Skip to main content
assurance support

For businesses

Evidence, not promises

A vendor can tell you their application is secure. An Assurance.Support record shows you what was independently reviewed, at which version, and what is still open.

Due diligence

How to read a verification record

Eight checks that take five minutes and materially reduce software-purchasing risk.

  1. 01

    Check the application name

    Confirm the record describes the exact application you are evaluating — not a similarly named product or a different offering from the same developer.

  2. 02

    Check the reviewed version

    Verification applies to a specific version and source commit. Ask the vendor which version you would be running and confirm it matches the record.

  3. 03

    Check the issue and expiration dates

    Every record shows when the review was completed and when the verification expires. An expired record means the application has not been recently re-reviewed.

  4. 04

    Review the conditions

    A record marked Verified with Conditions lists ongoing obligations, such as quarterly dependency reviews. Ask the vendor how they are meeting each one.

  5. 05

    Confirm the deployment scope

    The record documents which deployment was reviewed — for example, the production web application and its documented API. Confirm the deployment you would use is the one that was assessed.

  6. 06

    Understand the exclusions

    Excluded components were not reviewed and are not covered. If an exclusion matters to your use case — such as a payment integration — factor that into your evaluation.

  7. 07

    Check whether verification is active

    The public record always shows the current status. A verification can be suspended or revoked before its expiration date, so check the live record rather than a screenshot or PDF.

  8. 08

    Report suspected badge misuse

    If an application displays an Assurance.Support badge but has no matching active record — or the record does not match the version being sold — report it through our contact page. We investigate every report.

What verification does not mean

An Assurance.Support verification is an independent technical review within a documented scope — it is not a guarantee that software is free from every defect or vulnerability, and it is not legal or regulatory certification. Use it as one strong input in your evaluation, alongside your own requirements for support, contracts, and compliance.

Evaluating software without a verification record? You can request an independent assessment of an application you are considering, with the software owner's authorization. Contact us to arrange it.

Check before you commit.

Look up any application in the public verification registry.