# Endpoint security teardown: coding notes (codebook v2.0, collected September 26, 2026)

The published codes are the reader codes in coded_v2/. The rules-based coders (v1.5 in coded/, v1.6 as the first pass) are not the source of any published figure.

## Coding method and agreement

- Every one of the 100 answers was coded by two independent AI readers (Claude agents, not people), each working blind from gold2/READER_PROTOCOL_v2.md, published with the dataset as reader-protocol.md. Where they disagreed, a third AI reader decided under the same protocol.
- Six codes: picked (the answer's own verdict, overall or for a case), recommended (assigned to a stated case or fit without being the verdict), listed, passing, anchor, not_a_mention. "Recommended" in the tables and in mentions.csv mention_type is the broad level and includes picked; the "picked" column is 0/1.
- Reader vs reader: 93.7% identical on the six codes, 97.7% at the broad level (413 of 441 brand codes identical).
- Codes decided by the third reader: 28, in 14 answers (q001, q002, q004, q005, q013, q017, q019, q054, q056, q057, q058, q084, q087, q089). By dispute: picked vs recommended 18, listed vs passing 7, passing vs not_a_mention 2, listed vs recommended 1.
- The v1.6 rules-based first pass matched the final codes on 93.7% at the broad level. Positions, bold/table flags, Google flags and citations in coded_v2/ come from that first pass; the codes and which rows exist come from the readers.

## Judgment calls that matter for this category

- Shortlists count as picks. Endpoint answers rarely name one winner. They say "My shortlist for a serious evaluation" (q010), "I'd shortlist ..." (q021, q026, q030, q088), "I would generally evaluate Microsoft Defender for Endpoint first" (q057), "I'd run both vendors through the same proof-of-concept" (q060), "I'd put Huntress and Blackpoint through the same 5-10 attack scenarios" (q055). The protocol codes a shortlist the answer tells the buyer to act on as picked, so these are picks. In 50 of the 93 answers with a pick, the deciding line of at least one pick is shortlist or evaluation language (story_numbers.md).
- A "practical shortlist" table is picked; a catalog table with fit labels is recommended. The third reader applied this in q001 (all seven brands picked: the table is the answer's own "practical shortlist" of products to investigate), q089 (Bitdefender, SentinelOne, Sophos picked: "my usual shortlist" and a quick recommendation by company size), and the other way in q004 (Sophos recommended: a table fit, named only as an example of common shortlists), q013 (Microsoft Defender and Sophos recommended: catalog fits for Microsoft 365-heavy businesses and existing Sophos customers) and q084 (Bitdefender recommended: it has a fit row in the table but the answer's own proof-of-concept list leaves it out).
- This is why Sophos and Bitdefender show the largest recommended-minus-picked gaps (8 each): they are often given a fit row ("Smaller/mid-sized organizations", "Cost-conscious organizations wanting strong prevention") in tables whose verdict lines name other products.
- Head-to-heads with "choose A if / choose B if" or "bottom line" case splits pick both sides: q044 ThreatLocker vs CrowdStrike (both picked from the bottom-line split), q054 SentinelOne or Sophos for a startup (third reader: both picked as case verdicts), q057 Defender or SentinelOne on Microsoft 365 (SentinelOne picked: "where I'd seriously consider it"). The one head-to-head with no pick is q046 SentinelOne vs Cybereason, which gives each a fit label and does not choose.
- Follow-up offers are passing. q087 ends by offering to compare SentinelOne and Sophos; the third reader coded both passing.
- Bare "Defender" as the buyer's existing Microsoft stack is passing (q056, q058; one reader called it not a mention, the third reader coded passing).
- Brands in a list of "strong choices" with no fit are listed, not passing (q002 Check Point Harmony, Trellix, WithSecure; q017 ESET and Palo Alto Cortex; q019 Bitdefender).
- Anchor: the brand named in an alternatives question is always anchor (20 anchors), including Microsoft Defender in q063 and q077.
- Answers with no pick (7): q009 (popularity list, all listed), q017 (schools catalog with fit labels), q046 (above), q067 and q079 (Defender given a fit, no verdict), q078 and q082 (one-sentence answers naming no products).

## Reader-added brands

- 12 flags across the two readers (A 8, B 4) for dictionary brands the alias match missed; 6 new rows in coded_v2/mentions.csv:
  - AVG in q063, q065, q073: the answers write "Avast / AVG" or "Avast/AVG Free", which the AVG aliases (avg antivirus, avg business, avg internet security) do not match. Picked in q063 and q073, recommended in q065.
  - Cisco Secure Endpoint in q062: "Cisco XDR / Secure Endpoint" in a table, fit "Cisco-centric environments". Recommended.
  - Microsoft Defender in q056 and q058: bare "Defender" as part of the buyer's Microsoft stack. Passing.
- One reader also flagged ESET and Palo Alto Cortex in q017, which the first pass already had (listed).

## Collection

All 100 ChatGPT tasks and 100 Google tasks were posted and fetched between about 8:15 and 8:30 PM US Mountain time on September 26, 2026, through the DataForSEO standard queue (the raw files carry UTC timestamps, early September 27). Zero failed tasks, no retries. Raw responses are saved exactly as returned.

Two answers came back as a single sentence with no products and no sources: q078 "sophos alternative for MSPs" and q082 "which endpoint protection platform should I use for a 50 person company". They are counted as answered, as returned; q078 has only the Sophos anchor and q082 has no brand and no citation.

## Dictionary

- No change to brands.csv after collection. The dictionary (53 brands) and its folds are described in INPUT_NOTES.md: Malwarebytes and ThreatDown, Kaseya and Datto, WithSecure and F-Secure, WatchGuard and Panda Security, Xcitium and Comodo are one brand each.
- Case-sensitive aliases (capitalized only): Coro, Velociraptor.
- Deliberately not aliases: bare "defender", "falcon", "cortex", "palo alto", "checkpoint", "avg". The readers still code a brand the answer plainly names by meaning (see reader-added brands).
- broadcom.com counts as the own site of both Symantec and Carbon Black; any microsoft.com page counts as Microsoft Defender's own site.
- "Avast Business" is matched by bare "avast", so consumer mentions of Avast Free Antivirus count toward it (q005, q063, q065, q073).
- Out of dictionary: the scraper's entities outside the dictionary are bare "Microsoft" (every such answer is already coded for Microsoft Defender) and one-off firewall and device-management names (Ubiquiti, OPNsense, pfSense in q074; Microsoft Entra ID and Intune in q090). Nothing picked in 5 or more answers is missing.
- Kaspersky and McAfee are in the dictionary and are named in none of the 100 answers.

## Category notes

- Six answers read the question as home antivirus rather than business endpoint security (q005, q049, q051, q063, q065, q073), which is why Norton, Avast, AVG and consumer Bitdefender products appear. Norton's four picks are all in alternatives answers (q063, q065, q072, q073).
- q074 "cheaper alternative to sophos" is answered entirely as a firewall question (FortiGate, WatchGuard Firebox, pfSense), so WatchGuard's one pick and one of Fortinet's three picks are for firewalls; q064 "sophos alternatives" adds a firewall row, which is where another Fortinet pick comes from.
