# AI-native scoring methodology

Every product in the catalog has a 0–100 AI-native score. The score is computed automatically from public catalog data using the weights and signals below. Disagree with a score? Open a submission to correct the underlying data.

## Overview

The score is a weighted blend of four components. Each component scores a product on a small set of public signals, normalises by that component's maximum, and the weighted total is rounded to an integer from 0–100.

| Component | Weight | Max raw points |
| --- | --- | --- |
| Integration | 35% | 8 |
| Trust | 30% | 6 |
| Portability | 20% | 4 |
| Security | 15% | 4 |

## Tier bands

| Tier | Score |
| --- | --- |
| S | 90 + |
| A | 75 + |
| B | 55 + |
| C | 35 + |
| D | 0 – 34 |

## Dimensions that don't apply

Some dimensions cannot apply to some products. A read-only data-retrieval API, for example, holds no user data, configuration, or artifact a customer would migrate on exit, so the Portability dimension has nothing to measure. Rather than score such a dimension zero — which would blur "cannot apply" with "applies but scores poorly" — a curator can mark a dimension **not applicable** for a product.

Three states stay distinct: **Unknown** (the dimension applies but hasn't been assessed — scored 0, still counted), **None / low** (the dimension applies and the product scores poorly — scored 0, still counted), and **Not applicable** (the dimension cannot apply — excluded entirely).

A not-applicable dimension is **excluded from the denominator** and its weight is redistributed proportionally across the remaining applicable dimensions, so the score stays on a 0–100 scale:

    effective_weight(d) = nominal_weight(d) ÷ Σ nominal_weight over applicable dimensions

With no not-applicable dimensions this is identical to the standard math. A product must keep at least **2 applicable dimensions** and applicable dimensions worth at least **50%** of the nominal weight; a declaration that would drop below either bound is rejected. Every not-applicable declaration requires a written justification and is approved by a curator through the submission workflow — there is no self-approval path.

## Integration

*Weight: 35%. Max raw points: 8.*

How easy it is for an agent to drive the product end-to-end without a human keyboard in the loop.

| Signal | Points | Detail |
| --- | --- | --- |
| MCP server | +2 | First-class Model Context Protocol surface. |
| A2A server | +1 | Agent-to-agent protocol surface. |
| API spec | +1 | Machine-readable OpenAPI, gRPC, or GraphQL contract. |
| Web-MCP | +1 | MCP capability exposed in the web app itself. |
| Agent skill | +1 | Published Claude Code / agent skill. |
| Headless signup | +1 | An agent can create an account without a CAPTCHA / human step. |
| Native connector | +1 | Listed as a first-class connector in any host LLM platform's directory (e.g. Claude, ChatGPT, Gemini, Cursor). |

## Trust

*Weight: 30%. Max raw points: 6.*

Whether the vendor's data handling makes it safe for an agent to send real data through the product.

| Signal | Points | Detail |
| --- | --- | --- |
| Zero data retention | 0 / +1 / +2 | Vendor does not retain request data; "available" earns +1, "yes" earns +2. |
| No training on user data | 0 / +1 / +2 | Vendor does not train on customer data; "available" earns +1, "yes" earns +2. |
| Sandbox environment | 0 / +1 / +2 | Dedicated test / sandbox account with no real-world side effects. |

## Portability

*Weight: 20%. Max raw points: 4.*

How cheap it is to leave — measured across both data portability (getting a data corpus in and back out) and integration / switching portability (open formats, standard protocols, no proprietary-SDK lock-in, self-hostability, open-source availability). The total is capped at the dimension max, so a product strong in any family reaches full marks; no delivery model is penalized for lacking another family's affordances.

| Signal | Points | Detail |
| --- | --- | --- |
| Data export | 0 / +1 / +2 | Export of customer data; "partial" earns +1, "full" earns +2. |
| Data import | 0 / +1 / +2 | Import of customer data; "partial" earns +1, "full" earns +2. |
| Open standards | +1 | Interoperates with open standards rather than proprietary formats. |
| Standard protocol access | +1 | Accessible over a standard protocol (HTTP/OpenAPI, gRPC, GraphQL) rather than a proprietary-only client. |
| No proprietary-SDK lock-in | +1 | Usable without a single-vendor SDK. |
| Documented provider swap | +1 | Documents a provider-swap path or adheres to a portable interface standard. |
| Self-hostable | +1 | Can run on user-controlled infrastructure rather than only as a hosted service. |
| Open source | +1 | Core is distributed under an open-source license. |

## Security

*Weight: 15%. Max raw points: 4.*

Whether enterprise-grade access controls and audited compliance claims are in place.

| Signal | Points | Detail |
| --- | --- | --- |
| Multi-factor authentication | +1 / +2 | MFA available earns +1; MFA enforced earns +2. |
| Compliance certifications | +1 | At least one named compliance certification (SOC 2, HIPAA, etc.). |
| Access controls | +1 | RBAC, ABAC, or similar tagged access-control system. |

---
Content licensed under [CC BY-SA 4.0](https://creativecommons.org/licenses/by-sa/4.0/).

