Company claim verification begins before research. A claim needs a subject, a specific representation, an applicable period, and a definition clear enough that two reviewers could look for the same evidence.
“We have always served enterprise customers” is not ready to verify until “enterprise,” “served,” and the relevant start date are defined.
Build the claim record first
Preserve the exact source quotation and locator. Then create a separate normalized claim for research. The normalized version may clarify syntax, but it should not quietly strengthen what management said.
- Source: document name or meeting record, page or section, and date received
- Exact wording: the unedited representation in context
- Normalized claim: subject, predicate, value, date range, and relevant definition
- Materiality: which thesis, risk, or decision this could affect
- Evidence plan: the records capable of supporting or refuting it
- Disposition: supported, conflicting, not located within scope, inconclusive, or out of scope
Use an evidence hierarchy matched to the claim
There is no universal “best source.” An executed agreement may be authoritative for contract terms but irrelevant to when a public representation first appeared. A dated archived page may be strong evidence of the wording captured on that date but cannot prove a private event.
| Evidence | Useful for | Important limit |
|---|---|---|
| Primary business records | Contracts, transactions, financial activity, certifications, and ownership | Authenticity, completeness, and period still require review |
| Contemporaneous public records | What the organization represented publicly and when the source was issued | Public disclosure can be selective or delayed |
| Archived web captures | Captured wording, page evolution, removed references, and positioning changes | Coverage is incomplete; capture time is not necessarily publication time |
| Later summaries | Research leads and context | May repeat an unverified earlier assertion |
Run a bounded, reproducible search
- Set an as-of cutoff before reviewing evidence.
- List current and former domains, known product names, and relevant page families.
- Search sources that could reasonably contain the representation during the period.
- Record both supporting and conflicting observations with exact dates and quotations.
- Preserve source URLs, capture identifiers, and retrieval details.
- Stop at the stated boundary; do not turn an open-ended web search into false certainty.
Asteron Systems: certification timing
- Current claim
- “Asteron has maintained SOC 2 Type II compliance since 2020.”
- Record located
- A February 2020 fictional security capture describes encryption in transit and daily backups but does not mention SOC 2. An April 2023 capture states that Asteron is SOC 2 Type II compliant.
- Disposition
- No supporting capture was located for the claimed 2020 start date within the reviewed website scope. The 2023 representation is evidence of what the site stated then, not proof of the report’s scope or effective period.
- Question
- Please provide the SOC 2 reports, covered systems, and exact review periods supporting the 2020 start date.
Report observations separately from conclusions
A strong finding makes the reasoning inspectable: current claim, original source, historical representation, capture date or range, observed change, why it may matter, citations, confidence, and the analyst’s review state. It uses careful phrases such as “the available public record indicates” and “this may warrant clarification from management.”
Do not convert “not found” into “false.” Search scope, access failures, domain changes, and archive gaps should remain visible. For web-specific techniques, continue with company website history and Wayback Machine due diligence.