Trust Reviews
Public trust profiles with TrustScore, v2026.2 domain breakdowns, AI scope notes, public website hygiene checks, and verified practitioner feedback — built for buyers who need more than a logo wall.
Security trust, inspectable like a review profile
Each Trust Review shows a TrustScore, an Excellent-to-Poor label, methodology domains, buyer lenses, and written feedback — plus a dated narrative with honest gaps.
Stars without scope are marketing. Stars with dates, domains, AI notes, and limitations are usable.HKISG Trust Reviews principle
How to read a Trust Review
- Score + label
TrustScore and Excellent/Poor label are headlines — not warranties.
- Scope, version, AI flag
Confirm what was assessed, which methodology version, and whether AI was in scope.
- Domains + primary gap
Read the six-domain table and the gap line before trusting category stars alone.
- Limitations + expiry
Every report expires. Material AI or architecture change can force earlier retest.
Fortinet
ExcellentNetwork Security · SASE · SecOps
Reference-grade security platform maturity for Hong Kong enterprises — 5.0 TrustScore / 96/100 under methodology v2026.2. Near-perfect is not risk-free: residency wording, AI-overtrust controls, and a few public-site header gaps still need buyer discipline.
Primary gap: Board-ready residency / data-plane language, explicit AI-overtrust controls for SOC automation, and fuller public CSP beyond frame-ancestors.
Moxie Co. Ltd.
ExcellentEvent Planning · Marketing · Customer Relations
Strong, buyer-ready trust profile for a Hong Kong events and marketing agency — 4.5 TrustScore (88/100) under v2026.2. Excellent label is not a perfect 5.0: subcontractors, after-hours incident contact, AI/data-feeding rules, and public-site header hardening still need formalising.
Primary gap: After-hours security contact, subcontractor change notification, default PDPO/AI data-map, and public-site CSP / framing headers.
Frequently asked questions
- How do I read a Trust Review?
- Start with TrustScore + label, then read scope, methodology version, domain scores, public website hygiene (passive header/TLS check — not a pentest), and limitations. Stars without scope are marketing.
- Do you scan the company website for vulnerabilities?
- Each Trust Review can include a passive public-surface check (HTTPS redirect and security response headers). It is not a penetration test and does not prove there are no vulnerabilities. See the Website hygiene panel on each report.
- How is an HKISG Trust Review different from a random web rating?
- Trust Reviews combine a dated methodology score (including AI security under v2026.2), domain breakdown, optional public-site hygiene, and verified practitioner commentary. Rules are published under Methodology and Governance.
- Does “Excellent” mean a perfect 5.0?
- No. Excellent is a qualitative band. A 4.5 can still be labelled Excellent when controls are strong with managed gaps. Always read the primary gap line and domain table.
- What if an organisation says they do not use AI?
- After inventory verification, AI may be scored N/A and weight redistributed. Declaring “no AI” without an inventory check fails Evidence quality. See Methodology.
- Can companies pay for 5 stars?
- No. Fees fund assessment capacity. Star bands follow the published rubric — membership does not buy outcomes.
- How do I request a Trust Review for my organisation?
- Start with membership or contact HKISG for review-queue eligibility.