vulgate.
← Back to the site
The side-by-side

One task.
Two very different answers.

We wrote a realistic buying scenario and handed the identical brief to two assistants: one grounded on the Vulgate corpus, one relying on the open web. Same evidence rules for both — cite real documentation or say so. This page is the unedited outcome.

The scenario

Meridian Trust Systems — a fictional payments company. ~400 engineers, PCI-DSS scope, self-managed GitLab, a Java/Kotlin monorepo plus Go and TypeScript services, and a card-processing build enclave with no internet access. They’re consolidating application-security tooling.

The ask

Evaluate 10 named vendors against 12 requirements — 8 mandatory, 4 preferred. 120 cells, each labeled with an evidence state and backed by a documentation citation. Then shortlist the top three and justify every exclusion.

The rules

Vendor documentation only. Every non-silent cell needs a source URL and a date. No marketing pages, no memory, no guessing — if the docs don’t say it, the answer is silent, not yes.

Grounded on Vulgate

Delivered the matrix.
All 120 cells, cited.

Claude, restricted to the Vulgate corpus as its only source of vendor facts, returned the complete compliance matrix: every cell labeled, every non-silent claim carrying a documentation URL, a retrieval date, and the corpus file it came from. Qualifiers traveled with the cells.

120/120
cells returned, cited
0
fabricated URLs
2
documented negatives caught

The scoring goes deeper than yes/no. Every cell lands in one of five evidence states, and qualifiers travel with the claim — “supported, on the SaaS tier only” never flattens to “supported.” Documented negatives surface as conflicts instead of being skipped, and the shortlist rules are mechanical: a missing mandatory excludes, preferred requirements break ties. The full matrix is below.

General assistant, open web

Declined the task.

“I can’t produce that matrix reliably without first searching the vendors’ documentation… That’s on the order of hundreds of documentation lookups.”

To its credit, it refused honestly — held to the no-fabrication rule and proposed evaluating one vendor at a time instead. But the evaluation you asked for never arrived. The lookups it balked at are exactly the work Vulgate does in advance.

And in earlier rounds, when it did answer
×

Stale sources. Cited a 2021 vendor blog post as evidence — outside the docs-only rule, and five product versions old.

×

False silence. Reported one vendor’s docs silent on OpenAPI 3.1 support. The documentation exists; it just wasn’t found.

×

Marketing as evidence. Sourced a performance claim from a vendor’s marketing pages rather than its documentation.

What Vulgate returned

The mandatory matrix, cell by cell.

Eight mandatory requirements across the candidate field. Hover any column header for the full requirement; every non-silent cell in the source output carries a documentation URL and retrieval date.

EExplicit
QQualified
IImplied
SSilent
CConflict
CandidateM1M2M3M4M5M6M7M8Verdict
Endor LabsEEEESEEEShortlist #1 — 7/8 mandatory, 4/4 preferred
SemgrepEEEESEEEShortlist #2 — 7/8 mandatory, 3/4 preferred
Aikido SecurityEIEESEEQShortlist #3 — 6/8 mandatory, 3/4 preferred
SnykESEQSQEQExcluded — M2, M5
SocketEEESSEQEExcluded — M4, M5
VeracodeEEECQQQEExcluded — M4 conflict, M5
Contrast SecurityCSEQEQSQExcluded — M1 conflict, M2, M7
MendESQEQQQQExcluded — M2, M5
OX SecurityQQEQQQQEExcluded — thin evidence across mandatories

Preferred requirements P1–P4 — license policy, container scanning, malicious-package detection, IaC scanning — scored separately as tiebreakers.

The verdict

Three finalists. Every exclusion justified.

01

Endor Labs

7/8 mandatory · 4/4 preferred

Only gap is M5: scan compute can run on-prem, but the tenant and vulnerability database stay cloud-hosted — no offline DB updates documented.

02

Semgrep

7/8 mandatory · 3/4 preferred

Only gap is M5: the CLI engine runs locally, but Supply Chain reachability and policies require the SaaS platform. No container scanning (P2).

03

Aikido Security

6/8 mandatory · 3/4 preferred

Gaps at M2 — Go reachability implied by architecture docs, never stated — and M5. License policy support is qualified.

What a cited cell looks like
CellSource URLCorpus fileRetrieved
Endor Labs — M1docs.endorlabs.com/scan/sca/reachability-analysis/corpus/endor-labs/…/reachability-analysis.md2026-08-01
Semgrep — M3docs.semgrep.dev/supported-languages.mdcorpus/semgrep/supported-languages.md2026-08-01
Semgrep — M7docs.semgrep.dev/extensions/pre-commit.mdcorpus/semgrep/extensions-pre-commit.md2026-08-01
What the test taught us

Documented negatives are evidence

Two cells came back as conflicts — the docs answered no. Contrast’s reachability requires a runtime agent, which the scenario forbids. That’s why the evidence contract now has a fifth state.

The blocker was real

Air-gapped deployment (M5) eliminated nearly the whole field — the kind of finding that usually surfaces three demos into a sales cycle, surfaced before the first call.

Failure modes differ

The corpus’s failures are visible and fixable — a disclosed gap. The open web’s failures needed an auditor to catch: stale blogs, marketing pages, missed docs.

Request accessBack to the site

Methodology: run 2026-08-02. Both arms received the identical scenario, candidate list, and evidence rules. Vulgate arm: Claude (Opus) restricted to the Vulgate documentation corpus as its sole source of vendor facts. Comparison arm: a leading general assistant with web browsing. Meridian Trust Systems is a fabricated evaluation scenario; the vendors, requirements, and citations are real. Evidence states reflect vendor documentation as collected on 2026-08-01 and may change as documentation changes.