Datasets

Security base rates, measured in the open

27 controls measured passively across defined populations of domains, packages, certificates and networks — sliced by country, company size, ecosystem and issuing CA. Each figure is the share not meeting the control, with a 95% confidence interval. Aggregate-only; no company is ever named; free to reuse (CC BY 4.0).

91% What share of networks in South Korea have no RPKI ROA, so their route origins cannot be validated? South Korea (networks) · n=928 Chosen automatically: the highest-severity control's worst credible segment (n≥400) · updates as measurements change

All checks, by rate

25 controls, ranked by the share of the population not meeting each. Each row shows the control's worst credible segment — the slice of the population (n≥400) where the gap is widest.

Context measures

Composition of the same population — not failures, and deliberately not ranked above. They give the denominators the checks above sit inside.

For AI agents: MCP server

Every dataset here is also served over MCP — an agent can look up a base rate, get the full measurement doc with citation metadata, and run a live check of a specific domain against it. Free, no auth; live checks are rate-limited.

claude mcp add --transport http quiet-failures https://mcp.quietfailures.com/mcp

Tools: list_base_rates · find_base_rate · get_base_rate · check_email_auth · check_subdomain_takeover · check_whois. Prefer raw files? The catalog is at /datasets/manifest.json and every dataset page has .json / .csv.

Each control is measured once a week on a fixed weekday, since 2026-08-01 — so figures for different controls can be up to six days apart, and each dataset states its own measurement date. Aggregate-only — no company is ever named. A slice is published only where it holds at least 100 measured members, so an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0; every page has .json / .csv downloads.