Independent buying research
EDR Buyers GuideEndpoint security decisions, documented

How we research

What we collect, where it comes from, and the rules we follow before anything is published.

Last reviewed
2026-10-05

What a record is

Each record is one buying decision by one organization. A purchase can produce many documents (a request for proposal, amendments, an evaluation, an award and a contract), and we keep them together as one decision with several sources, rather than counting them as several purchases.

Where evidence comes from

Context, not generalization

Our readers are mostly U.S. private companies, but some of the best-documented purchases come from public bodies and from other countries. Every record shows its organization type and country, for example "Public sector · United Kingdom", so you can judge how well it applies to you.

How well supported is a record?

Each record carries an editorial rating (well supported, partly supported, thinly supported, or not yet reviewed) describing how well its sources support what we've recorded. A person on our team makes this judgment. It is never assigned automatically or by AI, and it is separate from the type of source and from whether a vendor published it.

Pricing

We record what a price included (software, managed service, implementation, incident response and other items) and whether the scope is clear enough to compare. We never divide a bundled contract by its endpoint count and call the result a license price.

Unknown means unknown

If a source doesn't state something, we show "Not disclosed." We don't estimate, infer or fill gaps.

Names

We name an organization when a public source identifies it and there's no reason to withhold it. Otherwise we use a description such as "Regional manufacturer, about 1,200 endpoints."

Corrections

When better evidence becomes available, we update the record and the page's last-reviewed date.