The free Avernic Privacy Checkup pilot is open. No payment required.Start your free Privacy Checkup
Skip to main content

Methodology

How Avernic turns your context into a practical privacy plan

Avernic uses a structured review process. First, it organizes your answers about tools, services, settings, habits, and priorities. Then it looks for coverage, overlap, unclear protections, and privacy risks that may deserve attention. The goal is a practical plan, not a generic checklist. This page describes that review process in plain language, without disclosing implementation details or proprietary rule logic.

1. Capability-based evaluation

Avernic evaluates products by what they do, not what they are called. A password manager that includes dark-web monitoring is evaluated across both capabilities separately. This prevents a single product label from hiding a coverage gap or inflating a coverage claim.

2. Existing-product review

Assessment answers identify which products a person currently uses, at what subscription level, and whether specific features are enabled or only available. Products are mapped to capabilities and reviewed against each other for redundancy.

3. Subscription-cost analysis

Annual cost estimates are based on the information supplied by the person completing the assessment. Avernic does not access billing systems, payment records, or account portals. Estimates may differ from actual charges.

4. Overlap identification

When two or more products cover the same capability at comparable protection levels, Avernic flags the overlap and identifies which product is more likely to provide reliable coverage given the person's setup and context.

5. Material-gap identification

A gap is identified when no current product covers a capability that is relevant to the person's context and threat model. Not every gap is a priority. Gaps are evaluated against personal context before a recommendation is made.

6. Personal-context analysis

Answers about household composition, work situation, public exposure, travel patterns, budget, and technical comfort level are used to filter which risks are relevant and which capabilities are material. Context that does not affect recommendations is not used.

7. Asset identification

Assets are the specific things worth protecting: financial accounts, identity documents, private communications, professional credentials, physical access, reputation, and other items identified from personal-context answers.

8. Threat-source relevance

Threat sources are assessed for relevance to the individual's context. A threat source that is theoretically significant but not plausible given a person's life circumstances is not treated as a priority.

9. Exposure-path analysis

An exposure path is the specific mechanism by which a threat source could reach an asset. Identifying plausible exposure paths prevents recommendations based on abstract threats rather than actual risk.

10. Likelihood and impact

Likelihood and impact are considered together, not separately. A high-impact event with very low likelihood and strong existing controls may not be a priority. Avernic does not assign numeric probabilities or use actuarial models.

11. Existing controls

Before recommending action on a threat scenario, Avernic identifies existing controls that already reduce likelihood or impact. This prevents recommending actions for threats the person has already adequately addressed.

12. Priority tiers

Scenarios are placed into five tiers: Do first, Do next, Monitor, Optional optimization, and Accept for now. Most people have very few items in the top tier. The tiers reflect a combined judgment of relevance, likelihood, existing controls, cost, and implementation effort.

13. Dependency-aware sequencing

The 30-day sequence is ordered so that prerequisites are completed before the actions that depend on them. For example, creating a secure backup before enabling stricter account recovery requirements.

14. Cost and effort

Recommendations include an approximate implementation effort level. High-effort recommendations are placed later in the sequence unless they are foundational prerequisites.

15. Free and already-owned alternatives

Where a free option or a product the person already owns can replace a paid subscription, Avernic identifies it. This applies even when the paid alternative has an affiliate relationship.

16. Deterministic free preview

The live free Checkup preview is generated from structured answers using deterministic rules. The paid Complete Privacy Assessment is in development and is not delivered automatically.

17. Human quality review

Any future founding-pilot paid report will be reviewed by an Avernic operator before delivery. Human review is quality control, not a consultation, setup service, or ongoing advisory relationship.

18. Product review dates

Product information used in recommendations includes a review date. Privacy product features, pricing, and policies change. Avernic does not guarantee that product information is current at the time a report is generated.

19. Preventing threat exaggeration

Avernic's methodology includes explicit checks against common patterns of threat exaggeration: overstating the likelihood of rare events, treating theoretical threats as practical priorities, and recommending expensive solutions to low-probability scenarios.

20. Methodology limitation

Avernic's recommendations are based on assessment answers. They are not legal advice, financial advice, or professional security consulting. The methodology does not imply scientific or actuarial precision. Results reflect structured judgment applied to self-reported information.