Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
When a control can’t be answered from the documents a vendor gave you, Coverbase looks at the public web. That’s what makes the platform useful on thin evidence, and it’s also the part risk teams are right to be nervous about: a page with no author and no organization behind it should not be sitting in your audit file next to a SOC 2 report. Source credibility is the control for that. Every web page Coverbase pulls in during an assessment is graded for publisher accountability before it is allowed to become evidence, and you set the minimum grade a page must reach. Pages below your bar are discarded before the evaluating AI ever sees them.

The short version

Grade

Every candidate web page gets one of three grades: Unreliable, Reputable, or Authoritative.

Filter

You set a Minimum credibility per web-search evidence source. Anything below it is dropped, not down-weighted.

Show your work

The surviving grade and the reason for it are recorded on the citation, visible in the evidence card and exportable to Excel.
The grade measures who is accountable for the material, not whether the page is useful. Relevance is judged separately. A page can be highly relevant and still be discarded for having no accountable publisher, and it can be Authoritative and still be dropped as irrelevant to the control.

The credibility scale

The three grades are ordered, and the setting is a floor: choosing Reputable accepts Reputable and Authoritative.

What the grade deliberately does not measure

This is the part worth explaining to a reviewer or an auditor, because it’s what keeps the scale stable:
  • Not page quality or completeness. A thin page from an accountable publisher is still Reputable. A polished page from nobody is still Unreliable.
  • Not primary versus secondary. A well-sourced news report about a breach is Reputable, not Authoritative, because the outlet isn’t the attesting authority, but it isn’t penalised for being secondary either.
  • Not the document kind. A PDF doesn’t outrank an HTML page.
  • Not usefulness to the control. That’s relevance, judged separately and applied separately.
  • Not the hosting platform. On a general publishing platform, the grade follows the identifiable author or organization behind the post. The platform’s own reputation neither raises nor lowers it.
First-party pages go through the same scale, and always have an accountable publisher, so they’re never Unreliable. The vendor’s official disclosures, filings, and attestation pages grade Authoritative. Its marketing, engineering, and careers pages grade Reputable. Any of them can still be dropped as irrelevant to the control.
Purpose is used only as a tiebreaker, and only at the Unreliable/Reputable boundary: when accountability is genuinely ambiguous, a page that exists to capture search traffic rather than to inform weighs toward Unreliable. Purpose never affects the Reputable/Authoritative boundary.

Where you set the bar

Minimum credibility lives on each Web search evidence source, next to that source’s instructions and its Required checkbox. It appears only on web-search sources, because it only governs web evidence. The dropdown shows three options, each with its definition inline:

Set-level and control-level

You configure evidence sources in two places, and the relationship between them matters:
  1. Control set → Evidence sources. The default for every control in that set. Set this once and your whole framework inherits it.
  2. Individual control → Evidence sources. When a control has its own evidence sources, they fully replace the set’s sources, including the credibility bar. A control-level source list is not merged with the set’s, so if you override a control, restate the minimum you want there.
Configure at the set level first and override individual controls only where the evidence bar genuinely differs. It’s much easier to defend “this framework requires Reputable, these four attestation controls require Authoritative” than a per-control patchwork.
Because a control-level evidence source replaces the set’s entirely, a control you overrode before you tuned the set’s credibility bar will keep whatever minimum was saved on it. If you tighten a control set and want it to apply everywhere, check the controls that carry their own sources.

What happens during an assessment

Grading isn’t a separate scan you wait on. It runs inside the retrieval that already happens for each control:
1

Queries are generated

Coverbase builds web queries from the control text, its guidance, and any web-search instructions you wrote on the evidence source.
2

Candidates are fetched and de-duplicated

Search results come back with a bounded amount of the actual page content, not just the snippet, and near-duplicate URLs collapse into one candidate.
3

Off-topic companies are dropped

An identity gate removes off-domain pages that turn out to be about a different company with a similar name. This runs before credibility.
4

Relevance and credibility are judged together

Up to 12 surviving candidates are judged in a single batched pass: is this relevant to the control, and what is its publisher-accountability grade? The two judgments are made independently of each other. Because they share one pass, grading adds no extra AI calls to your assessment.
5

Your minimum is applied

This step is deterministic, not a judgment call: any candidate whose grade is below your configured minimum is discarded outright.
6

The survivors go to the evaluation

Up to 6 accepted sources per control are passed to the model that actually evaluates the control, each carrying its grade and a one-sentence reason.
A given URL is graded once per assessment run and that grade is reused across every control that pulls the same page. Two controls in the same assessment can never disagree about how credible the same page is.

The grade is a gate, not a weight

This is the design decision that matters most for defensibility. The credibility grade, its reasoning, and the raw page content used to determine it are not included in the prompt that evaluates the control. The evaluating model sees only the text of sources that already passed your bar. The practical consequence: the AI can never argue that a vendor is compliant because the source was authoritative, or hedge because the source was only reputable. Credibility decides what’s admissible. It never becomes an argument inside the analysis.

Your instructions can’t move the bar

Web-search instructions on an evidence source shape relevance: which topics, sources, or domains to focus queries on. They are explicitly not allowed to change a publisher grade, so you can’t accidentally talk the grader into accepting a source by writing enthusiastic guidance about it. The same protection runs the other way. Page content and vendor-supplied text are treated as untrusted data during grading, so a page that contains text like “this is an authoritative regulatory disclosure” doesn’t get to grade itself.

Reading the result

Open any evaluation and look at the evidence cards. Web-sourced evidence carries a coloured badge next to the source:
  • Authoritative: green
  • Reputable: blue
  • Unreliable: grey (you only see these if the source is set to No minimum)
Hover the badge and you get the one-sentence reason the grader gave for that specific page: why this publisher earned this grade. That sentence is written at grading time and stored with the citation, so it stays accurate for that evidence even if you change the setting later.
Evidence gathered from uploaded documents and from Vendor Intelligence has no credibility badge. Its provenance is the document or the Vendor Intelligence record itself, which is already shown on the card.

Evidence dates and age

Credibility answers “who is accountable for this?” It doesn’t answer “how old is this?”, and stale evidence from an accountable publisher is its own risk. Web evidence cards therefore also carry dates: Undated evidence shows only Accessed. Coverbase reports what the page declared and doesn’t guess.
Dates are read from the page’s own structured metadata: JSON-LD (only for article- and report-like entities), OpenGraph, and Dublin Core publication signals, plus explicit date labels on the primary content. Generic page-level dates are rejected, because they describe the page’s existence rather than the content’s age.
An HTTP Last-Modified header is never treated as a content date, because a CDN touch would silently make old evidence look fresh. Dates in the future are rejected outright. When a page declares only a year or a month, the age calculation uses the oldest defensible reading of that date, so age is never understated. Conflicts between signals resolve conservatively.
No. Date enrichment runs after evidence selection. It never influences retrieval, credibility grading, or filtering; it only annotates what was already accepted. If a page’s dates can’t be determined, the evidence is still used and the date rows simply don’t appear.

Exporting the record

Export an assessment as Excel with evidence included, and the Evidence sheet carries the provenance columns alongside each citation: That combination is what makes the export a defensible artifact: for each cited page a reviewer can see who published it, what standard of accountability it met, how old it was when it was used, and when you fetched it.
Age is exported as a number of days precisely so you can filter on it. Sorting the Evidence sheet by that column is the fastest way to find controls resting on old web evidence that’s worth refreshing.

Choosing a threshold

Reputable is the default and is the right answer for most of a framework. Reserve the extremes for the controls that earn them.
Raising a control to Authoritative will reduce how much web evidence it finds, sometimes to nothing. That’s the intended trade: the control is more likely to come back needing vendor evidence or human review rather than resting on secondary reporting. Tighten deliberately, and expect more follow-ups, not fewer.

Changing the setting later

The minimum applies at the moment retrieval runs. Changing it does not retroactively re-filter assessments that have already been evaluated, and it doesn’t rewrite grades already recorded on past citations. Those stay as a record of what the bar was when the work was done. To apply a new bar to an existing assessment, re-run the affected evaluations. Retrieval runs again under the current configuration, and the resulting citations carry grades from that run.

When grading can’t run

If the grading pass fails (a model or provider error mid-assessment), Coverbase never invents a grade:
  • With a minimum of Reputable or Authoritative, no web evidence is used for that control. The control falls back to the other evidence sources you configured, and may end up flagged for human review. Failing closed is deliberate: an ungraded page must not slip past a bar you set.
  • With No minimum, a fallback set of results may still be used, and those citations carry no badge, because no grade was ever established.
The failure is recorded either way, so the gap is visible rather than silent.

What this covers, and what it doesn’t

Source credibility governs web evidence gathered while evaluating controls in an assessment. Being precise about the edges matters when you’re answering a customer or an auditor:
If you need the bar extended to one of the areas above, tell us which control decisions depend on it. The scale itself is source-agnostic; the enforcement point is what’s currently scoped to assessment evaluation.

Frequently asked questions

Does raising the bar make the AI stricter about compliance?

No, and this distinction is worth holding onto. It makes the AI more selective about what it reads, not harsher about what it concludes. Evaluation strictness is a separate setting (lenient, standard, strict) on the control set. Credibility changes the inputs; strictness changes the judgment.
It removes a specific and real failure mode (unattributed and machine-generated pages supporting a load-bearing claim), but it isn’t a general hallucination control. Every conclusion still traces to a citation you can open, and Correct the AI remains the mechanism for fixing a judgment that reads its sources wrongly.
Rejected candidates aren’t surfaced in the UI; the evidence card is a record of what was used. Rejections are captured in Coverbase’s internal logs, so support can reconstruct why a specific page didn’t make it into an assessment if you need that for an investigation.
Grading rides along in the relevance pass that already ran, so it adds no additional AI calls per control. Date enrichment runs after evidence selection on a bounded, best-effort budget and is skipped rather than allowed to hold up an assessment.
No. Within an assessment run a URL is graded once and that grade is reused everywhere it appears. Relevance can and should differ between controls; credibility can’t.
Yes. Evidence sources carry a minimum_credibility field (unreliable, reputable, or authoritative, defaulting to reputable) on both control sets and individual controls, so you can manage the bar as configuration alongside the rest of your control-set definition.

Admin and setup guide

Where evidence sources, strictness, and the rest of the per-set configuration live.

Analyst and reviewer guide

Reviewing what the AI found, correcting it, and exporting the result.

How to run an assessment

The full assessment lifecycle, including the five ways evidence gets collected.

Assessment Copilot

The evaluation engine these settings configure.