How this site is funded
This publication is funded entirely by HumanAudit Inc., through consulting engagements and ISO/IEC 42001 documentation products. We carry no advertising, no sponsored content, no affiliate links and no paid vendor placement of any kind, and we do not operate a newsletter or collect email addresses. That funding model is the reason vendor coverage can say what it says: no vendor on this site has paid us anything, and none can.
1. Scope and purpose
This policy governs all editorial content published on nhigovernance.com, including definitional articles, framework explainers, breach case studies, vendor profiles, comparison pages and interactive tools. It applies to all contributors, staff, commissioned authors, and guest contributors.
The purpose of this policy is twofold. First, to make explicit the standards we hold ourselves to. Second, to make those standards public so that you, reader, practitioner, vendor, can hold us to them.
2. Editorial independence
Editorial decisions (what we cover, how we cover it, which vendors appear in comparisons, which breaches get deep-dive treatment) how we rank or score products, are made exclusively by the editorial team. No external party has approval rights, sign-off, or veto over editorial decisions.
This means in practice:
- No vendor has the right to review an article about their product before publication.
- We have no sponsors, affiliate partners or advertisers, so none can influence editorial direction. The only commercial interest behind this publication is HumanAudit Inc.’s own consulting and product work, which is disclosed on every page.
- No factual correction process confers editorial sign-off (see §6).
- The editorial team reports to HumanAudit Inc.'s leadership but its editorial decisions are not subject to commercial override.
3. Sourcing and accuracy standards
Every factual claim on this site must be supportable by a named, verifiable, and accessible source. We prefer primary sources over secondary sources, and non-vendor sources over vendor marketing claims.
Source hierarchy (highest to lowest weight)
- Standards bodies and working groups, IETF RFCs and drafts, NIST Special Publications, OWASP working group outputs, CNCF projects, ISO/IEC standards.
- Regulatory bodies and their guidance, European Commission, ENISA, CISA, FBI, NCSC, national data protection authorities.
- Published academic and peer-reviewed research, USENIX, IEEE, ACM, Black Hat briefings with published papers.
- Incident-response and threat-intelligence publications from credible forensic providers, Google/Mandiant, Microsoft Incident Response, CrowdStrike OverWatch, Wiz Research, Unit 42, CERT advisories.
- Respected industry analysts, Gartner, Forrester, IDC, 451 Research, Cloud Security Alliance research.
- Vendor technical documentation, treated as authoritative about the vendor's own product, not about the market.
- Vendor marketing content, used only with skepticism and typically only to establish a vendor's own claimed positioning.
When sources conflict, we explain the conflict rather than pick a favourite. When a claim cannot be sourced to our satisfaction, we leave it out, even if it would strengthen the narrative. When we are uncertain, we say "unknown."
4. How we cover vendors
A vendor's appearance on this site is determined by editorial relevance, not by commercial relationship. Our standard for including a vendor in coverage is: do readers trying to understand non-human identity governance need to know about this vendor? If yes, we cover them. If no, we don't, regardless of any commercial relationship.
When we profile or compare vendors, the following rules apply:
- No paid placement. No vendor has paid us to be listed, profiled, reviewed, compared, or mentioned on any content page.
- No placement by sponsorship. We carry no advertising and no sponsored content. This publication is funded entirely by HumanAudit Inc. consulting and product revenue, which is disclosed on every page through the publisher statement in the footer.
- No "strategic partner" tier. We do not maintain a paid-partner programme that grants dedicated profile pages, logo placement, or editorial priority.
- Equal editorial standard. Every vendor profile page is researched and written using the same editorial process, independent research, publicly available documentation, consultation of the vendor's own written materials, and where appropriate request of clarification on technical detail.
- <
5. How we make money, and what it means
This site has three revenue streams. We describe each in full here so you can assess them.
Affiliate and referral revenue
< Clicking through and purchasing may result in a commission paid to HumanAudit Inc. These links are clearly labelled. The decision to include an affiliate link on a page is made independently of the editorial assessment of the vendor on that page.Cross-promotion to HumanAudit commercial products
This site occasionally links to the commercial toolkit products on our sister sites (euaiactchecklist.com and iso42001toolkit.com) where those products are genuinely relevant to the reader's compliance context, for example, on our EU AI Act × NHI framework page. These links are first-party and clearly identified as HumanAudit products.
What we do not do
- We do not accept money to place a vendor in a comparison.
- We do not accept money to rank a vendor higher.
- We do not accept money to omit a vendor from a comparison.
- We do not accept money to soften a breach case study that involves a specific vendor's product.
- We do not accept money to stop covering a topic.
6. Corrections, updates, and reader challenges
We will make mistakes. When we do, we fix them, and we say so. Our correction policy:
- Factual corrections: Any reader, including a vendor whose product we have described inaccurately, can request a correction via editorial@nhigovernance.com. We triage within two business days. If the correction is warranted we update the page and add a dated note to the bottom of the article. Significant corrections (e.g. a factual claim was wrong in a way that affected the article's conclusion) are flagged at the top of the article and recorded in our corrections log.
- Interpretive disagreements: Where a vendor or reader disagrees with an editorial interpretation (not a factual error), we consider the argument on its merits. Where we find the argument strong, we update our position with attribution. Where we don't, we publish the disagreement so readers can weigh it themselves.
- Evolution over time: Standards move, vendors are acquired, breaches get re-examined. Every definitional and framework page is reviewed at least quarterly. We display the "last reviewed" date on every such page.
- Major revisions: When we materially change an article's conclusion, we preserve a summary of the prior position and link to it, rather than silently overwriting.
7. Use of AI in editorial work
We use AI tools (including large language models) as editorial assistants, for research synthesis, draft outlining, fact-checking, and summarisation. No article on this site is published without human editorial review, fact-verification against sources, and human final approval. We never publish AI-generated content wholesale. We do not use AI to fabricate sources, quotes, or statistics. Where we cite statistics from AI-generated summaries of survey data, we trace back to the primary source and cite the primary source directly.
We disclose this use of AI because transparency about editorial process is part of earning reader trust, and because the security community we write for has every right to understand how we work.
8. Conflicts of interest
Members of the editorial team may have prior employment history, consulting relationships, advisory roles, or financial interests with companies we cover. Where a conflict exists, we disclose it in-line on the affected article or recuse the conflicted author from the piece. Our standard disclosure format:
Disclosure example
"Author X was an employee of [Vendor] between 2019 and 2022, and holds shares in [Vendor] from that period. They had no role in editing this article; this profile was written by Author Y and edited by Author Z."
9. Bylines and pseudonyms
Articles are signed with real names where possible. Some practitioners, particularly those still employed at organisations covered in our content, may contribute under a verified pseudonym where disclosure would risk professional consequences disproportionate to the contribution. Pseudonyms are flagged as such on the author's byline, and the editorial team holds the real name on file.
10. Privacy and reader data
We collect the minimum amount of reader data needed to operate the site. We do not sell, rent, share, or otherwise monetise reader data. Our use of cookies is restricted to operational and analytics purposes described in our cookie policy and privacy policy.
11. Feedback channel
This policy is a living document. We welcome challenges to it. Write to editorial@nhigovernance.com. We read every message.
Summary, for the person who skimmed
We do not take money to write favourably about any vendor. Vendor profile pages are researched independently. Factual corrections are welcome and published with date stamps. If we ever violate this, email editorial@nhigovernance.com and call us on it.