Skip to main content

Methodology

See how your setup becomes a prioritized privacy plan.

Avernic considers coverage, context, priority, and sequence so recommendations reflect what you already use, what matters to you, and what should happen first.

Coverage in practice

Coverage

How existing tools, costs, overlap, gaps, alternatives, and current product information are evaluated.

Avernic evaluates products by what they do, not what they are called. A password manager that includes dark-web monitoring is evaluated across both capabilities separately. This prevents a single product label from hiding a coverage gap or inflating a coverage claim.

Assessment answers identify which products a person currently uses, at what subscription level, and whether specific features are enabled or only available. Products are mapped to capabilities and reviewed against each other for redundancy.

Annual cost estimates are based on the information supplied by the person completing the assessment. Avernic does not access billing systems, payment records, or account portals. Estimates may differ from actual charges.

When two or more products cover the same capability at comparable protection levels, Avernic flags the overlap and identifies which product is more likely to provide reliable coverage given the person's setup and context.

A gap is identified when no current product covers a capability that is relevant to the person's context and threat model. Not every gap is a priority. Gaps are evaluated against personal context before a recommendation is made.

Where a free option or a product the person already owns can replace a paid subscription, Avernic identifies it. This applies even when the paid alternative has an affiliate relationship.

Product information used in recommendations includes a review date. Privacy product features, pricing, and policies change. Avernic does not guarantee that product information is current at the time a report is generated.

Context in practice

Context

How circumstances, assets, plausible exposure paths, and existing protections shape relevance.

Answers about household composition, work situation, public exposure, travel patterns, budget, and technical comfort level are used to filter which risks are relevant and which capabilities are material. Context that does not affect recommendations is not used.

Assets are the specific things worth protecting: financial accounts, identity documents, private communications, professional credentials, physical access, reputation, and other items identified from personal-context answers.

Threat sources are assessed for relevance to the individual's context. A threat source that is theoretically significant but not plausible given a person's life circumstances is not treated as a priority.

An exposure path is the specific mechanism by which a threat source could reach an asset. Identifying plausible exposure paths prevents recommendations based on abstract threats rather than actual risk.

Likelihood and impact are considered together, not separately. A high-impact event with very low likelihood and strong existing controls may not be a priority. Avernic does not assign numeric probabilities or use actuarial models.

Before recommending action on a threat scenario, Avernic identifies existing controls that already reduce likelihood or impact. This prevents recommending actions for threats the person has already adequately addressed.

Priority in practice

Priority

How relevance, effort, and safeguards against exaggeration inform what deserves attention first.

Scenarios are placed into five tiers: Do first, Do next, Monitor, Optional optimization, and Accept for now. Most people have very few items in the top tier. The tiers reflect a combined judgment of relevance, likelihood, existing controls, cost, and implementation effort.

Recommendations include an approximate implementation effort level. High-effort recommendations are placed later in the sequence unless they are foundational prerequisites.

Avernic's methodology includes explicit checks against common patterns of threat exaggeration: overstating the likelihood of rare events, treating theoretical threats as practical priorities, and recommending expensive solutions to low-probability scenarios.

Sequence in practice

Sequence

How dependencies, deterministic preview rules, human quality review, and limitations bound the plan.

The 30-day sequence is ordered so that prerequisites are completed before the actions that depend on them. For example, creating a secure backup before enabling stricter account recovery requirements.

The live free Checkup preview is generated from structured answers using deterministic rules. The paid Complete Privacy Assessment is in development and is not delivered automatically.

Any future founding-pilot paid report will be reviewed by an Avernic operator before delivery. Human review is quality control, not a consultation, setup service, or ongoing advisory relationship.

Avernic's recommendations are based on assessment answers. They are not legal advice, financial advice, or professional security consulting. The methodology does not imply scientific or actuarial precision. Results reflect structured judgment applied to self-reported information.

Methodology trust

Bounded by evidence, assumptions, and human judgment.

The method is designed to keep unknowns visible and prevent a product recommendation from outrunning the evidence behind it.

  • Free and existing options firstWhat you already have and built-in actions are considered before a paid addition.
  • Dated evidenceProduct information carries review dates because features, prices, and policies change.
  • Visible assumptionsUnknown or customer-unverified details remain items to confirm rather than invented facts.
  • Human review where promisedThe planned Complete Privacy Assessment receives operator quality review before delivery.
  • Integrity before commercial valueAffiliate availability does not determine whether, where, or how a product is recommended.

Apply the method to your setup

Start with a free, structured result.

The Privacy Checkup uses structured answers and deterministic rules to identify a prioritized starting point without passwords, account access, or payment.