What did the study find?
Among the 15 platforms in our current research dataset, 13 have supported public evidence for their API permission model, 10 have verified evidence for a no-withdrawal model, and 0 include a publicly linked independent platform-security audit in our source records.
Security disclosure findings
Architecture distribution
Architecture changes who is responsible for secrets, uptime and patching. The categories below are simplified for cross-product comparison; hybrid products may expose more than one model.
How the counts are calculated
Every value is produced during the build from product trust factors, source types, architecture categories and stored claim statuses. “Documented” means the current dataset contains supporting public evidence; it is not a penetration test. “Independent audit linked” requires a source record that explicitly identifies independent audit or assurance coverage for the platform.
Unknown information remains unknown. We do not infer that a missing audit means insecure software, or that published security language proves implementation effectiveness.