Methodology
Short on purpose. Four scoring decisions worth explaining; the rest of the work lives in /sources.
1. MITRE ATT&CK coverage
Scored as the share of the ATT&CK Enterprise tactic-and-technique grid[32] with at least one pre-built detection rule shipped in the base SIEM SKU. We do not count community-contributed rules unless the vendor commits to maintain them. We do not count behavioural detection that triggers across tactics without naming the technique. Snowflake scores 0% because the lake itself does not produce detections.
2. Pricing-model normalisation
For the homepage bar chart and the IngestCalcStrip every vendor that publishes a unit price is converted to a per-GB equivalent at a 500 GB/day, 1,000-employee, 1,500-endpoint reference shape. Per-employee vendors (Chronicle) use their list rate divided by the equivalent per-GB cost for the shape; per-asset vendors (Rapid7) likewise. Quote-only vendors are not converted. We refuse to fabricate a unit rate for a vendor that does not publish one.
3. Quote-only flag
A vendor is marked quote-only when no public unit price exists on the vendor pricing page on the verification date. We attempted to request a quote from every quote-only vendor in the dossier; the date of that attempt is the "verified" date on each vendor sheet. Channel-reported rates are cited as channel reports, never presented as vendor-published.
4. M&A and pricing-model change tracking
Owner and pricing-model changes are dated and cited on each vendor dossier. The consolidated view lives at /dossier/ma-consolidation-map and /dossier/pricing-model-changelog. Both are refreshed quarterly; each page carries a verified-date stamp top-right that updates on the re-verification pass.
This site is editorially independent. No vendor pays for placement. No affiliate links. For corrections email editor@siemvendors.com.