We measure the gap between what your privacy policy promises and what your GTM stack actually does at runtime. Then we publish receipts.
SOC 2 made security legible to auditors. ISO 27001 made information governance legible to enterprises. BTS makes GTM behavior legible to legal, buyers, and regulators.
You earn it with proof—or you don't.
/.well-known/blackout.jsonBadge can be suspended or revoked on critical breach.
| Pay-to-Play Rankings | Blackout Evidence |
|---|---|
Sponsorable placement | Revocable badge tied to runtime proof |
Vendor self-reported data | Third-party detection with chain-of-custody |
Analyst subjectivity | Automated control scoring (0.0–1.0) |
Annual refresh cycles | Quarterly re-verification for badge holders |
Opaque methodology | Open spec, published controls, public revocation log |
Influence wins | Behavior wins |
This isn't Gartner or G2. You can't sponsor your way up a chart. We grade behavior, not influence.
We fingerprint every script, pixel, and API call. Runtime reality vs. what you disclosed.
+186 ms post-reject → s3-us-west-2.amazonaws.com/b2bjsstore/.../reb2b.js.gzWe compare detected vendors against your subprocessor list and privacy policy. No guessing. Just facts.
policy_subprocessors[] ≠ runtime_vendors[] (3 undisclosed: ████, ██████, █████)Counsel-ready Evidence Pack with timestamped artifacts, control results, and remediation roadmap.
sha256(evidence_pack.zip) = a3f9c8e7d2b1a4f6c9e8d7b3a2f1c0e9Companies holding a BTS badge receive private notification of gaps discovered in quarterly re-scans. You get 30 days to remediate before public disclosure.
Challenge a finding. We re-scan. Outcome is logged. If you're right, we publish the correction. If you're wrong, the gap stands.
Silent deanonymization vendor detected post-badge issuance? Consent gate bypassed? You have 72 hours to remediate or we suspend the badge and publish the evidence.
We're inviting 25 companies to the BTS Founding Cohort. You get priority audit windows, quarterly re-checks, and early steering group invites. Your logo (optional) goes on the founding page.
What you provide: Runtime access for initial audit. Public commitment to disclosure parity.
What you get: Badge (if you pass), evidence pack, remediation roadmap, founding member status.
Click to fill out the application form on our main page
We measure behavior. Timing + URLs. We don't provide legal opinions. Jurisdictional analysis happens in the evidence report.
Tier (Bronze/Silver/Gold), score (70–100), last verified date, and a link to your company-hosted manifest at /.well-known/blackout.json.
Yes—on critical breach. See Revocation Policy. Badges can be suspended or revoked.
A machine-readable file you host at /.well-known/blackout.json containing your disclosed subprocessor list, policy URL, and badge metadata.
Enterprise audit and cohort pricing on request.