What we measure, and how it earns your trust
Watch a score earn itself.
ShipReady reads the evidence in the systems your teams already run and scores the health of your technology estate. 300+ signals go in. Four integrity gates decide what survives: criticals cap the score, thin coverage discounts it, and anything unproven reads Not measured, never a fabricated zero. Below is the actual mechanism, live.
Stress-test it yourself. Every number holds its ground.
Read-only connections · your first score comes from your own evidence, typically the day you connect · self-serve, no sales call required
The scoring bench · ShipReady Method v1 · illustrative estate
Signal ledger · Security Readiness
Derivation
The method
Every number earns its way through four gates.
This is the measurement method in full. Each clause below is the complete rule you just fired on the bench, not a summary. Most scoring products have none of these; each one exists because of a specific way dashboards mislead. The full scoring methodology is public at shipreadymetrics.com/methodology.
§1 · CRITICAL CAP
A healthy average can't hide a critical.
One actively exploited vulnerability (CISA KEV) caps the domain at 30, and any open critical caps it at 50. The executive's number refuses to look fine until the risk that deserves attention is resolved.
fires on the bench: Introduce a CISA KEV
Read the full clause +
§1.1 A finding on CISA's Known Exploited Vulnerabilities list caps Security Readiness at 30 while open. §1.2 Any open critical-severity finding caps it at 50. §1.3 A business-critical asset past end-of-life floors Lifecycle Risk. Caps apply to the VALUE and are never softened by confidence. Markers: CISA KEV incident cap · Critical-vulnerability score cap · EOL anti-dilution floor.
§2 · COVERAGE DISCOUNT
Thin evidence buys less score.
Confidence scales the domain's composite weight: two-plus sources ×1.0, one source with corroborating signals ×0.8, less than that ×0.55. At low confidence the letter grade is withheld, never guessed. Coverage is confidence, and confidence is earned.
fires on the bench: Drop to a single source
Read the full clause +
§2.1 Confidence is derived from independent sources and signals: 2+ sources → high (×1.0), 1 source + 2 signals → medium (×0.8), else low (×0.55). §2.2 The factor scales the domain's weight in the ShipReady composite. §2.3 At low confidence the letter grade is withheld, displayed as “—”, never guessed. Markers: Coverage-weighted confidence · Evidence freshness gate · Honest compliance denominator.
§3 · NOT-MEASURED NULL
Unknown never reads as good.
A dark scanner doesn't produce a clean zero. It produces Not measured, a shrunken denominator, and a blind-scanner alarm. Hiding the evidence can never restore your score.
fires on the bench: Disconnect the scanner
Read the full clause +
§3.1 A signal with no producing source reads Not measured and leaves the denominator; it never backfills a zero. §3.2 A scanner whose coverage collapses raises the blind-scanner alarm; its findings read unknown, not clean. §3.3 A previously earned score returns only when its evidence does. Markers: Blind-scanner alarm · MTTR not-measured rule · AI-readiness coverage disclosure.
§4 · PROVENANCE WALL
Measured and modeled never blend.
Scanned facts, survey answers, and modeled dollars are labeled and kept apart. Preview deploys don't count as production. An AI-drafted document can support a control, but it can never declare one met.
holds everywhere: every rationale names its evidence
Read the full clause +
§4.1 Every rationale names its evidence: scanned, self-reported, or modeled, never blended. §4.2 Deployment metrics count production only. §4.3 The same CVE across repos counts once, at worst severity, with the raw-vs-distinct gap disclosed. §4.4 An AI-drafted document routes to a named human; it can never declare a control met. Markers: Provenance split · Production-only DORA · Distinct-CVE dedup · AI-attestation boundary.
Straight answers
The questions every Technology leader asks.
Each answer below is guaranteed by a gate, not by copywriting. Why the audit question got urgent →
Are our teams following best practices?
Checked, not asked.
Thirteen practice markers read straight from your repos and pipelines: tests, type/lint guardrails, protected branches, CI automation, containers, IaC, AI-context docs, and real production delivery cadence. The repos that fall short are named.
guaranteed by §4 · Test-suite presence · Guardrails · Protected branches · CI automation · Production-only DORA · Containers · IaC · +6 more
Where is our biggest risk?
It can't hide in an average.
One actively-exploited vulnerability caps the score at 30. Exploited-in-the-wild findings outrank what a severity formula says.
guaranteed by §1 · CISA KEV cap · Critical-vuln cap · EPSS probability · Exploitation-first triage · +4 more
Can we safely scale AI?
Only as safely as the engineering under it.
ShipReady measures the foundation AI multiplies, and whether agent work survives review and verification, not how busy the tools are.
guaranteed by §4 · Engineering readiness for AI · Agent outcome durability · Agent verification · +9 more
What's about to become an emergency?
The countdown is already running.
Every runtime is tracked against its end-of-support deadline, weighted by criticality and instance count. One critical past EOL sets the grade.
guaranteed by §1 · EOL catalog · Anti-dilution floor · Instance-exposure weighting · +1 more
Could we pass an audit today?
Evidence says, not optimism.
Unassessed controls stay in the denominator, evidence past its cadence stops counting, and an AI draft can support a control but never declare it met.
guaranteed by §2 · Honest denominator · Evidence freshness gate · AI-attestation boundary · +3 more
Can we trust the numbers?
It knows its limits.
Thin domains lose weight and their grade is withheld. Where there's no evidence, ShipReady says Not measured, the most honest thing a metrics product can say.
guaranteed by §3 · Coverage-weighted confidence · Provenance split · No-fake-0/100 quantizer · +1 more
Built for the people who sign
Every quarter already runs on these numbers.
The only question is whether they are evidence or estimates. ShipReady replaces the quarterly spreadsheet census and the pre-board scramble with a number that is already assembled and already defensible. Here is what each seat gets.
CTO · CISO
A number you can defend.
When the board asks why the score moved, the answer is on the screen: the marker, the finding, the evidence, the gate that held. Hostile questioning is the design condition, not the failure mode.
CFO
Figures finance can actually use.
Measured and modeled dollars never blend, so the numbers that reach finance carry their provenance. One prioritized agenda replaces competing anecdotes when capital gets allocated.
CEO · Board · PE
An answer, not another dashboard.
What is healthy, what is risky, what to fix first, in one board-ready pack generated from the same evidence. When diligence arrives, the trail is already built.
The evidence under the method
The 45 markers that anchor 300+ live signals.
A curated, buyer-facing view of the measurement engine. Every marker shows what it observes, the evidence behind it, which score it feeds, and the gate it can trigger. Depth is the proof.
Showing 45 of 45 markers · a curated view of 300+ live signals · §n = the gate this marker can trigger
§0 · Refusals, where we draw the line
ShipReady does not:
Knowing what not to fabricate is the first principle of a score you can defend.
Method questions
Asked by every serious evaluator.
Do you need access to our source code?
No. ShipReady connects with least-privilege, read-only scopes and reads metadata, configuration, findings, and delivery events. It never reads your source. Every connector's exact scopes are documented before you grant them.
What happens on day one, with partial coverage?
You get an honest partial picture: measured domains score, unmeasured ones read Not measured, and thin domains carry a visibly discounted weight. The score gets stronger as evidence connects. It never pretends to be stronger first.
How do you decide what we should fix first?
By exploitation evidence and exposure, not raw counts: CISA KEV first, then EPSS exploitation probability, then severity, each weighted by business criticality and instance exposure. The agenda names the few things that move the score most.
What does it cost, and how do we start?
Plans are published on the pricing page. You can start self-serve, connect read-only, and see your first score from your own evidence before you ever talk to sales.
Is a ShipReady Score an audit or certification?
No, and it will tell you so on every surface. It's a readiness indicator computed from your own evidence, built so that when an auditor does arrive, the evidence trail is already there.
See it on your estate
Run the method on your technology.
Connect read-only and get your first ShipReady Score from your own evidence, or book a demo and we'll walk your hardest questions through the gates. The decisions will be made either way. This is the difference between making them on evidence and making them on estimates.
Plans are published at shipreadymetrics.com/pricing. If we can't measure it, your report will say so. · ShipReady is a readiness indicator from your own evidence, not an audit or certification.