Terms, corrections and right of reply
This registry is built to publish findings about named companies once it is safe to stand behind them. It does not yet: what is below states who would publish them, what a score does and does not mean, and how to check or correct anything that already appears — under a pseudonym, not a name.
For information only. Not advice, and not to be relied on.
- Everything here is published for general informational and educational purposes. It is a description of what documents say, not a recommendation about what to do.
- Nothing here is legal, compliance, regulatory, financial, investment, procurement or safety advice, and reading it creates no advisory or professional relationship of any kind.
- Do not act, or decline to act, on the basis of anything here without your own verification. Every claim names the document it came from and the date it was read, so that verification is possible rather than merely recommended.
- Information ages. A score describes documentation as it stood on a stated date and may not describe what a vendor publishes today.
- It is one input among several. It is not a substitute for your own diligence, your own testing, or advice from someone qualified and accountable to you.
Who publishes this
- Publisher
- not configured — GH_LEGAL_ENTITY
- Governing law and venue
- not configured — GH_LEGAL_JURISDICTION
- Contact
- [email protected]
- Corrections
- [email protected]
What a score is
- A GRI score measures the documentation this registry located about a system at a stated URL on a stated date, against a published method. It does not measure the system.
- A low score means the located documentation is thin. It is not a finding that a vendor governs its models poorly, that a system is unsafe, or that anyone has broken a law or a rule.
- Documentation a vendor holds privately, publishes elsewhere, or supplies to customers under contract is not counted, because this registry cannot see it.
What this is not
- Not an audit, an assurance opinion or an attestation.
- Not a certification, accreditation or approval.
- Not a credit rating or any other regulated rating.
- Not investment, financial, safety or legal advice.
- Not a statement that any system is unlawful, unsafe or non-compliant.
No relationship of any kind is implied between this registry and any company named in it. Product and company names are the marks of their owners and are used to identify the systems described, which is what a registry is for. Nothing here should be read as an endorsement, a disparagement, or a recommendation to buy, avoid or dispose of anything.
How a finding can be checked
- Source and date. Every scored claim names the document it came from and the date that document was fetched.
- A fingerprint of what was read. Each scanned entry records the SHA-256 of the exact document scored. If the document later changes, the registry can still show what it read, and so can you.
- A versioned method. Scores are comparable only within a method version and a weighting profile. Both are shown wherever a score is.
- Scope, applied as a rule. Only systems published by organisations are scored. Individual accounts and test namespaces are excluded — determined mechanically, not case by case, so no entry can be said to have been singled out.
- Nothing invented. The registry holds 55 systems and 1298 claims, of which 0 are fabricated. Seven invented demonstration systems were removed in migration 018; the counter in the site header is computed, so it reports a fabricated entry if one is ever inserted again.
Corrections and right of reply
- Use the request a correction form on the entry itself, or write to [email protected].
- You do not have to be the vendor. Anyone who can point at a factual error may raise one.
- We aim to respond within 10 working days. Where a claim is shown to be wrong it is corrected at once, and the correction is published in the corrections log with its date.
- Where we review and do not change a finding, that is published too, with the reason. A log that records only the corrections we were happy to make would be worth nothing.
- Pointing us at documentation we could not locate is the fastest route to a different score, because a score is a measurement of located documentation. Publishing that documentation changes the number; asking us to change the number does not.
Personal data
The registry describes systems published by organisations, and holds the organisation account names under which they were published. Accounts belonging to individual people are outside its scope and are excluded automatically. If you believe personal data about you appears here, write to [email protected] and it will be removed unless there is a clear public-interest reason to keep it, which we will explain.
Requests to the router are logged as a salted hash of the prompt, never the prompt. Inbound enquiries store the address you give and a salted hash of your IP, kept to throttle abuse.
Requests to this site
Since 13 September 2026, each request to a page or API on this site writes one line to a server log. It exists to show which pages are read, and to tell people apart from crawlers and from automated attacks, which make up most requests to any public site.
Each line records:
- the time, the request method, and the path requested — with the credential in an invitation or examiner link replaced, so a link that grants access is never written down;
- what kind of request it was: a page, an API call, a background fetch made by the page itself, or a request for software this site does not run, of the kind automated attacks send;
- of the query string, only
profileandstate, which change what a page shows and say nothing about you; - a broad category for the software making the request — a browser, a search or AI crawler, a link preview, or another automated client — and, where a crawler names itself, that name;
- the site a link was followed from, as a hostname only; for a link followed from another page of this site, the path of that page;
- the country Cloudflare reports for the connection;
- a visitor identifier: a salted hash of your IP address and browser identification string, which changes every day.
It does not record:
- your IP address, or your browser’s full identification string;
- cookies, form contents, or any other query parameter;
- anything you paste into /scan or /before-you-paste, which run in your browser and send nothing to this server.
The visitor identifier lets a day’s visits be counted without following anyone from one day to the next. It is pseudonymous, not anonymous: combined with other records it could in principle be linked to a connection, which is why it is kept for a limited time and read by no one but the operator of this site.
The log is rotated when it reaches about 2 MB, and only the twenty most recent files are kept; older ones are deleted. At current traffic that is roughly two months, but the limit is the number of files, not a date. No analytics cookies or third-party tracking scripts are used.
Every request also passes through Cloudflare, which carries traffic to this site and processes connection data, including IP addresses, under its own terms. To ask about any of this, write to [email protected].
No warranty, and the limits of liability
This registry is provided as is. Its contents may be incomplete, out of date, or wrong, and a score computed on one date may not describe what a vendor publishes on another. No warranty of accuracy, completeness or fitness for any purpose is given.
Do not use it as the sole basis for a procurement, deployment, compliance or investment decision. It is one input, and it measures documentation. To the fullest extent permitted by the law of not configured — GH_LEGAL_JURISDICTION, the publisher accepts no liability for loss arising from reliance on it. Nothing here excludes liability that cannot lawfully be excluded.