Legit.Show · data for investors

The part of the deck
nobody can verify

Every founder says the product is production-grade. We measure whether it is — from the outside, deterministically, on 5,317 launched services, and without the company’s cooperation. That last part is why it works for diligence: a target has no way to prepare for it.

5,317services measured
7+1frames each
45median security score
17%clear a basic policy
What the market actually looks like

Teams either did the production work or they didn’t

Security scores across every live web product we measure. The shape is not a bell curve — it is two populations. One mass sits at 20–45: no Content-Security-Policy, no HSTS, defaults left as shipped. A second sits at 80–100, where the team did the unglamorous work. Very little sits between them.

0–9: 5 services510–19: 75 services7520–29: 1286 services128630–39: 71 services7140–49: 1770 services177050–59: 169 services16960–69: 330 services33070–79: 52 services5280–89: 579 services57990–99: 47 services47100–109: 702 services7020102030405060708090100 median 45 Security score

n = 5,086 live web products, Security frame, measured from HTTP headers and transport. Red bars fall at or below the median of 45.

The gap is binary because the work is binary. A team either wired up headers, consent and a real 404, or it did not — and that decision predicts far more than the demo does.

Why the category on the deck tells you nothing

Every category has the same median

Six categories, from developer tools to consumer productivity, and the median Security score is 45 in all of them. The 90th percentile is 100 in all of them too. The spread lives inside each category, not between them.

Productivityn=1283AI & Agentsn=957Business & Financen=711Developer Toolsn=595Lifestyle & Othern=361Education & Referencen=235 median 45 90th pct 100

Amber dot: category median. Green dot: 90th percentile. Bar: the range between them.

For a fund this is the useful finding. “It’s an AI agents company” predicts nothing about engineering quality. The specific team does — which is exactly the variable diligence is supposed to resolve, and the one a pitch cannot settle.

Before the first call

Screen the pipeline against a policy

Point the API at a list of domains and apply the bar your later-stage co-investors will apply anyway. Most of a pipeline does not clear it.

Measured services in the catalog5,317Live web products (repos excluded)5,086Security 70 or better1,380…and Privacy 50 or better869

Filters run against the live catalog: Security ≥ 70, then Privacy ≥ 50. One call, no vendor contact.

27%clear Security 70

Roughly one in four live products meets a bar most enterprise buyers already enforce.

17%also clear Privacy 50

Add consent and a reachable policy and the field halves again.

0questionnaires sent

Nothing is requested from the company. The measurement is of the public surface it already ships.

Positioning a single target

A fast product is not a finished one

Security against Performance for one category. If polish predicted rigour these points would form a line; they form a cloud. The product that loads instantly in the demo is as likely as any other to be shipping without headers.

policy line 70 CartAI — Security 55, Performance 96Wavetype — Security 45, Performance 99Verse — Security 80, Performance 63Try Tested — Security 25, Performance 92ValueSnap — Security 45, Performance 69WyberAi — Security 80, Performance 68DocuViralPro — Security 80, Performance 81AI CEO — Security 45, Performance 83freddy — Security 100, Performance 99Life by Synheart — Security 25, Performance 83LoovaAI — Security 45, Performance 42SimTelemetry — Security 45, Performance 76Bunstation — Security 25, Performance 90Rex — Security 80, Performance 63AI Moderated Int. — Security 55, Performance 80Sakana — Security 25, Performance 74Wirable — Security 25, Performance 80Veles — Security 25, Performance 94Verity Lex — Security 80, Performance 99ZeroSphere — Security 45, Performance 63FinAdvisor — Security 25, Performance 80Speak naturally — Security 55, Performance 80Flowise — Security 55, Performance 80QUANTIZ — Security 45, Performance 31PDF.chat — Security 60, Performance 93ManyManyLogos — Security 100, Performance 88DEEIX AI — Security 25, Performance 80AskLedger — Security 45, Performance 86apiP2P — Security 60, Performance 87ReZonTree — Security 25, Performance 72SkillServer.ai — Security 25, Performance 72Nortex — Security 45, Performance 61Pixailer — Security 25, Performance 81Relvios — Security 25, Performance 64freddyBunstationRexVelesVerity LexQUANTIZ Security → Perf fast demo, unguarded did the production work

34 AI & Agents products, real scores. Hover any point for the name. Green: clears a Security 70 policy. Red: does not.

This is the chart to open in an IC meeting. It puts the target somewhere specific rather than somewhere flattering, and the evidence behind every point is a public page anyone in the room can open.

After the cheque

Watch the number move, or fail to

Every service is re-measured on a schedule, so engineering quality becomes a series rather than a snapshot. A board deck claims the team hardened the platform last quarter; the series says whether it did.

+4.8avg points gained

Across companies re-measured so far, over a 100-day window.

44%improved

The rest held flat or slipped — which is itself the signal you want on a portfolio call.

27with a full series today

Re-measurement accrues weekly. Biggest movers so far: Mindwalk +60 · Salestrics +20 · Legit.Show +20.

We would rather show a small honest series than a smooth invented one. The history is 27 companies deep today and widens every week; a licence includes it from the day it exists for the names you care about.

What a licence includes

The public half is free on purpose

Per-frame scores are open and quotable — that is how the measurement travels. What a fund pays for is the shape you cannot assemble from single lookups.

FieldAccessWhat it is for
Per-frame scorespublic Screen one company, cite a number in a memo, link the evidence page
Category benchmarkspublic Place a target against its market, as in the charts above
Overall scorelicensed One number to rank a pipeline or a portfolio by
Score time serieslicensed Post-investment monitoring, regression alerts, quarterly reporting
Bulk indexlicensed Join 5,317 services against your own CRM or pipeline
AI attentionlicensed Which answer engines read a product, and how often — an early discovery signal

Try it on a company you already know

Open any product page and read the frames and the evidence behind them. If the shape is useful for your pipeline, we will run your current watchlist and send back the screen.

Ask for a pipeline screen

Or start free: the query API · how the seven frames are measured · the published reports