus good habits is a reasonable alternative. If you find an article here where the inconvenient facts are missing, that is a failure of this policy and we want to hear about it.
Updating and corrections
Articles are revisited when a vendor changes its tiers, when a cited source is superseded, or when a reader shows us an error. Corrections are dated and described in the article’s own corrections section; we do not overwrite a published claim silently. The full procedure, including what happens if we disagree with you, is in the editorial policy.
Tell us we are wrong: info@vestrovia.online.