Straight answer

Read the two reasons, not just the two numbers. A score says how well public material documents a capability; the reason says what was found. A one-point gap often means one vendor names specifics and the other states the same idea in general terms.

One row, two parts

Every row in a head-to-head shows a score for each tool and a one-line reason for each score. The score uses the same five levels for every tool: 5 means documented in detail with specifics, 1 means not addressed on public pages or built for a different job.

A worked example

Rule lifecycle weight 7%

Mars Security 3 / 5: Backtesting before go-live is documented; version history, review and CI are not described on public pages.

Nebulock 5 / 5: Every rule must pass a retrohunt before deployment, with immutable version history, compare and revert, and GitHub export.

Here the gap is two points. Both vendors test rules before they go live, but only one of them also publishes version history, compare and revert, and export to GitHub. The gap is about what is documented, not a test of the product.

Questions to ask of any row

Is the gap about a missing capability or a missing description? Does the reason name specifics, such as platforms or a stated figure? Does the criterion matter to your team? If the answer to the last question is no, the row can be skipped.

Where to find the rows

Every head-to-head on this site lists all seven criteria. Start from the matrix and open the pair you are weighing.

Reading one row across more tools

The side-by-side compare page shows the same row for up to five tools at once, with the highest score in each row marked. Read it the same way: compare the reasons, not only the numbers, and note which vendors name platforms or state a figure. There is also a head-to-head page for every one of the 15 pairs, listed on the compare page.

Next lesson

Building a shortlist from this matrix

Five steps to turn the matrix on this site into a two or three tool shortlist: check the question, set your weights, drop poor fits, read the reasons and plan demos.

Related

Editorial assessment · Desk research from public vendor material, last reviewed September 2026