AI made cybersecurity move faster at everything — including buying it. Right now your answers come from bias or a model’s guess, and the guess ships with your name on it. Vulgate is the unbiased source of truth, built from vendor documentation. Requirements in; a ranked, fully cited matrix out — source, date, and qualifiers on every claim.
No hallucination. No brand damage. No wondering.
A language model is a next-token predictor. It uses the identical machinery to recall a fact and to invent one — fluency and truth come out of the same pipe. It has no internal signal that says “I know this” versus “this is plausible.”
A hallucination isn’t a malfunction. It’s the model doing exactly what it always does — producing a likely-sounding continuation — in a spot where likely and true happen to diverge. And its confidence is uncorrelated with its correctness. It is just as fluent when it’s wrong.
Vendor capability claims are exactly the kind of thing that’s plausible but maybe false. If a tool is a SAST scanner, it’s plausible it supports your language, does SSO, deploys air-gapped — so the model asserts it, confidently, whether or not that vendor documents it.
Then the answer goes to your client under your letterhead. One hallucinated cell in one matrix, and you’ve spent trust with everyone at the table.
“Vendor X supports FIPS 140-3 validated encryption in its air-gapped tier.”
feels misled — and remembers who misled them.
is furious. Their win is now built on claims they never made.
are furious. They lost to evaluation criteria that were wrong.
You can’t prompt your way out of hallucinations, it’s a property of the architecture. You fix it by taking the facts out of the model’s discretion entirely.
A fixed substrate for the recall job, so the model only ever does the reasoning job. The corpus is fixed text: a passage in a vendor’s documentation either exists or it doesn’t. There’s no sampling, no temperature, no distribution.
Every claim is forced into one of five states. The model can’t smooth a maybe into a confident yes — it has to declare what the documentation actually supports.
The documentation directly states it.
Adjacent documented functionality strongly suggests it.
Stated — with a tier, dependency, or limitation attached. The qualifier travels with the claim. Always.
Nothing found. And silent never renders as "does not support."
The documentation answers no — a stated limitation, or a condition that contradicts your requirement. Documented negatives are evidence too.
| Vendor | Claim | Evidence | Source |
|---|---|---|---|
| Claroty xDome | Explicit | “Passive monitoring via SPAN/TAP requires no endpoint agent…” qualifier: requires CTD sensor appliance | docs.claroty.com/… last modified 2026-05-14 |
| Dragos Platform | Qualified | “Passive collection of industrial network telemetry…” qualifier: passive collection only in Platform tier | docs.dragos.com/… last modified 2026-06-02 |
| Vendor C | Silent | No documentation found. Silent never renders as “does not support.” | flagged for vendor verification |
Determinism isn’t a feature you switch on. It’s a discipline you dial. The deeper you go, the more discretion you take away from the stochastic layer — until the answer to a high-stakes cell is a lookup, not a generation.
Exploratory question? Let the model range wide. A cell going into a contract? Force it down to where there’s almost no stochastic surface left to hallucinate from. You choose the trust level per use — and every tier still cites.
Vendor documentation, gathered at the source — politely and transparently. No scraping arms race, no evasion. Gated docs go through the front door: partner channels and direct verification.
Every page chunked with its full heading context, tagged by capability, with qualifier language — "requires," "only available in," "beta" — extracted and pinned to the claim it modifies.
Each vendor scored on the strength of its best evidence, never on page count. A vendor with 40 precise pages outranks one with 4,000 pages of noise. Corpus size is a bias; we remove it.
Work inside the platform, or let the data come to you — matrices exported with citations intact, evidence pulled into your existing proposal workflow.
Evaluations move at machine speed now — and somewhere right now, an AI is describing your product without you.
Every claim about you is quoted from your documentation — cited, dated, faithful. Not analyst takes, not reviews, not our opinion. Improve your docs, and your representation improves the same day.
No vendor can massage their row — including you. That neutrality is exactly what makes your row worth believing when a buyer reads it.
Where your docs are quiet, we say "no documentation found" — never "does not support." Qualifiers travel with every claim, so your nuance survives the matrix.
Capability evidence answers "who can do this." It deliberately doesn’t answer "who should we lead with" — that’s a business decision. Deal-context overlays (delivery history, margin, certifications) apply only after vendors tie on documented capability. Evidence ranks. Business breaks ties. The layers never blend silently.
Capability evidence says the product can do it. Delivery evidence says you’ve done it — deployment counts and outcomes from your own CRM, cited like everything else, just with an internal source.
Two tracks: automated collection where vendors publish openly, verified partner submissions where they don’t — plus a standing intake sweep of funding rounds, startup showcases, and analyst lists, so the corpus already knows the vendor your client just asked about.
We gave a leading general AI assistant and Vulgate identical instructions — real citations or say so — and asked both to build a 10-vendor, 12-requirement evaluation matrix. The assistant declined the task:
“That’s on the order of hundreds of documentation lookups.”— the other assistant, asked for one sourced evaluation
Vulgate returned all 120 cells — cited, dated, qualifiers intact — including its own coverage gaps, flagged honestly. The lookups were already done. That’s the point.