What we measure, and how it earns your trust

Watch a score earn itself.

ShipReady reads the evidence in the systems your teams already run and scores the health of your technology estate. 300+ signals go in. Four integrity gates decide what survives: criticals cap the score, thin coverage discounts it, and anything unproven reads Not measured, never a fabricated zero. Below is the actual mechanism, live.

Stress-test it yourself. Every number holds its ground.

Read-only connections · your first score comes from your own evidence, typically the day you connect · self-serve, no sales call required

Read-only scopes300+ technology signals9 health scores72 evidence collectors560+ controls · 22 frameworks

The scoring bench · ShipReady Method v1 · illustrative estate

Signal ledger · Security Readiness

CISA KEV exposurenone detected
Open critical CVEs0
Scanning coverage54 / 58 repos
Finding SLA agingwithin SLA
Branch protection41 / 58 repos
Evidence sources3 connected

Derivation

base (91×.25 + 88×.25 + 76×.25 + 77×.25) = 83
§1 no critical present — no cap fires
→ 83
83grade B · Strong
Mirrors the production gate rules: KEV cap 30 · critical cap 50 · coverage factors ×1.0 / ×0.8 / ×0.55 · grade withheld on low confidence · unmeasured never reads as zero. Simplified single-domain estate; inputs illustrative.Run it on your estate →

The method

Every number earns its way through four gates.

This is the measurement method in full. Each clause below is the complete rule you just fired on the bench, not a summary. Most scoring products have none of these; each one exists because of a specific way dashboards mislead. The full scoring methodology is public at shipreadymetrics.com/methodology.

§1 · CRITICAL CAP

A healthy average can't hide a critical.

One actively exploited vulnerability (CISA KEV) caps the domain at 30, and any open critical caps it at 50. The executive's number refuses to look fine until the risk that deserves attention is resolved.

fires on the bench: Introduce a CISA KEV

Read the full clause +

§1.1 A finding on CISA's Known Exploited Vulnerabilities list caps Security Readiness at 30 while open. §1.2 Any open critical-severity finding caps it at 50. §1.3 A business-critical asset past end-of-life floors Lifecycle Risk. Caps apply to the VALUE and are never softened by confidence. Markers: CISA KEV incident cap · Critical-vulnerability score cap · EOL anti-dilution floor.

§2 · COVERAGE DISCOUNT

Thin evidence buys less score.

Confidence scales the domain's composite weight: two-plus sources ×1.0, one source with corroborating signals ×0.8, less than that ×0.55. At low confidence the letter grade is withheld, never guessed. Coverage is confidence, and confidence is earned.

fires on the bench: Drop to a single source

Read the full clause +

§2.1 Confidence is derived from independent sources and signals: 2+ sources → high (×1.0), 1 source + 2 signals → medium (×0.8), else low (×0.55). §2.2 The factor scales the domain's weight in the ShipReady composite. §2.3 At low confidence the letter grade is withheld, displayed as “—”, never guessed. Markers: Coverage-weighted confidence · Evidence freshness gate · Honest compliance denominator.

§3 · NOT-MEASURED NULL

Unknown never reads as good.

A dark scanner doesn't produce a clean zero. It produces Not measured, a shrunken denominator, and a blind-scanner alarm. Hiding the evidence can never restore your score.

fires on the bench: Disconnect the scanner

Read the full clause +

§3.1 A signal with no producing source reads Not measured and leaves the denominator; it never backfills a zero. §3.2 A scanner whose coverage collapses raises the blind-scanner alarm; its findings read unknown, not clean. §3.3 A previously earned score returns only when its evidence does. Markers: Blind-scanner alarm · MTTR not-measured rule · AI-readiness coverage disclosure.

§4 · PROVENANCE WALL

Measured and modeled never blend.

Scanned facts, survey answers, and modeled dollars are labeled and kept apart. Preview deploys don't count as production. An AI-drafted document can support a control, but it can never declare one met.

holds everywhere: every rationale names its evidence

Read the full clause +

§4.1 Every rationale names its evidence: scanned, self-reported, or modeled, never blended. §4.2 Deployment metrics count production only. §4.3 The same CVE across repos counts once, at worst severity, with the raw-vs-distinct gap disclosed. §4.4 An AI-drafted document routes to a named human; it can never declare a control met. Markers: Provenance split · Production-only DORA · Distinct-CVE dedup · AI-attestation boundary.

Straight answers

The questions every Technology leader asks.

Each answer below is guaranteed by a gate, not by copywriting. Why the audit question got urgent →

Are our teams following best practices?

Checked, not asked.

Thirteen practice markers read straight from your repos and pipelines: tests, type/lint guardrails, protected branches, CI automation, containers, IaC, AI-context docs, and real production delivery cadence. The repos that fall short are named.

guaranteed by §4 · Test-suite presence · Guardrails · Protected branches · CI automation · Production-only DORA · Containers · IaC · +6 more

Where is our biggest risk?

It can't hide in an average.

One actively-exploited vulnerability caps the score at 30. Exploited-in-the-wild findings outrank what a severity formula says.

guaranteed by §1 · CISA KEV cap · Critical-vuln cap · EPSS probability · Exploitation-first triage · +4 more

Can we safely scale AI?

Only as safely as the engineering under it.

ShipReady measures the foundation AI multiplies, and whether agent work survives review and verification, not how busy the tools are.

guaranteed by §4 · Engineering readiness for AI · Agent outcome durability · Agent verification · +9 more

What's about to become an emergency?

The countdown is already running.

Every runtime is tracked against its end-of-support deadline, weighted by criticality and instance count. One critical past EOL sets the grade.

guaranteed by §1 · EOL catalog · Anti-dilution floor · Instance-exposure weighting · +1 more

Could we pass an audit today?

Evidence says, not optimism.

Unassessed controls stay in the denominator, evidence past its cadence stops counting, and an AI draft can support a control but never declare it met.

guaranteed by §2 · Honest denominator · Evidence freshness gate · AI-attestation boundary · +3 more

Can we trust the numbers?

It knows its limits.

Thin domains lose weight and their grade is withheld. Where there's no evidence, ShipReady says Not measured, the most honest thing a metrics product can say.

guaranteed by §3 · Coverage-weighted confidence · Provenance split · No-fake-0/100 quantizer · +1 more

Built for the people who sign

Every quarter already runs on these numbers.

The only question is whether they are evidence or estimates. ShipReady replaces the quarterly spreadsheet census and the pre-board scramble with a number that is already assembled and already defensible. Here is what each seat gets.

CTO · CISO

A number you can defend.

When the board asks why the score moved, the answer is on the screen: the marker, the finding, the evidence, the gate that held. Hostile questioning is the design condition, not the failure mode.

CFO

Figures finance can actually use.

Measured and modeled dollars never blend, so the numbers that reach finance carry their provenance. One prioritized agenda replaces competing anecdotes when capital gets allocated.

CEO · Board · PE

An answer, not another dashboard.

What is healthy, what is risky, what to fix first, in one board-ready pack generated from the same evidence. When diligence arrives, the trail is already built.

Before you connect anythingRead-only, least-privilege scopes, documented per connectorReads metadata, configuration, findings and delivery events, never your application source; nothing installed in your environmentTenant-isolated storage enforced by live row-level-security checksTamper-evident, cryptographically anchored evidence corpus

The evidence under the method

The 45 markers that anchor 300+ live signals.

A curated, buyer-facing view of the measurement engine. Every marker shows what it observes, the evidence behind it, which score it feeds, and the gate it can trigger. Depth is the proof.

Showing 45 of 45 markers · a curated view of 300+ live signals · §n = the gate this marker can trigger

§0 · Refusals, where we draw the line

ShipReady does not:

§0.1Invent a number when the evidence isn't there. Unmeasured reads Not measured, never zero.
§0.2Let a healthy average hide a critical risk. Caps and floors hold the score down until it's resolved.
§0.3Blend measured cost with modeled risk into one dollar figure.
§0.4Count CI runs or preview deploys as production delivery.
§0.5Let an AI-drafted document declare a compliance control met. Only a named human can.
§0.6Claim to be an audit or a certification. It's a readiness indicator from your own evidence.

Knowing what not to fabricate is the first principle of a score you can defend.

Method questions

Asked by every serious evaluator.

Do you need access to our source code?

No. ShipReady connects with least-privilege, read-only scopes and reads metadata, configuration, findings, and delivery events. It never reads your source. Every connector's exact scopes are documented before you grant them.

What happens on day one, with partial coverage?

You get an honest partial picture: measured domains score, unmeasured ones read Not measured, and thin domains carry a visibly discounted weight. The score gets stronger as evidence connects. It never pretends to be stronger first.

How do you decide what we should fix first?

By exploitation evidence and exposure, not raw counts: CISA KEV first, then EPSS exploitation probability, then severity, each weighted by business criticality and instance exposure. The agenda names the few things that move the score most.

What does it cost, and how do we start?

Plans are published on the pricing page. You can start self-serve, connect read-only, and see your first score from your own evidence before you ever talk to sales.

Is a ShipReady Score an audit or certification?

No, and it will tell you so on every surface. It's a readiness indicator computed from your own evidence, built so that when an auditor does arrive, the evidence trail is already there.

See it on your estate

Run the method on your technology.

Connect read-only and get your first ShipReady Score from your own evidence, or book a demo and we'll walk your hardest questions through the gates. The decisions will be made either way. This is the difference between making them on evidence and making them on estimates.

Plans are published at shipreadymetrics.com/pricing. If we can't measure it, your report will say so. · ShipReady is a readiness indicator from your own evidence, not an audit or certification.