Scoring & Freshness

How static rankings and assurance levels should be interpreted

Static score is the comparable baseline

Static score reflects the versioned thethermark AI security baseline. AISecurityBase does not recompute it or alter it because a project received deeper work, sponsorship, or a paid service.

Public ordering follows static score

The primary public leaderboard is ordered by static score. Freshness is shown beside the result and may cause a row to be withheld when its evidence is no longer comparable.

Assurance labels stay separate

Static Assessed, Deep Reviewed, and Runtime Assessed describe increasing evidence depth. A runtime label never silently changes the static score.

Publication requirements

Every published result must identify the repository version, assessment date, methodology version, dimensions, freshness, limitations, and evidence safe enough to substantiate the score. If validated data is unavailable, the public index shows an unavailable state rather than sample results.