{
  "schema_version": "1.0.0",
  "published_at": "2026-08-12",
  "claim_fields": [
    "claim_id",
    "display_value",
    "definition",
    "population",
    "sample_size",
    "measurement_window",
    "eligibility_and_exclusions",
    "distribution",
    "source_type",
    "source_url",
    "approved_surfaces",
    "owner",
    "reviewed_at",
    "expires_at"
  ],
  "publication_note": "These entries document directional figures already present in ContraForce materials. They are not independent benchmark results or approvals for commercial reuse. Null sample sizes and measurement windows are intentional disclosure gaps pending validation.",
  "claims": [
    {
      "claim_id": "eligible-incident-mean-response-v1",
      "display_value": "140 seconds (directional; validation pending)",
      "definition": "Elapsed time from an eligible incident becoming available to ContraForce until the first completed response outcome is recorded by a Security Delivery Agent.",
      "population": "Eligible incidents made available through supported integrations with an active Gamebook.",
      "sample_size": null,
      "measurement_window": null,
      "eligibility_and_exclusions": "Excludes incidents outside connector or Gamebook coverage, incidents received before a connection is ready, and containment or recovery work that occurs after the first response outcome.",
      "distribution": "Arithmetic mean; median, P90, P95, range, and cohort mix have not yet passed the public validation gate.",
      "source_type": "internal_product_telemetry_pending_validation",
      "source_url": null,
      "approved_surfaces": [
        "benchmark_methodology"
      ],
      "owner": "ContraForce Security Operations",
      "reviewed_at": "2026-08-12",
      "expires_at": "2026-11-12"
    },
    {
      "claim_id": "eligible-incident-automated-investigation-rate-v1",
      "display_value": "100% (directional; validation pending)",
      "definition": "Share of eligible incidents for which the configured agent completes triage and investigation without an analyst performing those steps.",
      "population": "Eligible incidents supported by the connected integration and an active Gamebook.",
      "sample_size": null,
      "measurement_window": null,
      "eligibility_and_exclusions": "Excludes unsupported incident classes, incomplete connections, incidents routed to an analyst by policy, and any incident without a configured investigation path.",
      "distribution": "Proportion of eligible incidents; numerator, denominator, cohort mix, and confidence interval have not yet passed the public validation gate.",
      "source_type": "internal_product_telemetry_pending_validation",
      "source_url": null,
      "approved_surfaces": [
        "benchmark_methodology"
      ],
      "owner": "ContraForce Security Operations",
      "reviewed_at": "2026-08-12",
      "expires_at": "2026-11-12"
    },
    {
      "claim_id": "analyst-ticket-reduction-v1",
      "display_value": "Approximately 85% (directional; validation pending)",
      "definition": "Reduction in incidents requiring a new analyst-owned ticket compared with the participating provider's prior workflow.",
      "population": "Participating managed security providers that supplied a comparable pre-deployment ticketing baseline.",
      "sample_size": null,
      "measurement_window": null,
      "eligibility_and_exclusions": "Baseline methods and ticketing policies vary by provider. Providers without a comparable baseline are excluded.",
      "distribution": "Customer-reported directional outcome; cohort count, range, median, and weighting method have not yet passed the public validation gate.",
      "source_type": "customer_reported_outcome_pending_validation",
      "source_url": null,
      "approved_surfaces": [
        "benchmark_methodology"
      ],
      "owner": "ContraForce Customer Outcomes",
      "reviewed_at": "2026-08-12",
      "expires_at": "2026-11-12"
    },
    {
      "claim_id": "automated-close-rate-top-providers-v1",
      "display_value": "95% or greater among top providers (directional; validation pending)",
      "definition": "Share of eligible incidents closed by configured policy without analyst intervention.",
      "population": "A top-performing subset of providers that enabled the applicable closure policies.",
      "sample_size": null,
      "measurement_window": null,
      "eligibility_and_exclusions": "Excludes providers without automated closure enabled and incidents routed to human approval or outside policy coverage. “Top providers” is not yet a publishable cohort definition.",
      "distribution": "Threshold observed in a selected cohort; cohort selection, denominator, median, P90, and P95 have not yet passed the public validation gate.",
      "source_type": "internal_product_telemetry_pending_validation",
      "source_url": null,
      "approved_surfaces": [
        "benchmark_methodology"
      ],
      "owner": "ContraForce Security Operations",
      "reviewed_at": "2026-08-12",
      "expires_at": "2026-11-12"
    },
    {
      "claim_id": "connection-to-agent-readiness-v1",
      "display_value": "Approximately 10 minutes from connecting a tenant to Security Delivery Agents working incidents.",
      "definition": "Elapsed time from completion of a supported tenant connection until agents are ready to begin work on an eligible incident.",
      "population": "Supported tenant connections that complete without third-party licensing, consent, or credential remediation.",
      "sample_size": null,
      "measurement_window": null,
      "eligibility_and_exclusions": "Excludes procurement, customer consent, third-party licensing, failed credentials, unsupported configurations, and time waiting for an eligible incident.",
      "distribution": "Directional elapsed-time figure. Statistic type, cohort size, median, P90, and P95 remain unpublished.",
      "source_type": "internal_product_telemetry",
      "source_url": null,
      "approved_surfaces": [
        "benchmark_methodology",
        "resources/best-siem-for-msps"
      ],
      "owner": "ContraForce Product Operations",
      "reviewed_at": "2026-08-18",
      "expires_at": "2026-11-18"
    },
    {
      "claim_id": "first-quarter-margin-expansion-v1",
      "display_value": "30% or greater (directional; validation pending)",
      "definition": "Change in service gross margin reported by participating managed security providers during the first quarter after deployment.",
      "population": "Participating providers that supplied a before-and-after gross-margin calculation.",
      "sample_size": null,
      "measurement_window": "First quarter after deployment; exact calendar windows have not yet been approved for publication.",
      "eligibility_and_exclusions": "Affected by provider pricing, labor allocation, alert mix, service packaging, and accounting policy. Providers without comparable calculations are excluded.",
      "distribution": "Customer-reported directional outcome; cohort count, range, median, and weighting method have not yet passed the public validation gate.",
      "source_type": "customer_reported_outcome_pending_validation",
      "source_url": null,
      "approved_surfaces": [
        "benchmark_methodology"
      ],
      "owner": "ContraForce Customer Outcomes",
      "reviewed_at": "2026-08-12",
      "expires_at": "2026-11-12"
    },
    {
      "claim_id": "microsoft-editorial-incident-response-automation-v1",
      "display_value": "more than 90% of incident response",
      "definition": "A threshold statement about ContraForce published by Microsoft in an editorial customer-and-partner roundup. It is preserved as an attributed third-party statement, not represented as validated ContraForce telemetry or a guaranteed customer outcome.",
      "population": "Not disclosed in the Microsoft editorial source.",
      "sample_size": null,
      "measurement_window": null,
      "eligibility_and_exclusions": "Microsoft does not disclose the incident population, eligibility rules, exclusions, numerator, denominator, workflow versions, customer mix, or validation method supporting the statement.",
      "distribution": "Third-party editorial threshold; no underlying distribution or uncertainty interval is disclosed.",
      "source_type": "external_editorial_statement",
      "source_url": "https://blogs.microsoft.com/blog/2026/04/28/unlocking-human-ambition-to-drive-business-growth-with-ai/",
      "approved_surfaces": [
        "blog/microsoft-features-contraforce-frontier-transformation"
      ],
      "owner": "ContraForce Product Marketing",
      "reviewed_at": "2026-08-12",
      "expires_at": "2027-08-12"
    }
  ]
}
