StackAttestTechnical Trust
The Standard

What has changed, and what that does to old results

3 parts of the Standard carry a version: the control pack, the scoring policy and the consensus aggregation. Each is versioned so that a result can say what it was produced under, which is the only thing that makes a score from last year readable this year.

This list is short because there has not been much to change yet. It will stay honest about that rather than filling out.

Scoring policy2.0.022 August 2026

The overall score weights each category by the evidence weight actually verified in it, rather than counting every category equally.

Under the previous policy a category verified by a single medium-weight control moved the headline score as much as the entire security category. One real run scored 92.85 and fell to 69.44 the moment two thin categories gained their first partial evidence, which is a score reacting to the shape of the pack rather than to the product.

Scoring policy1.0.0no dated release

The original policy, weighting every control category equally.

Superseded. Runs scored under it keep their recorded policy version, so an older result stays interpretable as what it was rather than being silently restated.

Consensus aggregation1.0.0no dated release

Deterministic aggregation of structured council opinions into an agreement percentage, with the votes cast and the seats configured reported alongside it.

Current. The aggregation is arithmetic over opinions rather than an opinion of its own, which is what lets it be versioned at all.

Control pack: StackAttest Core1.0no dated release

The baseline pack: thirteen controls across security, reliability, operations and performance, mapped into six external vocabularies.

Current. Control keys are stable and a change in a control's meaning requires a new control version rather than an edit, so a result recorded against a control still means what it meant.

Old results are never rescored

When a policy version changes, results produced under the old one keep their recorded version and their original numbers. Nothing is retroactively restated.

The trade is that two results under different policy versions are not directly comparable, and a reader comparing them should look at the version each one carries. That is a real cost and it is smaller than the alternative, which is a trust product whose past claims quietly change meaning.

What a control version change means

Control keys are stable. If what a control means changes, it takes a new control version rather than an edit, and a new pack version with it. So a result recorded against a control still means what it meant when it was recorded, and a reader who wants to know what was tested can look up that exact version rather than the current one and hope.

Keep reading