vulgate.
ProblemEvidenceVendorsProof
Request access
Capability intelligence for security evaluations

Evidence,

not answers.

AI made cybersecurity move faster at everything — including buying it. Right now your answers come from bias or a model’s guess, and the guess ships with your name on it. Vulgate is the unbiased source of truth, built from vendor documentation. Requirements in; a ranked, fully cited matrix out — source, date, and qualifiers on every claim.

No hallucination. No brand damage. No wondering.

See a sourced matrixWhy this matters
The problem

AI can’t tell you
when it’s guessing.

A language model is a next-token predictor. It uses the identical machinery to recall a fact and to invent one — fluency and truth come out of the same pipe. It has no internal signal that says “I know this” versus “this is plausible.”

A hallucination isn’t a malfunction. It’s the model doing exactly what it always does — producing a likely-sounding continuation — in a spot where likely and true happen to diverge. And its confidence is uncorrelated with its correctness. It is just as fluent when it’s wrong.

Asked three times
Supports air-gapped deployment?
Yes — fully offline capable.
Same confidence, every time. None of them cited. One of them, at most, is true.
The stakes

The guess ships with
your name on it.

Vendor capability claims are exactly the kind of thing that’s plausible but maybe false. If a tool is a SAST scanner, it’s plausible it supports your language, does SSO, deploys air-gapped — so the model asserts it, confidently, whether or not that vendor documents it.

Then the answer goes to your client under your letterhead. One hallucinated cell in one matrix, and you’ve spent trust with everyone at the table.

A confident answer — hover to inspect

“Vendor X supports FIPS 140-3 validated encryption in its air-gapped tier.”

source: vendorx.com/docs/security/fips.html
01

The client

feels misled — and remembers who misled them.

02

The winning vendor

is furious. Their win is now built on claims they never made.

03

The losing vendors

are furious. They lost to evaluation criteria that were wrong.

The fix

So Vulgate splits them — a deterministic layer
the model can read but not rewrite.

You can’t prompt your way out of hallucinations, it’s a property of the architecture. You fix it by taking the facts out of the model’s discretion entirely.

A fixed substrate for the recall job, so the model only ever does the reasoning job. The corpus is fixed text: a passage in a vendor’s documentation either exists or it doesn’t. There’s no sampling, no temperature, no distribution.

The evidence contract

The model must classify
its own certainty.

Every claim is forced into one of five states. The model can’t smooth a maybe into a confident yes — it has to declare what the documentation actually supports.

Explicit

The documentation directly states it.

Implied

Adjacent documented functionality strongly suggests it.

Qualified

Stated — with a tier, dependency, or limitation attached. The qualifier travels with the claim. Always.

Silent

Nothing found. And silent never renders as "does not support."

Conflict

The documentation answers no — a stated limitation, or a condition that contradicts your requirement. Documented negatives are evidence too.

The states, applied
Requirement — “Agentless discovery of OT assets across Purdue L2/L3”
VendorClaimEvidenceSource
Claroty xDomeExplicit
“Passive monitoring via SPAN/TAP requires no endpoint agent…”
qualifier: requires CTD sensor appliance
docs.claroty.com/…
last modified 2026-05-14
Dragos PlatformQualified
“Passive collection of industrial network telemetry…”
qualifier: passive collection only in Platform tier
docs.dragos.com/…
last modified 2026-06-02
Vendor CSilent
No documentation found. Silent never renders as “does not support.”
flagged for vendor verification
Determinism as discipline

Turn the dial
toward certainty.

Determinism isn’t a feature you switch on. It’s a discipline you dial. The deeper you go, the more discretion you take away from the stochastic layer — until the answer to a high-stakes cell is a lookup, not a generation.

Exploratory question? Let the model range wide. A cell going into a contract? Force it down to where there’s almost no stochastic surface left to hallucinate from. You choose the trust level per use — and every tier still cites.

ExploratoryContractual
Tier 1 — Exploratory
Model discretion
High
Answer variance
±3 cells
Latency
~30 min
Scoping a question, casting wide
How it works
01 — Collect

Vendor documentation, gathered at the source — politely and transparently. No scraping arms race, no evasion. Gated docs go through the front door: partner channels and direct verification.

02 — Structure

Every page chunked with its full heading context, tagged by capability, with qualifier language — "requires," "only available in," "beta" — extracted and pinned to the claim it modifies.

03 — Rank

Each vendor scored on the strength of its best evidence, never on page count. A vendor with 40 precise pages outranks one with 4,000 pages of noise. Corpus size is a bias; we remove it.

04 — Deliver

Work inside the platform, or let the data come to you — matrices exported with citations intact, evidence pulled into your existing proposal workflow.

For vendors

Your documentation is your best salesperson.
Let it work.

Evaluations move at machine speed now — and somewhere right now, an AI is describing your product without you.

Your words, only

Every claim about you is quoted from your documentation — cited, dated, faithful. Not analyst takes, not reviews, not our opinion. Improve your docs, and your representation improves the same day.

Credible because no one can edit it

No vendor can massage their row — including you. That neutrality is exactly what makes your row worth believing when a buyer reads it.

Silence is never "no"

Where your docs are quiet, we say "no documentation found" — never "does not support." Qualifiers travel with every claim, so your nuance survives the matrix.

Verify your documentationVerification is free. It always will be.
Where this is going

The parity gate

Capability evidence answers "who can do this." It deliberately doesn’t answer "who should we lead with" — that’s a business decision. Deal-context overlays (delivery history, margin, certifications) apply only after vendors tie on documented capability. Evidence ranks. Business breaks ties. The layers never blend silently.

Delivery evidence

Capability evidence says the product can do it. Delivery evidence says you’ve done it — deployment counts and outcomes from your own CRM, cited like everything else, just with an internal source.

Living coverage

Two tracks: automated collection where vendors publish openly, verified partner submissions where they don’t — plus a standing intake sweep of funding rounds, startup showcases, and analyst lists, so the corpus already knows the vendor your client just asked about.

We ran the test

Same rules. Same questions.
One of us answered.

We gave a leading general AI assistant and Vulgate identical instructions — real citations or say so — and asked both to build a 10-vendor, 12-requirement evaluation matrix. The assistant declined the task:

“That’s on the order of hundreds of documentation lookups.”
— the other assistant, asked for one sourced evaluation

Vulgate returned all 120 cells — cited, dated, qualifiers intact — including its own coverage gaps, flagged honestly. The lookups were already done. That’s the point.

653
vendors under collection
65,000+
documentation pages
120/120
matrix cells cited
0
fabricated URLs
See the side-by-side

The model reasons.
The corpus remembers.

Request access