Vendor evidence index

The evidence behind enterprise technology decisions, published

nexalign collects evidence on the vendors that turn up in security, identity, cloud and governance decisions: government vulnerability registers, EU and German authorities, practitioner discussions, analyst and neutral press coverage, and the vendors' own documentation. This is that pool, opened up. 4,345 items across 131 vendors, each one linked to the source it came from. What a plain web search returns about a company, its directory profiles and lead-generation listings, is not in here.

Vendors

131

with a published record

Evidence items

4,345

source and date on each

From authorities

3,145

NVD, ENISA, CISA, BSI

Last checked

Jul 31, 2026

sources re-queried

What this index is, and what it is not

It is a record, not a ranking. There are no stars, no quadrants and no "leaders", because a leader only exists relative to a buyer's criteria, and those live in the decision, not in the vendor.

No vendor pays to be in here

There is no sponsored placement, no premium profile and no way to buy a change. A vendor is listed because a decision in its category came up, not because it asked.

Every item names its source

A finding without a source is not a finding. Each entry links back to the register, thread or document it came from, and carries the date that source states. Where a source states none, the entry says so instead of inventing one.

Gaps are shown as gaps

Where nothing was found, the page says nothing was found. Silence is never rendered as a clean bill of health, and no missing fact is filled in by a language model.

How sources are classified

A vendor can rewrite its own site overnight. It cannot edit a government register or a years-old thread. Every item is classified by how much the vendor could influence it, and each profile reports the resulting mix.

Authoritative

Government and regulatory registers: NVD, the European Vulnerability Database, the CISA catalogue of known exploited vulnerabilities, CERT-Bund advisories from the BSI, EUR-Lex.

Independent

Third parties the vendor does not control: practitioner threads, plus a fixed list of recognised analysts, review marketplaces and neutral technology press. Social networks, press-release wires and company directories are excluded, because placement there is trivial.

Vendor-controlled

The vendor's own material: documentation, whitepapers, submissions. Kept in the record and labelled, never counted as independent confirmation.

Vendors in the index

Grouped by the kind of decision they show up in. The counts are the size of each record, not a quality signal: a large record can mean a widely deployed product or a busy year of advisories.

Endpoint security (EDR and XDR)18

Identity and access management14

Privileged access management6

SIEM and log analytics12

Managed detection and response6

Network security16

Email security8

Cloud and sovereign cloud10

Backup and recovery10

Data security7

DevSecOps and application security14

Governance, risk and compliance10

Citing and reusing this record

The record is published to be quoted. These are the terms, stated here because the structured data on every page points at this section.

Quoting from these pages and linking to them is welcome, with attribution to nexalign and a link to the page the figures came from. Please quote a number together with the date it was checked, because the record moves as the sources do.

The underlying entries are not nexalign's to license. They belong to the bodies that publish them: NIST, ENISA, CISA, the BSI, and the platforms and outlets each item links to. What nexalign compiled is the selection, the attribution and the counting, and that is what the attribution request covers.

For bulk or automated reuse, write to [email protected] first, so the load stays predictable and corrections can reach you.

The index answers what is true. DecisionOS answers what to do.

Reading a vendor record is the easy half. The hard half is weighing five of them against criteria your CISO, your CFO and your auditor all have to live with. That is what DecisionOS is for: same evidence pool, your criteria, one memo that holds up afterwards.

Vendor evidence index: sources, advisories and open questions | DecisionOS by nexalign