CoverageReportsCalendarReproducibilityContactVerlumia Intelligence ES EN FR
verlumia Support
Doctrine · principles & method · doesn't change monthly

Method

Measured truth, not manufactured

Every figure Verlumia publishes can be rebuilt step by step, from the official source to the number. That's how it's built — and how it's audited.

In one line

What this method guarantees

Verlumia measures citizen cyber-risk with deterministic statistical code over official sources. No published figure comes out of a generative AI: AI helps us build and audit the system, never to produce the data. Every number carries its grade of evidence and its full lineage, and anyone can reproduce it.

How it works

From source to figure

The path of every datum is the same and doesn't change from one edition to the next: an official source (an administrative registry or a government survey) is downloaded and sealed with its digital fingerprint —a hash that fixes exactly which file was used—; a deterministic computation turns it into an index; and the result is signed with its lineage, so that another person with the same inputs obtains the same number. Today the index is fed by the SESNSP fraud registry (RNID), INEGI's cyberbullying survey (MOCIBA) and CONDUSEF's annual cross-check.

Not all data carry the same weight, and Verlumia says so with a grade of evidence visible on every figure:

Grade A
Measured truth
Official count of events that occurred. It is the only grade painted teal.
Grade B
Survey estimate
Prevalence measured in a sample, with its stated confidence interval. No teal.
Grade C
Reference and context
Third-party indices and explanatory material. Not index data. No teal.

Teal is not a brand color: it signals measured truth and nothing else. If something is teal and does not point to a grade-A datum, that's a defect.

Today the index has two public pillars: Citizen fraud, monthly and grade A, and Cyberbullying, annual and grade B. Other dimensions are declared in incubation and are neither published nor forcibly filled in: Data exposure and Citizen defense —no stable official source, after the dissolution of INAI (2025) and the continuity risk to ENDUTIH from the wind-down of the IFT— and direct cyber-harm —remote crimes against the person (extortion by other means and identity impersonation), measured since their 2026 baseline but without a comparable series yet—. The gap is declared; it isn't dressed up. To measure is not to publish: Verlumia measures from day one and publishes a figure only when it is meaningful.

Example · Citizen fraud pillar
75.8High
Grade A · measured truth
0 100 5,406.58 case files 12,777.65 case files <0 · Low >100 · Critical Jul 2026 · 75.8 High
The scale is a fixed-anchor linear normalization: index 0 marks the typical level of the 2015–2019 base regime (5,406.58 case files/month) and 100, the historical maximum plus 15% headroom. The number is not clipped: it can fall below 0 (band "Low") or exceed 100 (band "Critical") without altering the figure. The anchors are frozen by version, so that "60 means 60" across the entire series.
Lineage of this figure
Source
RNID · SESNSP — 10 995 case files (Jul 2026)
Methodology
ICC/1.4 · fixed-anchor linear transformation
Edition
July 2026 · sealed and immutable
Grade
A — measured truth
Case record
Full lineage with hash @ commit →

"Citizen fraud" measures the crime of fraud in all its forms (RNID/SESNSP): what is reported —there is under-reporting, the dark figure—, it includes digital fraud but is not limited to it, and it is one pillar of the ICC, not total cyber-risk.

For months already closed, the headline is the measured official datum. The early estimate for the current month (the nowcast) exists and is published, but as an annex, never as the headline: estimates are kept distinct from measured data.

Technical lineage

For anyone who wants to audit it

The pipeline is a deterministic Python codebase, versioned under version control (git), where the identity of each computation is fixed by the commit, not by a file name. The computation methodology is also versioned, with explicit rules about what may change and what breaks the comparability of the series.

Current methodology
ICC/1.4. A minor change adjusts parameters within the same anchor and measured object; a major change replaces the measured object and forces a re-issue of the entire series.
0–100 scale
Fixed-anchor linear normalization: index = (x − FLOOR) / (CEILING − FLOOR) × 100, with FLOOR = 5 406.58 and CEILING = 12 777.65. No clipping; anchors frozen by version.
Estimation
Nowcasting by ordinary least squares (OLS) regression, with backtesting and measured error (MAPE). A transparent, explainable model, not a black box. Only for the not-yet-reported month; the headline of a closed month is always the official one.
Reproducibility
Every sealed figure is protected by an exact reproduction proof, and every code artifact is cited as hash @ commit: a hash without its commit identifies nothing.
Review
The methodology is reviewed once a year and changed only when the evidence warrants it, never on schedule. Stability is the expected outcome of the review, not its failure.
Composite index
The pillars are not yet merged into a single figure: they are heterogeneous (monthly and annual, count and survey) and will not be composed until doing so is honest.

Generative artificial intelligence takes part in Verlumia as a construction scaffold and as an external auditor of the method — never as the source of the data. In an era awash in machine-generated figures, measuring the truth and proving it with lineage is the discipline that sets the index apart, not a limitation.

Every figure and decision at Verlumia is governed by five guiding principles. This method puts three of them into practice: zero generative AI in the data, teal reserved for measured truth, and end-to-end auditability — from source selection to the figure. Want the step-by-step explained version? Read "How Verlumia measures" in the Knowledge Center (grade C · explanatory content).