Home › Methodology
How VaultRubric turns sourced facts into scores and verdicts. Each rule has a stable link (e.g. /methodology#coverage-gate).
Each category has six criteria. Exchanges: fees, security & track record, supported coins, ease of use, customer support, US availability/regulation. Wallets: price, security, supported coins, ease of use, support, backup/recovery. High-yield savings: standard APY, minimum to earn the APY, fees, deposit insurance, regulatory record, access. Brokerage & IRA: trading costs, account minimum, IRA options, transfer-out fee, SIPC protection, regulatory record.
Every criterion is scored 0–10. The VaultRubric score is the weighted average × 10 (0–100%). Pages use equal weights unless the page states otherwise (for example, beginner pages weight ease of use higher); the weights and the full math are shown on every page, and you can change them in the tool.
Facts come from official provider pages and filings wherever possible. Third-party sources are flagged as such. Every fact carries its source link. Qualitative criteria (ease of use, support) are scored from cited reviews; customer-review-based scores are labelled ‘Customer reviews (Trustpilot), may skew positive’.
Every fact has an as-of date. Rates and fees are re-checked on a weekly refresh; pages show ‘Data as of’ and ‘Last updated’ dates. Rates change often: always confirm on the provider's site.
Coverage is the share of criteria we could back with real evidence. A product under 75% coverage is still listed (with a ‘limited data’ badge) but can never be VaultRubric's pick.
If a criterion is unknown, it is not dropped. It is scored at the lower of a neutral 5/10 and the median of the known scores for that criterion among the products compared, so a missing (possibly weak) score can never raise a product's rank. Imputed values are marked with * in the math. Coverage counts only real evidence.
If the top two eligible products are less than 3 points apart, we say ‘too close to call’ and name no winner.
A customer-funds hack in the last 48 months that customers weren't shown to be reimbursed for caps the product's score at 60% and makes it ineligible to be the pick. Data breaches and reimbursed incidents are shown as warnings.
Customer-funds losses follow the hack cap (−3 security points; capped at 60% and ineligible if not shown reimbursed within 48 months; a public commitment to reimburse is shown as ‘committed to reimburse’). Data leaks with no funds lost cost −0.5, halved after 24 months and zero after 48. Disclosed firmware/software vulnerabilities with no funds lost are scored only if remotely exploitable (via a malicious host, app, website or network, without physical possession of the device): −0.5 each with the same 24-month half / 48-month zero decay, bulletins from the same vendor in the same month count as one entry, and total vulnerability deductions are capped at 1.0 per platform. Flaws that need physical access or lab equipment are shown as informational notes only and don't change the score. Sources: vendor security bulletins, CVE/NVD records and reputable security press (flagged as third-party).
For savings and brokerages: base 10, minus 2 for each major enforcement action (consent order, redress/restitution, or ≥$25M) and minus 1 for smaller actions or class actions in the last five years; dismissed actions don't count.
Conditional or promotional APYs are shown but not scored by default; the standard rate is scored.
Some outbound links may be affiliate links. They never change scores, ranks or verdicts. See the disclosure.
VaultRubric is an information service, not a bank, broker, card issuer or adviser. Nothing here is investment, tax or legal advice.
Last updated 2026-10-11 · VaultRubric Research