Methodology
How euviq turns a claim into something you can act on.
This page explains the model behind every page on euviq: what is recorded, what is derived, and why unknown is never allowed to read as a negative result.
Vendor and Product
A company is not its software.
euviq treats a Vendor (the company) and a Product (the software it publishes) as separate subjects with separate evidence files. A Vendor may publish several Products, each reviewed on its own claims and its own timeline — a strong company file does not make an individual Product verified.
The evidence chain
Claim, evidence, review, state — in that order, every time.
- 01The vendor's word
Claim
A statement about a Vendor or a Product. Recorded exactly as given, never treated as settled.
- 02What backs it
Evidence
A certificate, a register entry, a published document or a direct observation — each with its own source, date and status.
- 03What euviq did
Review
Whether euviq has checked the evidence, when, and by what method. No review yet is shown as no review yet.
- 04The resulting state
Verification state
One of seven states, always attached to a specific claim — never a single figure for a whole Vendor or Product.
Verification states
Seven states. No single score.
Every claim resolves to exactly one of the states below — never a percentage, never a weighted average. Strength and freshness stay visible instead of being compressed into one number.
- Verified
- euviq checked the claim against independent evidence and it holds.
- Evidence reviewed
- Independent evidence is on file; euviq has not yet confirmed the claim in full against it.
- Vendor supplied
- The claim rests on the vendor's own statement. No independent evidence has been obtained.
- Under review
- Evidence has been submitted and is with the euviq evidence desk.
- Outdated
- Independent evidence existed and has lapsed — a certificate expired, for example — and nothing has replaced it.
- Conflicting
- Independent evidence disagrees with the vendor's own statement. euviq reports the disagreement rather than picking a side.
- Unverified
- No evidence has been obtained. The stated value is recorded, not checked.
The rule that matters most
Unknown is not, and never becomes, a negative result.
Absent evidence, an uncoded statement, or evidence that falls short of a requirement's own threshold all resolve to unknown — not to "no". A negative result requires evidence that actually contradicts a claim. Conflicting evidence is reported as conflicting, and stays that way; euviq does not resolve a disagreement in whichever direction would look tidier.
“All customer data is stored within the European Union.”
Vendor statement · Security questionnaire
Checked against an ISO/IEC 27001:2022 certificate issued by an independent certification body.
VerifiedControlled inheritance
Only company facts travel from Vendor to Product.
A small, fixed set of facts — legal entity, registered jurisdiction, headquarters, ownership, parent company — may be inherited by a Product from its Vendor when the Product has not evidenced them itself. Hosting, data residency, certifications and every other operational or compliance fact must be evidenced for the Product directly; a strong Vendor file never fills that gap.
An inherited value can never read stronger than the Vendor's own evidence for it, and it always displays the Vendor it came from. Where a Product evidences a fact itself, that Product-native evidence takes precedence — it is never blended with the inherited value.
Comparison
A view over the evidence, not a second opinion.
Comparison reads the same assessed positions the Vendor and Product pages already show — it opens no separate file and computes no separate score. A decisive difference is only ever raised when the evidence itself supports one: a genuine contradiction, an evidenced negative, evidence that has lapsed while a competitor's is current, or a criterion only one product has actually had reviewed.
Procurement requirements
The buyer's rules, evaluated against the evidence that exists.
A requirement is entirely buyer-authored: its importance (required, preferred or informational), the condition it tests, and the minimum evidence strength it will accept. euviq invents no requirement and assigns no importance — it evaluates the requirement as written against the evidence on file, and nothing more.
Minimum evidence is set per requirement, not once for the whole platform. "The vendor said so" may be enough for one requirement and clearly insufficient for another — the buyer decides which, requirement by requirement.
Why there is no score
Turning evidence into one number is a decision, not a measurement.
There is no agreed method for weighing "required" against "preferred", or a contradiction against an absence, into a single figure. Inventing one would mean euviq making the buyer's decision while presenting it as neutral reporting. euviq reports the evidence and the differences it produces; the weighing is the buyer's, because only the buyer knows what actually matters for this decision.