Method

Every page carries one verdict, a date, and a list of sources. This page is the whole of how that is decided.

How this site works

Every factual claim here is sourced to a vendor's own documentation, named and dated, so you can check it without trusting me. That is deliberate. The documentation is what both sides of an integration have to live with, and it is what you can verify for yourself.

The judgment is mine. What actually breaks, what it costs, what most people end up doing instead. That comes from doing this work, in product and on engagements I cannot always name. Where I am telling you what a document says, the page says so. Where I am telling you what I have seen, it says that instead.

The four verdicts

Verified The vendor documents it, I have read the page myself, and the evidence block names and dates it.
Partial Works within a limit worth knowing before you build: one direction only, a poll pretending to be a stream, a subset of fields.
Claimed only The vendor says it. I could not confirm it. Gray, not amber. An unconfirmed claim is an absence of evidence, not a warning.
Not supported The vendor documents the absence, or documents the behavior that makes it impossible. Named as removed, undocumented, or refused, never left to inference.

Where a claim came from

Every line in an evidence block is stamped with how the claim was arrived at. Four of the five name something you can open yourself. The fifth is me, and it looks different on the page for that reason.

VENDOR DOC The vendor’s own documentation, named and dated. The default here, and the only thing behind every claim currently published on this site.
THIRD PARTY Someone other than the vendor, published and attributable. Used where the vendor is silent and somebody credible is not.
USER REPORT A named account from somebody who ran it. Weaker than a document, stronger than nothing, and never promoted to Verified on its own.
TESTED I stood the integration up and watched what it did. Reserved for work I can describe in the open, which is why nothing on the site carries it yet.
FROM THE FIELD First hand, from doing this work in product and on engagements, rather than from a page. Not a document, not verifiable by you, and marked so you can weigh it accordingly. It is never applied backwards to a claim that was read rather than lived.

Freshness

Every page shows the date it was last checked. Past 180 days the page is marked stale, the headings step back, and every verdict on it is prefixed “Unconfirmed”. A stale page should look stale.

When two documents disagree

Vendors contradict themselves more often than they contradict each other. When two of a vendor's own documents give different answers to the same question, that is not a footnote on a verdict. It is the finding, and it gets its own block on the page, with both positions named and quoted. Here is what one looks like.

The documents disagree

How long a Falcon Event Streams appId may be

CrowdStrike API reference, Event Streams
32 characters
CrowdStrike Falcon Event Streams Add-on guide, v3.5
15 characters

Both are CrowdStrike's own documents, published at the same time, describing the same field. Nothing in either one acknowledges the other.

Build against: The shorter limit, until CrowdStrike says which is wrong. A 15 character appId satisfies both.

Versions, not just dates

A date answers when a claim was checked. It does not answer against what. Where the product version matters, every citation carries it beside the method and the date, because version drift is the way a reference like this goes quietly wrong: the date still looks fresh while the software has moved underneath it.

Money

The site carries advertising. No vendor pays for placement, for a verdict, or for a page. There are no sponsored posts and no affiliate links.

Who writes this is on the about page.